Re: Realisticness of header rearrangement

"Mark E. Mallett" <[email protected]> Tue, 6 Apr 2004 11:41:29 -0400
Newsgroups gmane.ietf.asrg.filtering
Message-ID <[email protected]>
On Tue, Apr 06, 2004 at 12:26:26PM +1000, Laird Breyer wrote:
> On Apr 05 2004, Mark E. Mallett wrote:
> 
> > I see "Received" as an overlapping set of information not necessarily
> > tied to the filter-produced headers.  There should be enough
> > information in the filter-generated headers to uniquely identify the
> > locus of operation of the filter.
> 
> Bear in mind that the spammer can easily obtain email samples
> containing information such as: all the names of spam filters passed
> through, all the names and IP addresses of the machines used during
> delivery.
> 
> For example, suppose the spammer wants to spam yahoo users. He gets an
> couple of yahoo accounts himself, sends some messages to himself, and
> looks at the message headers after delivery. Now he knows exactly which spam
> filters yahoo is currently using, what the names and IP addresses of
> the relaying MTAs are, etc. 
> 
> All of this information can now potentially be used, when he starts sending
> messages to other yahoo users. Moreover, he can use his own account to 
> debug his spam message structure.

My perspective is that the filter markings (a la "Tagged") are for
historical record only.  A filter consumer (e.g. the MUA that uses the
output of a filter) can only trust the ones inserted locally and
shouldn't be relying on these historical tags.  As I mentioned before,
I would want the filter consumer to operate on fixed tags that are
produced by the local filter suite, and *not* on the archival tags
such as the "Tagged" record.  I am not really sure what all the fuss
is about trying to rely on filter output placed by filters that aren't
yours (in some extended interpretation of "yours").  I'm interested in
those historical tags only to see what's been done to the message by
agents handling it along the way:  not to trust that information in
any way but simply to have access to that record to see (for example)
what transformations have occured on the message or (for another) what
filters are being employed up the line.  How much weight you give to
each such mark is up to you and up to your environment and is
analagous to how much weight you give to "Received" lines.  A simple
counter works just fine for backtracking through these.

So: if yahoo user wants to filter based on fixed-format (non-archival)
tags inserted at yahoo, the user does so.  yahoo makes sure that it
erases all such tags before inserting new ones.  Analogize for any
other environment.  This has no impact on any of the "Tagged" lines
currently in the header, forged or otherwise.

I just don't see the point of finding ways to trust filters outside
your own domain of control.  Inside your own domain of control, you
don't use the historical-format tags for anything other than, well, a
history.  For interpreting the result of your local filter(s) you use
fixed tags that are erased and then regenerated.

mm