mark: A photo of Mark kneeling on top of the Taal Volcano in the Philippines. It was a long hike. (Default)
Mark Smith ([staff profile] mark) wrote in [site community profile] dw_dev 2009-03-14 11:39 pm (UTC)

because it's good to close up the security hole.

It is not a security hole because this feature is entirely by design. Just because it doesn't do what someone expects doesn't mean it is a violation of security or otherwise "bad." Call a fish a fish, don't call it a shark.

a) won't work because users don't read.

d) how will this actually change anything? It's easy to spoof the "From" of an email unless you put some token in the email. And then you're right back where you started: someone forwards it, the receiver spoofs it, and we didn't solve anything.

I prefer B to C, but either would be fine. Except!

Why even bother? This "issue" has been in existence on LJ for years and years and years and ... well, years. And I'm sure it's generated a complaint from time to time, but really? You don't forward emails to your enemies. When you forward a comment mail to a friend, they're not going to do Evil Things In Your Name! (And the only evil they can do is make a comment.)

If you DO forward it to someone who you don't want to have it, then - oh well! You can deal with the fallout from having them say something bad in your name. And then you tell the person they replied to that you're sorry and the problem is solved without spending a ton of development time reimplementing this. :)

Post a comment in response:

If you don't have an account you can create one now.
HTML doesn't work in the subject.
More info about formatting

If you are unable to use this captcha for any reason, please contact us by email at support@dreamwidth.org