2751
General Software Discussion / Re: Fake Reviews: Amazon's Rotten Core
« Last post by Stoic Joker on August 29, 2012, 01:24 PM »I don't see why every stage of the journey would need to be different to now - you could leave the certificate verification to the last leg of the journey...-Carol Haynes (August 29, 2012, 11:56 AM)
Because the only time you can verify the sender is when something is sent. Otherwise you're just getting the MITM's version of who the sender is/was/should have been. Which would most likely make it easier to spoof because the servers would be tied up focusing on a cert instead of the rest of the message header.
The SPF (Sender Policy Framework) was supposed to be a cure for server validation ... it just never got off the ground. Because as simple as it is ... It's still too friggin complicated for fried admins to get setup right ... So they just declaw the thing and move on.

Recent Posts
)

... But I gotta make peace with 8 on my laptop first.