>> I added a couple of tickets for the various DHCP RFC that I reviewed when >> writing the DHCP draft. What is the process for picking new RFC to review? >> Just pick one at random and write a provisional ticket in >> https://trac.tools.ietf.org/group/ppm-legacy-review/wiki ? >> > > essentially, yes.
I have written a few more tickets, so the list is not so empty... I was going to enter a few comments on RFC 2821, but I wonder whether we already have some WG dealing with SMTP. There are basically three issue: the "transport in clear text" issues, the "ease of spoofing" issue, and the "too much information" issue. I assume that the transport issues are addressed by the current TLS effort. I don't know whether anyone is working on the "ease of spoofing" issue, which is known to be abused for "spear phishing" and other fun exercises. And I also don't know whether anyone is looking at information minimization, e.g. not carrying the "private" IP address of a user in the Received list, or not exposing a full list of message recipients to all relays. -- Christian Huitema _______________________________________________ ietf-privacy mailing list [email protected] https://www.ietf.org/mailman/listinfo/ietf-privacy
