Re: Problems with SPF, solutions, and a timeline.

"Alan DeKok" <[email protected]> Sat, 28 Feb 2004 15:36:07 -0500
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
"Peter J. Holzer" <[email protected]> wrote:
> [ legacy systems ]
>
> That's a different problem. Sure, there will always be such systems. The
> question is whether we get enough legitimate mail from such systems to
> bother.

  If you believe some people, throwing away *any* legitimate email is
a Mortal Sin, and is cause for all sorts of vilification.

  My opinion is that the recipient should decide how much legitimate
email can be thrown away.  If someone thinks that doing so is a Mortal
Sin, fine, but they shouldn't prevent *me* from doing so, and they
shouldn't oppose the design or implemenation of systems which allow me
to make that choice.

  This is really where most of the arguments among the anti-spam
people end up.  One camp wants freedom (i.e. everyone makes their own
choice, however stupid), and the other camp wants freedom
(i.e. everyone does what we say).  It's an interesting contradiction
in the use of the term "freedom".

> But John's objection is on another level: If it doesn't stop spam
> even if it is fully deployed, because spammers can simply publish LMAP
> information like anybody else, then that scheme doesn't do what it is
> designed to do

  So my previous message proposing a system to work around this
problem went to /dev/null, or was read & ignored.

  Once again, no one expects that LMAP in isolation will solve the
problem.  I don't see that ANY system will be so perfect that spammers
will be unable to work around it.  But that isn't a reason to oppose a
solution.  It's a reason to make d*mn sure the solution dos
*something* to help fight the problem, and to make sure that it saves
more than it costs.

> To make a signing scheme work, you need a scheme to express "trust".
> Somebody has to certify that K is never used to send spam. This could be
> some CA, but it doesn't necessarily have to be. Something like the PGP
> web of trust or social networks like friendster or orkut would be
> preferrable IMHO.

  Which is where I think we will end up.  And there will *still* be
hundreds of millions of spams floating around the net, because no one
wants to do anything to solve the underlying technical flaws.  That's
a shame.

  Alan DeKok.