Re: users with vanity domains

Raymond S Brand <[email protected]> Tue, 14 Oct 2003 13:53:37 -0400
Newsgroups gmane.ietf.asrg.rmx
Message-ID <[email protected]>
Hadmut Danisch wrote:
> 
> On Wed, Oct 08, 2003 at 05:02:27PM -0400, Raymond S Brand wrote:
> >
> > It's also why I created the ``provider delegations'' in the MVP proposal.
> > But the argument that Alan seems to be using in this thread is that mobile
> > users want to be able to send from anywhere AND protect their domain name
> > from forgery at the same time. None of the RMX/DMP/SPF/Vixie/DRIP/MVP
> > proposals achieve that. That WILL require cryptographically signed messages
> > to achieve, and I think that's where email is going in the long term due
> > to the forgery issues.
> 
> Wrong. RMX explicitely addresses and solves the problem of these
> mobile users since the 02 version of the RMX draft.

I just checked the 03 draft and didn't see how RMX solves the problem. What
section is the solution in. I did find discussion of the problem and the
suggestion the the POP server could be used for outbound mail but that isn't
part of the RMX proposal.

> The latest version (submitted yesterday) also covers cryptographically
> signed messages (currently experimental) and challenge response
> authentication, but still has a subchapter why cryptography can't
> solve the problem in common.

The are other methods to employ cryptographically signed messages that do
not encumber every user and is scalable. However, all domain name based
cryptographic suffer from the "throw away domain problem".

> But this is one of the main reasons why I do believe that we need
> a client library with some intelligence and cannot use just primitive
> DNS querying through rewriting rules.

Any standard that is so complicated that we need to supply a client
library so that sites will implement it, is not likely to be implemented
at enough sites to be useful.


Raymond S Brand