3 ms·
If they use SMTP, they run the risk of a compromised server sending spam through them. With the API, it makes it a bit more difficult for a compromised machine
by devicenull 16y ago
If they use SMTP, they run the risk of a compromised server sending spam through them. With the API, it makes it a bit more difficult for a compromised machine to start spamming, unless it already has API keys for this service.
- pilif 16y agoNothing prevents them from requiring SMTP-Auth for authentication to make sure that the sending is coupled to a specific account. If we are talking compromised machines, then the key would be compromised as well at which point a spammer can use that key to send spam regardless of protocol. I'm not saying to use smtp auth with your amazon username and password, but with some token derived from the API key, but just SMTP.
- dalore 16y agoExcept they already have auth setup for all their other webservices. Why not make email yet another service and the auth infrastructure is already there.
- taylorbuley 16y agoMakes sense to me. Those gradual rate increases show they're pretty wary of the spammer threat.
- rst 16y agoUnless the compromised server already has sendmail or postfix configured to use Amazon's perl script as a transport (according to the directions in Amazon's own help files). In that case, the attacker doesn't have to even bother looking around for the API keys --- everything's already set up.
- xilun0 16y agopurely security by proprietary obfuscation? clueless.