That much trouble?
Posted Sep 6, 2004 10:41 UTC (Mon) by
khim (subscriber, #9252)
In reply to:
That much trouble? by ametlwn
Parent article:
Debian rejects Sender ID
The fact is: with PGP you know who to trust and wuth SPF you do not. You trust some random DNS server - and there are literally thousands of points where you can add your server without much checking. SPF is designed with the stupid idea in mind: you should trust any server with valid SPF information. That's absurd. PGP, on the other hand is designed to live in hostile environment: it's not enough to have valid PGP signature in mail. You somehow should be in trustpath.
Plus you need to sign each and every outgoing mail - just add requirement to sign From: and To: lines as well and voila - great strain for initial sender (==spammer). Relay do not change signature at all so they are not affected.
(
Log in to post comments)