home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!mcsun!ub4b!news.cs.kuleuven.ac.be!blekul11!frmop11!dearn!esoc!kkeyte
- Organisation: European Space Operation Centre (E.S.O.C)
- Date: Wednesday, 29 Jul 1992 09:25:48 CET
- From: Karl Keyte <KKEYTE@ESOC.BITNET>
- Message-ID: <92211.092548KKEYTE@ESOC.BITNET>
- Newsgroups: comp.protocols.tcp-ip
- Subject: Re: SMTP mail
- References: <92209.190519KKEYTE@ESOC.BITNET>
- <1992Jul29.021534.6708@mp.cs.niu.edu>
- Lines: 25
-
- 14rticle <1992Jul29.021534.6708@mp.cs.niu.edu>, rickert@mp.cs.niu.edu (Neil
- Rickert) says:
- >
- >In article <92209.190519KKEYTE@ESOC.BITNET> Karl Keyte <KKEYTE@ESOC.BITNET>
- >writes:
- >>
- >>The SMTP has recently been removed at our site because of its well-known
- >>security hole.
- >
- > Would you like to enlighten us as to the nature of this "well known
- >security hole".
- >
- > It is well known that email can be forged. Most people don't consider
- >this a security problem, although it may present an identification
- >problem. If you consider email forgery a security hole, then I presume
- >you have also shut off all paper mail, which can just as easily be
- >forged.
- >
-
- & that's not a security hole? It is if you want to believe mail that you
- receive. Paper mail is usually signed. The point is, SMTP is stupidly
- simple (as we all know) in it's "authentication". My question still
- stands.
-
- Karl
-