Re: Problems with SPF, solutions, and a timeline.

John Levine <[email protected]> 28 Feb 2004 21:39:31 -0000
Newsgroups gmane.ietf.asrg.smtpverify
Organization I.E.C.C., Trumansburg NY USA
Message-ID <[email protected]>
>  On the other hand, if we're going to define spam to *not* include
>viruses and joe jobs, then by all means, LMAP doesn't fight spam.

Joe jobs aren't even on the radar in the big picture.  Viruses are.
Phishing is.  I personally have a big problem with joe jobs and bounce
floods, having gotten as many as 350,000 bounces per day due to forged
abuse.net mail, but I don't think my experience is typical of
anything.

>  That's not entirely what I was saying.  LMAP doesn't directly deter
>all spam.  It DOES directly deter a large proportion of spam, and
>perhaps the most problematic: forgeries and joe-jobs.  See longer
>explanations in the LMAP discussion document for more details.

Since spammers have proven to be quick to adapt to changing conditions
here's the question: How hard would it be for them to adapt to LMAP
and either send spam that's LMAP compliant, or that's non-compliant in
ways that LMAP won't detect?  I don't see any other answer than that
it would be trivial for them to do so.  If you're sending through a
hijacked PC, you use an address in the hijacked PC's domain.  Or if
you're sending from anywhere else, you can either use throwaway
domains, or pick from a large random list of dusty old domains with no
LMAP.  Since LMAP only checks the envelope, you can continue to forge
From: just like now so users won't see any less forgery than they do now.

There's no question that spammers will do this if LMAP becomes
popular.  Given that spammers will adapt, will the situation e any
more tractable than it is now?

Forcing hijacked PCs to use the real domain accomplishes nothing of
importance.  Consumer ISPs do port 25 blocking now.  (We can argue
whether it's a good idea, but they do.)  People who run large mail
systems tell me that vast amounts of spam comes from hijacked PCs
through ISPs' real outgoing mail gateways.  If ISPs want to deal with
the hijacking problem, they can do it now by looking at the mail
traffic through their own servers.  They don't need LMAP for that. nor
will LMAP make it any more likely that that do so.

So other than an increase in "accountability", for some vague
definition thereof, how will LMAP deter spam, or make it easier to
call spam sources to account, or otherwise address any of the large
e-mail problems?  What am I missing?

Regards,
John Levine, [email protected], Taughannock Networks, Trumansburg NY
http://www.taugh.com