-----BEGIN PGP SIGNED MESSAGE-----
>>>>> "TD" == Teresa Downey <Teresa.Downey@SLAC.Stanford.EDU> writes:
TD> This seems pretty weak security.
It was never intended to be "secure".
[...]
TD> I cannot turn off EXPN here since that would cause us to lose
TD> potential forgery alerts for ALL email.
A bogus argument. EXPN and VRFY are not used exclusively by spammers. In
fact, I have used it on a number of occasions to find the identity of a
spammer.
-----BEGIN PGP SIGNATURE-----
Version: 4.0 Business Edition
Charset: noconv
iQCVAwUBNIxWKp6VRH7BJMxHAQHimAP/UMTG8WCiePPU65BpsY9hIfR5MKTYKWih
gOXgzTlsqLemRK9YY0RVeqcB/wASf0dJgs3+keS1Q2tGZp6T2bZ+QjEqamTG07mh
9JktNz3Ljoanh3Jjg8l/MD30SDXW2eNcGSW0wgGYX2aXWts+TLDTf6Od3e4ovOJi
6w5Cs6O9l4k=
=ve7B
-----END PGP SIGNATURE-----
--
Rich Pieri <rich.pieri@prescienttech.com> / Caution: Happy Fun Ball may
Sysmonster, Unix Wrangler / suddenly accelerate to dangerous
Prescient Technologies, Inc. / speeds.
I speak for myself, not PTI or SWEC /
References:
|
|