Re: users with vanity domains

Raymond S Brand <[email protected]> Tue, 14 Oct 2003 14:06:39 -0400
Newsgroups gmane.ietf.asrg.rmx
Message-ID <[email protected]>
Alan DeKok wrote:
> 
> Raymond S Brand <[email protected]> wrote:
> > It's also why I created the ``provider delegations'' in the MVP proposal.
> > But the argument that Alan seems to be using in this thread is that mobile
> > users want to be able to send from anywhere AND protect their domain name
> > from forgery at the same time.
> 
>   From "some" forgery.  A graduated scale of protection would be
> useful.
> 
>   e.g. someone who roams a lot should be able to permanently say "my
> MTA, or the MTA of ISP X".  ISP X can then forge email from the users
> domain, but for the most part, who cares?  There are enough ISP's and
> domains that the odds of forgery succeeding are fairly low.  And any
> spammer who tries a dictionary attack will quickly be recognized by
> source IP, and filtered that way.
> 
>   Someone who roams occasionally can use dynamic DNS to narrow the
> time window for possible forgery.

With the delegation scheme, the domain name owner is able to specify
which IP addresses are OK (dynamic DNS) and can specify one or more ISP
server pools as OK also. But it requires the domain name owner to
actively manage it.

The vocal roaming users you referred to seem to want to send from any
IP address AND protect their domain name AND not have to manage the
delegations; they need to pick 2.

> > None of the RMX/DMP/SPF/Vixie/DRIP/MVP proposals achieve that. That
> > WILL require cryptographically signed messages to achieve,
> 
>   Which I would prefer to leave outside of the scope of this group.

I agree.


Raymond S Brand