Re: users with vanity domains

"Alan DeKok" <[email protected]> Thu, 09 Oct 2003 11:17:38 -0400
Newsgroups gmane.ietf.asrg.rmx
Message-ID <[email protected]>
Raymond S Brand <[email protected]> wrote:
> It's also why I created the ``provider delegations'' in the MVP proposal.
> But the argument that Alan seems to be using in this thread is that mobile
> users want to be able to send from anywhere AND protect their domain name
> from forgery at the same time.

  From "some" forgery.  A graduated scale of protection would be
useful.

  e.g. someone who roams a lot should be able to permanently say "my
MTA, or the MTA of ISP X".  ISP X can then forge email from the users
domain, but for the most part, who cares?  There are enough ISP's and
domains that the odds of forgery succeeding are fairly low.  And any
spammer who tries a dictionary attack will quickly be recognized by
source IP, and filtered that way.

  Someone who roams occasionally can use dynamic DNS to narrow the
time window for possible forgery.

> None of the RMX/DMP/SPF/Vixie/DRIP/MVP proposals achieve that. That
> WILL require cryptographically signed messages to achieve,

  Which I would prefer to leave outside of the scope of this group.

  Alan DeKok.