logoalt Hacker News

shadowgovtyesterday at 6:26 PM1 replyview on HN

Most of the time, in my experience, when one encounters a situation like this in Internet tech (i.e. "why is this suggestion treated like a hard requirement?"), this is the answer: "because attackers found a way to exploit the lack of the suggestion's implementation in the wild, so it is now a hard requirement."

The standards, to my observation, tend to lag the CVEs.

Side-note: If someone has built a reverse-database that annotates RFCs with overriding CVEs that have invalidated or rendered harmful part of the spec, I'd love to put that in my toolbox. It'd be nice-to-have in the extreme if it hasn't been created yet.


Replies

atherton94027yesterday at 6:41 PM

How is not having a message-id a security risk? It seems that Gmail is being pedantic for no reason

show 2 replies