Re: SMTP RFC: "MUST NOT" change or delete Received header

Dave Aronson <ietf2dave@davearonson.com> Sat, 29 March 2014 14:39 UTC

Return-Path: <davearonson@gmail.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9BCD61A0505 for <ietf@ietfa.amsl.com>; Sat, 29 Mar 2014 07:39:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.278
X-Spam-Level:
X-Spam-Status: No, score=-1.278 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FM_FORGED_GMAIL=0.622, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xl6w_7O3I2BK for <ietf@ietfa.amsl.com>; Sat, 29 Mar 2014 07:39:24 -0700 (PDT)
Received: from mail-pa0-x22b.google.com (mail-pa0-x22b.google.com [IPv6:2607:f8b0:400e:c03::22b]) by ietfa.amsl.com (Postfix) with ESMTP id 8E9FC1A04FA for <ietf@ietf.org>; Sat, 29 Mar 2014 07:39:24 -0700 (PDT)
Received: by mail-pa0-f43.google.com with SMTP id bj1so6239374pad.16 for <ietf@ietf.org>; Sat, 29 Mar 2014 07:39:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:sender:in-reply-to:references:from:date:message-id :subject:to:content-type; bh=kIS07sKLDaGAy0KPtoTdsiyZyngPaMUW4UpQ5lRaLd8=; b=Vu7fDd/4VLREK5rveNdg4lkxbxBdgpEh5LKc4Avr+65J9AvCP9FVGCmVXptMnR8m7x B8kKiS2ooTjuusYmEjlbaGLj3uwLKRqY+x+UUCCFwK4e6PX8PeM97CkScJkYv+mQZJqZ b/S4lYWm9HYws7h/fWwfWyD6mFySsZpPmKoxW96CUC0VH0n28mnyP3OEzYu6SlVYjtSi HnXgtd4ErYnedk2c3qh0C88gMWF4FvHvQuR4D+pMjsvNE8+WmTAaqKP9foidtdTd84vE O45UfKJ95u7Hv4Kh9o4/c6aLDGzEPZ2xCe6FCd32KFfu8pjDwCqH2UJ/yd3LT1lB8hOs CDzw==
X-Received: by 10.66.122.101 with SMTP id lr5mr14604386pab.130.1396103962194; Sat, 29 Mar 2014 07:39:22 -0700 (PDT)
MIME-Version: 1.0
Sender: davearonson@gmail.com
Received: by 10.68.211.136 with HTTP; Sat, 29 Mar 2014 07:38:42 -0700 (PDT)
In-Reply-To: <m24n2hcs1o.wl%randy@psg.com>
References: <mailman.1570.1395964793.2468.ietf@ietf.org> <53366F34.8050501@ageispolis.net> <m24n2hcs1o.wl%randy@psg.com>
From: Dave Aronson <ietf2dave@davearonson.com>
Date: Sat, 29 Mar 2014 10:38:42 -0400
X-Google-Sender-Auth: AH5e9Jxi4WGOctZN3Xm9nPm1SGk
Message-ID: <CAHxKQih-ViKw0xSQ0FCvYh-KDqCgnvgH+svp1bnGm1CMEtH-dg@mail.gmail.com>
Subject: Re: SMTP RFC: "MUST NOT" change or delete Received header
To: IETF Discussion <ietf@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: http://mailarchive.ietf.org/arch/msg/ietf/PQ1g11WV3mCriWqZe_oqkvHGjdA
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 29 Mar 2014 14:39:25 -0000

On Sat, Mar 29, 2014 at 4:44 AM, Randy Bush <randy@psg.com> wrote:

> perhaps an apporach would be to limit who can view email headers

Once a malicious actor has the email, how do you propose to limit his
ability to view whatever part of it he pleases?  Maybe add a "Do Not
Look At If You Are Evil" bit on each field?  ;-)

-- 
Dave Aronson, freelance software developer (details @ www.Codosaur.us);
see also www.PullRequestRoulette.com, Blog.Codosaur.us, www.Dare2XL.com