Hacker News new | ask | show | jobs
by gommm 5849 days ago
What I'm surprised is why posterous doesn't do more check on all the headers sent by the email software (X-Mailer, and so on) and ask for a confirmation if those other headers are different enough from a known correct configuration...

Of course someone who received an email from the blog owner could use that to fake all those headers but at least it would prevent people posting by simply guessing the email address.

1 comments

Oh, we do that. This was a specific bug that is now fixed.