Entry tags:
I'll type slowly so you can understand.
- Email is flawed.
- You can trivially forge an email from dork@example.com and by and large you'll get away with it.
- Various things are being done in an attempt to combat this, but the problem exists, and we have to live with it for now.
- When a spammer forges mail in this way, anything that treats the origin address as authoritative will not in any way affect the spammer.
- This includes your stupid challenge/response system.
- Instead, you will annoy the owner of the forged domain.
- This person most likely already has their hands full dealing with genuine spam, to say nothing of bounce messages (which are an automatic part of the email system, and can not as such be dispensed with).
- You are adding to this person's daily intake of useless crap.
- As one of these people, I am rapidly approaching the point at which I will set up an automated filter to approve spam to your mailbox.
- This should be considered fair warning.
- CHALLENGE/RESPONSE SPAM PROTECTION IS A BURDEN ON OTHERS. STOP USING IT.
no subject
no subject
no subject
However, because outgoing and incoming email are COMPLETELY SEPARATE (a fact I had a fun time explaining to the old-time BBSers), making that kind of thing actually work is, um, an interesting technical challenge. As far as I can tell, most challenge/response systems in actual use would fail if they encountered another instance of themselves.