Re: static versus dynamic nature of DNS: rate limiting

Patrik Fältström <[email protected]> Mon, 23 Feb 2004 04:49:33 +0100
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
On 2004-02-22, at 22.28, Ian Peter wrote:

> I wonder if its possible before the IETF meeting to have at least a
> brief exchange as regards SPF. SPF has gained quite a degree of
> momentum, and in my mind at least it's best to back winners in
> situations like this and put some of the other issues aside.

Problems with SPF (as I see it):

- It uses TXT records and not a new RR (it should use a new RR type)
- It has a (too complicated) macro language which I am nervous can 
create a target for an attack. Allowing "everything which is possible 
in perl" is not a generically good idea. I definitely want to see a 
security analysis of the language and security threats (mis 
configuration, ability to write macros which doesn't converge in memory 
and/or time) etc.

     paf