Re: The vulcan mind melt
Hadmut Danisch <[email protected]> Mon, 27 Oct 2003 22:04:27 +0100
| Newsgroups | gmane.ietf.asrg.rmx |
|---|---|
| Message-ID | <[email protected]> |
On Mon, Oct 27, 2003 at 12:35:00PM -0500, Alan DeKok wrote: > > i.e. The document should discuss reasons, scope, impact, cost, and > changes to the net *before* it goes into technical details about the > solution. The reason is simple: there has been too much controversy > and nonsense on ASRG about the proposals. That controversy MUST be > addressed in the document, or we will end up going through the > nonsense all over again. I fully agree. And I believe we have to learn from what happened on ASRG mailing list and to make our combined proposal "waterproof". Gentlemen: This means we have to question everything and to find a good reason why we do it this way and why we don't do it that way. We will never get there as long as a combined proposal is just the big pot filled with all "Me-too-proposals". We have to have good reasons for what we are doing, not just the kiddish "Don't touch my proposal or I'll touch your's" game. Within the last 1-2 Weeks several technical questions were raised, and, Gentlemen, very few found an answer. Answers to these questions need to go into a combined proposal. I repeat some of the questions: - What exactly do we do with HELO host names, why do we do it, and what do we gain by doing so in context of the subject of Anti-Spam. - Will we do the "simple method", where we just have a simple IP-to-DNS mapping and hope that every company and every private network fits into that scheme and every MTA is able to process it with rule bases or will we do the "meta-record" (as in RMX and SPF) containing a set of authorization records of different types, which would require to extend the capabilities of MTAs. Just to turn the discussion on and to show, that we are still at the beginning: - If we do so, do we stick to DNS, or should we go the slow and "expensive" in network traffic, but more modern way and fetch an XML description from any URL? - Or should we go even further and download some program to be run in a closed environment (like a java applet) which works as a black box and decides whether to accept it or not? Hadmut