The From header has always been spoofable. It's just most ISPs (and Google) chose to disallow it to address low-hanging fruit in the fight against spam.
But anyone can set up their own postfix/qmail/sendmail server and put anything they want as the From.
Or am I misunderstanding the issue here?