Re: Fwd: Re: mailing list question

Chris Fox <[email protected]> Tue, 29 Apr 2014 10:10:30 +0100
Newsgroups gmane.comp.ai.prolog.swi
Message-ID <[email protected]>
On 2014-04-28 21:12, Jan Wielemaker wrote:
> I'm getting pretty confused :-(  To summarize what I picked up:
> 
>   - Over the past couple of weeks, more than 100 people have been 
> removed
>     from the list and more follow every day.  That is clearly 
> unacceptable.
> 
>   - It seems that none of the work-arounds is nice.  The most promising 
> I've
>     seen is mailman's 2.1.16's plugin, which Chris claims is so ugly 
> he'd
>     consider unsubscribing.  I understand it is ugly, but is it also
>     ugly to the users, or merely one of these things no sane computer
>     scientist should want, but that `kind of works'?


IMHO the work-around provided by the plugin (and the latest version of 
Mailman) are ugly for the user, as they rewrite the From address. There 
is supposed to be another trick along the lines of having an empty From 
addresses, and relying on Sender instead. This breaks RFCs (and might 
not work well for some email software, not all MUAs show the Sender 
line), but then so does DMARC (which does not work for many usage 
scenarios). Another work around I have seen is to not check DMARC for 
incoming email, and set a DMARC policy of "none". But I don't know the 
precise details, and suspect it does not work for the Yahoo case.

According to discussions on IETF lists and elsewhere, DMARC was never 
supposed to be used like this. Everyone assumed that no sane 
organisation would set or enforce a strict reject policy as a matter of 
routine. Unfortunately it seems some email providers are "too big to 
block", and can in effect exploit DMARC to gain a competitive advantage 
(reminds me somewhat of secure UEFI boot), off-loading the pain and cost 
of DMARC failures on independent mailing lists and email servers, making 
it cheaper to switch to one of these too-big-to-block companies, as with 
the proposal to move to Google Groups.

DMARC is also problematic in that there are privacy issues related to 
forensic reporting (it is possible that some DMARC policies would be 
illegal in some jurisdiction). There has been a suggestion on IETF lists 
about declaring DMARC to be deprecated -- even before it has an RFC -- 
like ADSP before it, which also broke email in a similar way.  As of 
this month, IETF have the power to fix or deprecate DMARC, now that the 
DMARC consortium has handed management of the specification over to 
IETF, whose mailing lists it also breaks.

There are various discussions about what to do to fix or work-around 
this broken non-standard on the IETF DMARC list and ietf-822 list. (It 
is unfortunate that a number of big-players have jumped the gun and 
implemented something that has not yet been properly analysed, let-alone 
standardised. Perhaps they thought that handing the proposal over to 
IETF was enough to make it a standard.)

Chris


-- 
Dr Chris Fox  <[email protected]>   http://Chris.FoxEarth.org
Reader in Computer Science,  University of Essex, CO4 3SQ, UK
Tel: +44 (0)1206 87 2576 | GnuPG: 1024D/488F6C2A | QRA: M0PXZ