From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from localhost (localhost [127.0.0.1]) by olra.theworths.org (Postfix) with ESMTP id 98B55431FAF for ; Thu, 2 Aug 2012 00:21:24 -0700 (PDT) X-Virus-Scanned: Debian amavisd-new at olra.theworths.org X-Spam-Flag: NO X-Spam-Score: 0 X-Spam-Level: X-Spam-Status: No, score=0 tagged_above=-999 required=5 tests=[none] autolearn=disabled Received: from olra.theworths.org ([127.0.0.1]) by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bkLzBhrxb49C for ; Thu, 2 Aug 2012 00:21:23 -0700 (PDT) Received: from upsilon.hackadomia.org (upsilon.hackadomia.org [91.121.245.170]) by olra.theworths.org (Postfix) with ESMTP id B519A431FAE for ; Thu, 2 Aug 2012 00:21:23 -0700 (PDT) Received: from usha.takhisis.invalid (unknown [151.36.248.125]) by upsilon.hackadomia.org (Postfix) with ESMTPSA id DC7F3101AA; Thu, 2 Aug 2012 09:21:21 +0200 (CEST) Received: by usha.takhisis.invalid (Postfix, from userid 1000) id 75EAF6806EB; Thu, 2 Aug 2012 09:21:20 +0200 (CEST) Date: Thu, 2 Aug 2012 09:21:20 +0200 From: Stefano Zacchiroli To: Daniel Kahn Gillmor Subject: Re: notmuch-mutt: support for duplicate message removal Message-ID: <20120802072120.GB16678@upsilon.cc> References: <1343808582-9519-1-git-send-email-zack@upsilon.cc> <87pq7aam8n.fsf@nikula.org> <20120801162605.GA6012@sid.nuvreauspam> <50196548.3030504@fifthhorseman.net> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <50196548.3030504@fifthhorseman.net> User-Agent: Mutt/1.5.21 (2010-09-15) Cc: notmuch@notmuchmail.org, Andrei POPESCU X-BeenThere: notmuch@notmuchmail.org X-Mailman-Version: 2.1.13 Precedence: list List-Id: "Use and development of the notmuch mail system." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 02 Aug 2012 07:21:24 -0000 On Wed, Aug 01, 2012 at 01:20:08PM -0400, Daniel Kahn Gillmor wrote: > The proposed feature could also exacerbate the previously-discussed > attack vector [0] whereby a malicious Message-ID collision can be used > to hide messages from the victim's mailstore. > > [0] id:87k42vrqve.fsf@pip.fifthhorseman.net I didn't find the reference above but, if you're speaking about the proposed patch only, I don't think it's the case. The proposed patch only deduplicate file-identical (up to checksums, that is) messages in maildirs: a Message-ID collision is not enough to hide a message. But your comment is very interesting anyhow, as deduplicating on the basis of Message-ID is indeed something I've discussed with Kevin as future work. You just provided an extra argument not to enable that by default. Cheers. -- Stefano Zacchiroli zack@{upsilon.cc,pps.jussieu.fr,debian.org} . o . Maître de conférences ...... http://upsilon.cc/zack ...... . . o Debian Project Leader ....... @zack on identi.ca ....... o o o « the first rule of tautology club is the first rule of tautology club »