Re: Problems with SPF, solutions, and a timeline.

"Alan DeKok" <[email protected]> Sat, 28 Feb 2004 14:18:50 -0500
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
John Levine <[email protected]> wrote:
> Alan, snide answers that don't address the issue you're putatively
> responding to are not helpful.

  Exactly.  The same applies to arguments which have been brought up
and refuted many times.  Maybe I'm just frustrated at being involved
in ASRG for over a year, and having the same arguments brought up by
people who participate for a short while, and then disappear.  It's
like trying to fight quicksand... it never responds to your efforts,
and you can never fix the underlying problem.

> The question isn't whether LMAP is a magic bullet.  The question is
> whether LMAP will accomplish enough to be worth the enormous cost
> of deploying it across the net.

  Which is where I was trying to lead the discussion, when I asked if
we could focus on cost/benefit analysis, rather than on imperfections
in a proposal.

> It's clear that LMAP would prevent bounce floods, but at this point,
> I can't see how it would have much effect on spam and phishing
> because it is so easy to work around and always will be, unless you
> make some rather implausible assumptions that every legitimate
> mailer will publish LMAP data, and that there will be rapid and
> reliable ways to tell which new domains are going to send spam.

  I agree.  Hadmut's document makes it clear that the intention of RMX
(and also LMAP) is to add accountability, and to catch forgeries and
joe jobs.  It is stated explicitly in his document that RMX is not
intended to stop spam.  The LMAP discussion document says the same
thing.

  So any argument against LMAP, that it doesn't prevent spam is
*completely* missing the intent of the proposal, which is stated in
plain English in the document.

  LMAP permits receivers to quickly and provably associate a new
domain name with spam it sends.  This association limits the benefit
of registering new domains.

> I sympathize with the feeling that it's urgent to do something.  But
> doing something useless is worse than doing nothing at all.

  I agree completely.  But *technical* arguments against a proposal
are appropriate.  Other arguments that we've seen historically on
ASRG, like "it won't help", or "it's intended to stop spam, but it
won't" are beyond inappropriate.  They are unprofessional, and
demonstrate an inability to read a proposal, and critique it based on
its contents.

  This is not to say that RMX/LMAP are the best solutions, written by
leading figures in SMTP.  They're not.  That's what peer review is
for.  But that peer review should be based on reality, and not on
appeals to authority, lies, or opinions pulled out of the vacuum, as
much of the opposition to them has been.

  Alan DeKok.