Re: Moving forward ...

Laird Breyer <[email protected]> Fri, 27 Feb 2004 12:10:34 +1000
Newsgroups gmane.ietf.asrg.filtering
Message-ID <20040227021033.GD1618@ender>
On Feb 26 2004, Craig Hughes wrote:
> There are likely certain cases where "tampering" with the message to 
> modify it for the downstream is actually desirable though.  For 
> example, removing viruses or other potentially damaging payload, 
> defanging nasty MIME bits, etc.  I agree that generally you don't want 
> to change things too much for the downstream folks, but on the other 
> hand, sometimes you know there's a potential problem if you let things 
> go through w/out rewriting them.

To my current way of thinking, this isn't much of an issue. I'm happy
to accept that agents anywhere along the mail delivery path may elect
to remove an email, or say "replace" it with a notice that the email
is suspect and can be picked up in a quarantine zone. 

In this sort of case, filtering software is not likely to see 
tampered messages. For example, with a notice, the system may elect
not to learn the notice message at all, or to do whatever the user
decides. 

What concerns me is filters which directly modify messages in ways
which cannot be detected. Say I add an URL in the body, and clearly
mark it as MySpamFilter-Convenience-Url. Any filter which has never
heard of MySpamFilter won't know that it's not part of the
message. Because it's always the same added description, it likely
will quickly become a strong indicator for such a filter. When changes
occur (ie MySpamFilter is removed), the repercussions could be
dramatic for a while. In the long run of course, downstream filters
would be expected to adapt regardless.

-- 
Laird Breyer.