asrg-7----Page:6
1
2
3
4
5
6
7
8
9
10
Problem – Email Insecure by Default
Downgrade attack
I can tell a signed message comes from the sender
I cannot assume an unsigned message is false
Key is to know the security policy of the domain
PPT Version