Re: [Fwd: [Asrg] Re: Documents for LMAP BOF]
Yakov Shafranovich <[email protected]> Sun, 08 Feb 2004 17:45:19 -0500
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Organization | SolidMatrix Technologies, Inc. |
| Message-ID | <[email protected]> |
Yakov Shafranovich wrote: > Hadmut Danisch wrote: > >> On Sun, Feb 08, 2004 at 05:17:20PM -0500, Yakov Shafranovich wrote: >> >>> Let me play a little devil's advocate here: >>> >>> If the entire purpose of these proposals is to make sure that the >>> sender is who he claims to be according to DNS information, >> >> >> Let me be the devil himself: >> >> Since there is no semantic defined for being a sender, since we tend >> to confuse sending MTA, envelope sender, forwarder, mailing list, and >> all such things, >> we don't care at all who is the sender. All this is about >> is to find the name of a domain who is willing to cover >> the mail transport with a LMAP entry matching the IP address >> and which we can hold reliable in case the message turns out >> to be fraud. We don't care who is the sender. We won't to know who we >> can blame in case we need one to blame. > > > If so, then HELO checking with DRIP is sufficient :) > Come to think of it, why do we care about tying domains to the IP? If it is solely for the contact information, than rDNS data should be sufficient. If it is in order to get around the problem of bad rDNS management, than falsified WHOIS data is not much better. Which brings us back to your original point - why do we want to authenticate identity? Identity of the incoming MTA or the sender by itself will be meaningeless unless combined with some form of a reputation system. Additionally, there is a limited number of IP addresses as opposed to domains and senders. If we seek to create reputation system, then it would make more sense to have it IP based since it will be less data. As for stopping forgery, since this operates only on the SMTP Session level, it does not stop forgery of the mail content itself. Rather it autheticates the SMTP transaction which lets the network administrators complain to the originator. BUT, if the incoming IP is know, we know who the admin is anyway, so what's the point to tie it in with a domain. Interesting thoughts... Yakov ------- Yakov Shafranovich / asrg <at> shaftek.org SolidMatrix Technologies, Inc. / research <at> solidmatrix.com "Among all our enemies / The ones to be most feared are often the smallest" (Jean de la Fontaine) -------