Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>Right now you can forge email from any email address you can verify ownership.

how can you "forge" something if you verify ownership? when you own something, it's not "forging" to use it.

i think the point you're trying to get at is that the mail might fail dmarc requirements?



Because ownership can change. I can still use Gmail to send email from my old university address that I lost access to 15+ years ago. This should not be possible.


if the mail from that address is being delivered to mailboxes, that's your universities fault.

if it's not (i.e. spf & dkim is failing), that's just how email works and is not unique to gmail.


Cool try explaining any of these terms to the average sysadmin.

Email security is hopelessly broken, and the best you can do is try to limit exposure. Removing Gmail as an attack vector is one of those decisions.


>Cool try explaining any of these terms to the average sysadmin.

if someone is managing a mail system and doesn't know what spf is, they should be immediately fired.

i am also not convinced this will remove or limit exposure to anything. the attack vector lives in the protocol, not the service used.

this might end up as a tiny, tiny blip in some small percentage of spammer/phisher operations.


Yep, SMTP itself doesn't have any security.

Anyone else remember the open SMTP relays of the 90's?


One could use aol's smtp servers to send mail as clinton@whitehouse.gov




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: