4 ms·
This security hole is now fixed. We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that R
by convel 16y ago
This security hole is now fixed.
We had a specific problem with the way we dealt with SPF records. Dustin didn't set any up, and there was a specific way that Robin Duckett's email server responded that caused us to flag it as a false negative for spoofing.
http://news.ycombinator.com/item?id=1443143 http://news.ycombinator.com/item?id=1443143
- MichaelApproved 16y agoWhat keeps someone else behind the same smtp server from spoofing an email?
- _delirium 16y agoA lot of SMTP servers implementing SMTP AUTH will add an annotation "(Authenticated sender: localusername)" or similar, which will let you distinguish between different users of the same mail server, even when they spoof the From: header. Not sure if that's the solution Posterous is using, or how widespread it is, though.