Posterous really does fail here. I can see why they would want to tolerate a little of this to preserve ease of use for their users (just like Amazon with their Kindle email address). However, there are a number of steps that Posterous can take to combat forged headers in ways that should not impact users at all. Enabling SPF, for example, would be a good start. Technically, it's the same problem as email spam, and m…
> "The other fix would be to use an email address that can't be guessed from the blog address. In other words, the email address is the password." You'd still be sending your password in the clear, possibly through other peoples mail servers. Not great security.
There is a trade-off here between security and usability. 99% security is good enough for a lot of purposes and has its place.