[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

The spoofers have gotten more sophistocated!




The people that have been spoofing Jason Bobier, Philip Zimmerman, and
Randall Framer
have recently become more sophistocated in their techniques. They started
with barely
disguised headers and moved to equally lame PGP signed messages (that
nobody in
their right mind would accept, since the public keys have NO TRUSTED
INTRODUCERS).
Next, they progressed to faking the server-bounce messages to avoid
giveaway headers. For example, they did a very good forgery of a email
message
supposedly coming from PGP, even included the "shival.pgp.com" and
"fusebox.pgp.com"
portions with correct IP addresses and all.
I have a feeling this problem will only get worse....