Re: [Fwd: [Asrg] Re: Documents for LMAP BOF]

Yakov Shafranovich <[email protected]> Sun, 08 Feb 2004 17:45:19 -0500
Newsgroups gmane.ietf.asrg.smtpverify
Organization SolidMatrix Technologies, Inc.
Message-ID <[email protected]>
Yakov Shafranovich wrote:

> Hadmut Danisch wrote:
> 
>> On Sun, Feb 08, 2004 at 05:17:20PM -0500, Yakov Shafranovich wrote:
>>
>>> Let me play a little devil's advocate here:
>>>
>>> If the entire purpose of these proposals is to make sure that the 
>>> sender is who he claims to be according to DNS information, 
>>
>>
>> Let me be the devil himself:
>>
>> Since there is no semantic defined for being a sender, since we tend 
>> to confuse sending MTA, envelope sender, forwarder, mailing list, and 
>> all such things,
>> we don't care at all who is the sender. All this is about
>> is to find the name of a domain who is willing to cover
>> the mail transport with a LMAP entry matching the IP address
>> and which we can hold reliable in case the message turns out
>> to be fraud. We don't care who is the sender. We won't to know who we 
>> can blame in case we need one to blame.
> 
> 
> If so, then HELO checking with DRIP is sufficient :)
> 

Come to think of it, why do we care about tying domains to the IP? If it 
is solely for the contact information, than rDNS data should be 
sufficient. If it is in order to get around the problem of bad rDNS 
management, than falsified WHOIS data is not much better.

Which brings us back to your original point - why do we want to 
authenticate identity? Identity of the incoming MTA or the sender by 
itself will be meaningeless unless combined with some form of a 
reputation system. Additionally, there is a limited number of IP 
addresses as opposed to domains and senders. If we seek to create 
reputation system, then it would make more sense to have it IP based 
since it will be less data.

As for stopping forgery, since this operates only on the SMTP Session 
level, it does not stop forgery of the mail content itself. Rather it 
autheticates the SMTP transaction which lets the network administrators 
complain to the originator. BUT, if the incoming IP is know, we know who 
the admin is anyway, so what's the point to tie it in with a domain.

Interesting thoughts...

Yakov
-------
Yakov Shafranovich / asrg <at> shaftek.org
SolidMatrix Technologies, Inc. / research <at> solidmatrix.com
"Among all our enemies / The ones to be most feared are often the 
smallest" (Jean de la Fontaine)
-------