TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Arc (Authenticated Received Chain) is useless. Prove me wrong

1 点作者 cx42net超过 1 年前
This is something I&#x27;ve been wanting to talk about for a while.<p>I run an email forwarding service (ImprovMX.com) and at first glance, ARC might seem like a good idea when forwarding an email. When ARC signing an email, ImprovMX would tell to the next hop what was the situation about SPF, DKIM and DMARC even if that has changed now (like breaking SPF, which happens when forwarding an email).<p>BUT this relies on trusting the one creating the ARC signature.<p>And for me, this is bad.<p>What does trusting mean? In this specific case, it would mean having a list of trusted authorities (Google, Microsoft, AWS, etc) that we can trust, but be cautious with all the others?<p>Heck no! As this would mean a two-way internet, where the big ones have even bigger power, and new, emerging or small ones have no power.<p>&gt; ARC serves the big ones only.<p>Am I wrong?

暂无评论

暂无评论