--- /dev/null
+Return-Path: <novalazy@gmail.com>\r
+X-Original-To: notmuch@notmuchmail.org\r
+Delivered-To: notmuch@notmuchmail.org\r
+Received: from localhost (localhost [127.0.0.1])\r
+ by olra.theworths.org (Postfix) with ESMTP id 709BF431FBC\r
+ for <notmuch@notmuchmail.org>; Mon, 29 Oct 2012 04:15:23 -0700 (PDT)\r
+X-Virus-Scanned: Debian amavisd-new at olra.theworths.org\r
+X-Spam-Flag: NO\r
+X-Spam-Score: -0.799\r
+X-Spam-Level: \r
+X-Spam-Status: No, score=-0.799 tagged_above=-999 required=5\r
+ tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1,\r
+ FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7] autolearn=disabled\r
+Received: from olra.theworths.org ([127.0.0.1])\r
+ by localhost (olra.theworths.org [127.0.0.1]) (amavisd-new, port 10024)\r
+ with ESMTP id IXRRbxqq3ZYE for <notmuch@notmuchmail.org>;\r
+ Mon, 29 Oct 2012 04:15:23 -0700 (PDT)\r
+Received: from mail-pb0-f53.google.com (mail-pb0-f53.google.com\r
+ [209.85.160.53]) (using TLSv1 with cipher RC4-SHA (128/128 bits))\r
+ (No client certificate requested)\r
+ by olra.theworths.org (Postfix) with ESMTPS id E5E0C431FAF\r
+ for <notmuch@notmuchmail.org>; Mon, 29 Oct 2012 04:15:22 -0700 (PDT)\r
+Received: by mail-pb0-f53.google.com with SMTP id wz12so4497427pbc.26\r
+ for <notmuch@notmuchmail.org>; Mon, 29 Oct 2012 04:15:22 -0700 (PDT)\r
+DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;\r
+ h=date:message-id:from:to:subject:in-reply-to:references:mime-version\r
+ :content-type:content-disposition:content-transfer-encoding;\r
+ bh=mVwvvV/gvenCQk7iV3MpRPXYs6XCSh12JcvRv5YsHVg=;\r
+ b=qv/laTObkN+vHTeOiH8/mzcRKLwY1M1a6dLlzvKXqFzdKIhFwa6hdn3wlodW4FnuKz\r
+ iIzLLLLBZO/eIDbS6mg0Gfeas/6n4VR3bFP4ljcpTmqnD/a1YTgJ2R6wiMeiES3izF1W\r
+ 5YfIxUwlXtz08xxaPL0uRvLfSX9i5sIF+Tr9y6BEehjWZz+LCNJEazKtZzcE441ghWSa\r
+ bLLgur1ipfHx78AuNfWl+81K2CqVo/dKvSLttKZ1Td1zSlF1H8IP5OcPTJn2Dm97Z2uz\r
+ KxnE1HwPjP5MJSrZqvclmcrYUokFfnftL4+/Olf51Hp6q5xoP9vonXWqlT2w74lfykpr\r
+ geYA==\r
+Received: by 10.68.233.230 with SMTP id tz6mr91579591pbc.36.1351509322068;\r
+ Mon, 29 Oct 2012 04:15:22 -0700 (PDT)\r
+Received: from localhost (215.42.233.220.static.exetel.com.au.\r
+ [220.233.42.215])\r
+ by mx.google.com with ESMTPS id bf6sm5807644pab.3.2012.10.29.04.15.19\r
+ (version=TLSv1/SSLv3 cipher=OTHER);\r
+ Mon, 29 Oct 2012 04:15:20 -0700 (PDT)\r
+Date: Mon, 29 Oct 2012 22:15:16 +1100\r
+Message-ID: <20121029221516.GB20292@hili.localdomain>\r
+From: Peter Wang <novalazy@gmail.com>\r
+To: notmuch mailing list <notmuch@notmuchmail.org>\r
+Subject: Re: a DoS vulnerability associated with conflated Message-IDs?\r
+In-Reply-To: <87k42vrqve.fsf@pip.fifthhorseman.net>\r
+References: <87k42vrqve.fsf@pip.fifthhorseman.net>\r
+MIME-Version: 1.0\r
+Content-Type: text/plain; charset=utf-8\r
+Content-Disposition: inline\r
+Content-Transfer-Encoding: 8bit\r
+X-BeenThere: notmuch@notmuchmail.org\r
+X-Mailman-Version: 2.1.13\r
+Precedence: list\r
+List-Id: "Use and development of the notmuch mail system."\r
+ <notmuch.notmuchmail.org>\r
+List-Unsubscribe: <http://notmuchmail.org/mailman/options/notmuch>,\r
+ <mailto:notmuch-request@notmuchmail.org?subject=unsubscribe>\r
+List-Archive: <http://notmuchmail.org/pipermail/notmuch>\r
+List-Post: <mailto:notmuch@notmuchmail.org>\r
+List-Help: <mailto:notmuch-request@notmuchmail.org?subject=help>\r
+List-Subscribe: <http://notmuchmail.org/mailman/listinfo/notmuch>,\r
+ <mailto:notmuch-request@notmuchmail.org?subject=subscribe>\r
+X-List-Received-Date: Mon, 29 Oct 2012 11:15:23 -0000\r
+\r
+On Thu, 08 Mar 2012 11:37:09 -0500, Daniel Kahn Gillmor <dkg@fifthhorseman.net> wrote:\r
+> notmuch currently treats all messages with the same Message-ID as\r
+> the same message. I think this could be a vulnerability :(\r
+> \r
+> If two messages have the same Message-ID, is there a guarantee of which\r
+> of these messages will be produced during a notmuch show?\r
+> \r
+> Either way, it seems to create a potential DoS attack on notmuch users.\r
+\r
+Yesterday I was expecting a confirmation message which, seemingly, never\r
+came. It turns out my maildir already contained a message from the\r
+same system. From three years ago. With the same Message-ID.\r
+\r
+Malice has nothing on incompetence.\r
+\r
+Could we distinguish messages with identical Message-IDs based on\r
+some header fields, e.g. Date, From?\r
+\r
+Peter\r