Re: [ietf-822] one can re-sign without a permission to re-sign header

Paul Smith <paul@pscs.co.uk> Fri, 02 May 2014 12:58 UTC

Return-Path: <paul@pscs.co.uk>
X-Original-To: ietf-822@ietfa.amsl.com
Delivered-To: ietf-822@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9CE671A6FBB for <ietf-822@ietfa.amsl.com>; Fri, 2 May 2014 05:58:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.252
X-Spam-Level:
X-Spam-Status: No, score=-3.252 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.651, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vG0J7NhmxBHX for <ietf-822@ietfa.amsl.com>; Fri, 2 May 2014 05:58:50 -0700 (PDT)
Received: from mail.pscs.co.uk (mail.pscs.co.uk [188.65.177.237]) by ietfa.amsl.com (Postfix) with ESMTP id 19D931A081E for <ietf-822@ietf.org>; Fri, 2 May 2014 05:58:49 -0700 (PDT)
Authentication-Results: mail.pscs.co.uk; spf=none; auth=pass (cram-md5) smtp.auth=paul
Received: from lmail.pscs.co.uk ([82.68.5.206]) by mail.pscs.co.uk ([188.65.177.237] running VPOP3) with ESMTP for <ietf-822@ietf.org>; Fri, 2 May 2014 14:00:24 +0100
Authentication-Results: lmail.pscs.co.uk; spf=none; auth=pass (cram-md5) smtp.auth=paul
Received: from [192.168.66.101] ([192.168.66.101]) by lmail.pscs.co.uk ([192.168.66.70] running VPOP3) with ESMTP for <ietf-822@ietf.org>; Fri, 2 May 2014 13:58:41 +0100
Message-ID: <53639681.1050803@pscs.co.uk>
Date: Fri, 02 May 2014 13:58:41 +0100
From: Paul Smith <paul@pscs.co.uk>
User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:24.0) Gecko/20100101 Thunderbird/24.4.0
MIME-Version: 1.0
To: ietf-822@ietf.org
References: <20140501195449.68225.qmail@joyce.lan>
In-Reply-To: <20140501195449.68225.qmail@joyce.lan>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Authenticated-Sender: paul
X-Server: VPOP3 Enterprise V6.8 - Registered
X-Organisation: Paul Smith Computer Services
X-Authenticated-Sender: paul
Archived-At: http://mailarchive.ietf.org/arch/msg/ietf-822/lcTVAp9ySJpQqVOshDkg_CrsIEE
Subject: Re: [ietf-822] one can re-sign without a permission to re-sign header
X-BeenThere: ietf-822@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Discussion of issues related to Internet Message Format \[RFC 822, RFC 2822, RFC 5322\]" <ietf-822.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf-822>, <mailto:ietf-822-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf-822/>
List-Post: <mailto:ietf-822@ietf.org>
List-Help: <mailto:ietf-822-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf-822>, <mailto:ietf-822-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 02 May 2014 12:58:52 -0000

On 01/05/2014 20:54, John Levine wrote:
>
>>> Perhaps it's time for a more concrete proposal to be written down.
> It occurred to me that there's a very simple way to do this:
>
> http://datatracker.ietf.org/doc/draft-levine-may-forward/
>
>
Isn't this a bit dangerous?

I don't mean the draft - I mean what the draft suggests.

Unless I'm misunderstanding something badly, essentially all you are 
doing is signing the 'From' header field. So, if I get hold of one of 
those messages, I can just reproduce it and send zillions more messages 
pretending to be from you all with your From header, and all 'signed 
correctly'.

Maybe that's the point - the draft essentially makes clear that you 
can't use DKIM from the sender to authenticate the message, as the From 
header is pretty much all you can rely on staying the same (if that) by 
the time the list recipient gets the message from the mailing list. 
Hence trying to do this is a bad idea.

IMHO, you'd be better off just not using DKIM at all in these 
situations, rather than giving out a way for people to forge mail from 
you and 'sign' it.

-


Paul Smith Computer Services
Tel: 01484 855800
Vat No: GB 685 6987 53