GPG PGP S/Mime vulnerability

Julia A. Case
Wed Aug 8 16:38:02 2001

Quoting Guy Van Sanden

> Again, you are right about that, but the currently proposed
> legistation would put responsability with the customer.
> The point is, that if the signatures would incorporate the
> message-headers, they would provide better security...
Headers change on the server too often, I even change headers where delivering email on the server (as part of anti-spam handling we add certain headers to indicate the likelyhood of it being spam so that an email client can sort on those headers)... This doesn't seem like it would work well to me.

Julia