Re: The vulcan mind melt

Meng Weng Wong <[email protected]> Sun, 26 Oct 2003 18:18:32 -0500
Newsgroups gmane.ietf.asrg.rmx
Message-ID <[email protected]>
On Sun, Oct 26, 2003 at 05:40:27PM -0500, Yakov Shafranovich wrote:
|  The IETF is more likely to approve one combined proposal than a score
| of competing proposals.

My primary desire is to see a specification which
1) can be easily adopted by the majority of internet ISPs and domains
2) once adopted, will immediately begin to reduce spam, worms, and viruses.

To that end, I have reviewed all the existing designated sender
proposals, considered each of their strong and weak points, attempted to
gauge ISP response to each feature to the best of my ability, and
drafted a proposal, keeping in mind the considerations listed at
http://www.ietf.org/internet-drafts/draft-crocker-spam-techconsider-02.txt

I have also produced working code that implements the specification, and
invited other people to alpha-test it either on the publisher or the
client end.  The spec has appealed to a number of people; independent
contributors have written patches to MTAs, Milter plugins, and a web
validator.  (see http://www.dnsstuff.com/pages/testbed.htm)

| A joint proposal from all of the parties present, one document,
| not seven separate ones is what is needed from this subgroup.

I am sure that the other authors share both desires (1) and (2), but
differ in the details; for example, I believe that DNS admins will
prefer a single-line TXT config, whereas other authors believe that a
reversed-IP notation is technically superior; these differences are
founded on assumptions about caching, total lookup cost, and other
factors.  Other differences of opinion are based on personal experience.

I have tried to minimize personal bias by asking for input from the
active community of 200 subscribers on the SPF mailing list about how
different alternatives might fare in the real world, and by providing
more than one way to do things; some ways may be appropriate to small
domains, and others may be preferred by large domains.

Over the past three months, the SPF project has struggled up a learning
curve and in the process reached consensus on a number of design
decisions which are only being raised and debated now in this forum.  A
fair number of technically qualified people have recently reviewed the
SPF draft and given their comments and approval.

My concern with the ASRG process is that it will result in a technical
specification very similar to, but slightly incompatible with, what SPF
has developed so far; and that it will do so three months from now, when
spam has cost the email industry hundreds of thousands more dollars in
bandwidth and user goodwill.

I have suggested several times that the SPF draft be used as the basis
for a combined proposal, and offered front-page authorship to Hadmut and
Gordon, whose ideas it embraces and extends.  If you see technical
defects in the proposal, I would like to hear what they are.  If it
lacks something you would like to put in, I would like to know what.  If
the entire approach is, in your mind, incorrect, I would like to hear
that also, so I can know whether the overall consensus on this list runs
for or against the whole thing.

Ultimately the market will decide which standard to adopt.  The ASRG
community is perhaps not a valid sample of the ISP market, but it is the
closest thing available to us.  If "market testing" using ASRG can be
used to nip problems in the bud, that may save us some time.