redtiger7 opened this issue on May 21, 2008 ยท 28 posts
Penguinisto posted Fri, 23 May 2008 at 5:59 PM
Just one objection, spoken for security's sake:
Quote - Our emails are sent from noreply@contentparadise.com if you would like to verify real offers.
Frankly, people would be better off verifying the offer (and transacting it) on the SM website, and you (Smith Micro) should seriously avoid saying otherwise. You would be amazed at how drop-easy it is to fake a From: line in email (Google for "Joe Job" as a good parallel), as well as faking links within the message (a bit more complex to explain, but not hard at all to set up, esp. if the parodied website is susceptible to SQL injection attacks).
Don't believe me? Ask Bank of America - they see thousands of these attempts-via-spam each day... most of them amateur jobs, but at least one or two a week (on average) are very, very convincingly real-looking, right down to the real email reply addy in the "from" line.
So... unless everyone in here can competently read SMTP header files, I'd suggest that you (Smith Micro) avoid telling them that the "from" line is okay if it says such-and-such. Please, for the safety of folks who may not be conversant in IT matters, and for the sake of your own company's credibility... stop doing that.
Thx,
/P