[unisog] Good spam forgery getting me.

Russell Fulton r.fulton at auckland.ac.nz
Thu Dec 16 20:09:57 GMT 2004

On Thu, 2004-12-16 at 12:35 -0600, PaulFM wrote:

> I think spammers/virus-writers are doing everything they can to make their 
> mail look legit. Even if it doesn't get them by filters now - it cuts down on 
> items that a filter could use to decide something is spam.

It also renders services like spamcop less effective since this makes it
very difficult for automated systems to detect which system is the real
source of the spam.

The only way to combat this sort of trickery is by using crypto to
verify that the message really did pass though the MTA as claimed.
(signature based on PK encryption of message ID?  No I'm not advocating
this! It would probably create more problems than it solves)

The only surprising thing in this development is that it has taken them
this long to do it.  Sigh...

Russell Fulton, Information Security Officer, The University of Auckland
New Zealand

