Re: static versus dynamic nature of DNS: rate limiting
"Ian Peter" <[email protected]> Mon, 23 Feb 2004 07:28:16 +1000
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <!~!UENERkVCMDkAAQACAAAAAAAAAAAAAAAAABgAAAAAAAAAir8oDSM7nEeU6yNQVTbmpcKAAAAQAAAACYC7wkiuJUC+cdh1zWuvIQEAAAAA@ianpeter.com> |
WhatÂs clear to me is that major benefit will come from some sort of smtp verification scheme being adopted widely, be it lmap or spf or some other variation. What's also clear to me is that we need to act quickly to restore some sort of faith in email as a medium. I wonder if its possible before the IETF meeting to have at least a brief exchange as regards SPF. SPF has gained quite a degree of momentum, and in my mind at least it's best to back winners in situations like this and put some of the other issues aside. Let's leave aside issues of who thought of it first and whether it's proper form to start an initiative like this outside of asrg/ietf, and concentrate only on the technical merits of SPF. We have a good prototype. Does it have major flaws? Are they solvable or unsolvable? Is it worthwhile this group putting its efforts behind SPF? Ian Peter Ian Peter and Associates Pty Ltd P.O. Box 10670 Adelaide St Brisbane 4000 Australia Tel 61 7 3870 1181 Mobile 0419 667772 > -----Original Message----- > From: [email protected] [mailto:[email protected]] > On Behalf Of Patrik Fältström > Sent: Monday, 23 February 2004 6:28 AM > To: Hadmut Danisch > Cc: Yakov Shafranovich; [email protected] > Subject: Re: static versus dynamic nature of DNS: rate limiting > > On 2004-02-22, at 21.19, Hadmut Danisch wrote: > > > On Sun, Feb 22, 2004 at 09:06:34PM +0100, Patrik Fältström wrote: > >> > >> - Given a mail is coming from a peer which the domain owner the mail > >> comes from approves, there are legal and policing mechanisms which can > >> take over > > > > Are you sure? > > > > I do know a lot of countries where nobody would care about > > spammers. Countries which don't put drug dealers into prison > > won't certainly have strong legal mechanisms against spammers. > > > > Maybe you will have such mechanisms in the USA, but how will you > > know whom to sue if you don't know who sent the fedex envelope to > > lease a domain? > > First of all, I live in Sweden, not the US. > > Secondly, I said "can" and meant to use the word to mean "it is then > possible to...". Not that it always will happen. > > But, for example, just see the drastic changes in the EU the last year, > and similar reactions in the US. > > The idea is to create a trail which can be followed. If the authorities > go to a domain name seller to ask "who owns this domain name", and they > can not answer? What do you think the next law will be? Of course > people will be forced to know this in the future, or _they_ (the > registrar) will be the one doing the wrong things. Or, with help of > some whois it will be possible to say "no, I will not trust any domain > name which is registered by this registry" etc. > > All of these things are possible to do in a much better way when "we" > have minimized the risk for false sender addresses, so tracing the > source is easier. > > We need to go down this path. > > paf