RE: The gap

"Gordon Fecyk - Home" <[email protected]> Fri, 3 Oct 2003 11:36:16 -0500
Newsgroups gmane.ietf.asrg.rmx
Message-ID <[email protected]>
> Imagine we have such a mechanism to verify the
> sender address or its domain part based on information given
> in this domain's zone table, and the whole world has adopted
> the mechanism. Will this stop spam? No. It will change the
> flavour of spam. Spam will not come from @hotmail.com, @yahoo.com,
> @microsoft.com, but from domains like @example123.xy , and the
> authorization records will cover the sender, thus making the
> mechanism accept the mail.

That's likely because the most common spam today forges the sender.  When
forgeries become tougher, spammers will resort to other (and presumably more
expensive) ways to send their spam.  It costs nothing to falsify e-mail, but
it costs resources to set up one's own domain and administer it, until the
registrar or DNS host nukes it (or they get nuked).

I don't know if registrars will take responsibility for the behaviour of
their customers once spammers are forced to use their own domains.  CIRA
does so, but they're but one in a whole mess of garbage registrars.  Network
Solutions is requiring domain owners to provide valid contact info in
accordance with some recent ICANN agreement or something.

Blacklisting would likely shift to per-domain models.  I can see it now:

evil-spammer.com.dns-based-list.example.com. A 127.0.0.2

Not to mention all the legally actionable stuff brought up by this.  But I'm
not a lawyer.

> Since this is still a weak point of all our proposals, we should
> at least think about this.
>
> Our mechanism as the first link of the chain would solve many,
> but not all problems needed to get rid off to cope with spam.

It would introduce "new" problems certainly, for the spammers as well as for
us.  I took the Accountability approach, and have since 1998.  Spammers
don't like being accountable.

As for approaching ICANN on stuff, any proposal to ICANN or whoever to force
behavioural changes isn't likely to work without some selfish benefit to
ICANN or its members.

--
PGP key (0x0AFA039E): <http://www.pan-am.ca/[email protected]>
What's a PGP Key?  See <http://www.pan-am.ca/free.html>
GOD BLESS AMER, er, THE INTERNET. <http://vmyths.com/rant.cfm?id=401&page=4>