Re: [Fwd: [Asrg] Re: Documents for LMAP BOF]

Yakov Shafranovich <[email protected]> Sun, 08 Feb 2004 19:45:07 -0500
Newsgroups gmane.ietf.asrg.smtpverify
Organization SolidMatrix Technologies, Inc.
Message-ID <[email protected]>
Hadmut Danisch wrote:
> On Sun, Feb 08, 2004 at 05:45:19PM -0500, Yakov Shafranovich wrote:
> 
>>>Hadmut Danisch wrote:
>>>
...
>>Which brings us back to your original point - why do we want to 
>>authenticate identity? Identity of the incoming MTA or the sender by 
>>itself will be meaningeless unless combined with some form of a 
>>reputation system.
> 
> And that's where those problems begin SPF etc. don't solve.
> 
> In Germany, I am required to have an identity card, to provide
> an impressum on my web site and so on. 
> 
> What kind of reputation is there in the USA except for your
> driving license and Social security number? People use to 
> change their name arbitrarily and can lease domains anonymously 
> just by sending cash in a fedex envelope

That is correct - in the US nothing is required to setup a website. It 
is possible to setup domains anywhere in the world with false 
information as spammer regularly do since the domain registrars do not 
check WHOIS data for correctness (an old ASRG discussion on registrar 
costs comes to mind). Even though ICANN obligates registrars to have 
correct WHOIS information, it is too expensive for registrars to enforce 
it especially across international borders.

>>Additionally, there is a limited number of IP 
>>addresses as opposed to domains and senders. If we seek to create 
>>reputation system, then it would make more sense to have it IP based 
>>since it will be less data.
> 
> No. There are too many shared and dynamic IP addresses. And what about
> IPv6?
> 
> But you could have registries where you register as a well known
> person and will be covered bei an LMAP entry with your IP address
> until you logout. 
> 
> See my scaf draft where I describe exactly such a scheme for providers
> like Yahoo, Hotmail, AOL. Logging in into Hotmail etc. is a kind of
> such a reputation system.
> 

We have IP addresses today which can be used as a basis for a reputation 
system as well. All of the problems we have with blacklists today will 
still be here tomorrow with domain names and senders. I do not see yet a 
compelling reason as to why we should use domain names and senders as a 
basis of identity for reputation as opposed to IP addresses. We can 
implement a reliable reputation and accredition service bases on IPs, so 
why go to domains?

> 
>>As for stopping forgery, since this operates only on the SMTP Session 
>>level, it does not stop forgery of the mail content itself. Rather it 
>>autheticates the SMTP transaction which lets the network administrators 
>>complain to the originator. BUT, if the incoming IP is know, we know who 
>>the admin is anyway, so what's the point to tie it in with a domain.
> 
> Because a malicous admin (spammer's admins are malicous by definition)
> could still send tons of mail with forged sender addresses. If you tie
> it with a domain, the malicous admin is forced to use the own domain 
> name as the sender address. Unfortunately, the spam is still spam.
> 
> But it is a good protection in case the admin is not malicious. It
> stops those tons of worm and virus messages with forged sender
> addresses. 
> 
> With the HELO approach anyone could still send messages with 
> sender domain @danisch.de. You will know whom to blame for doing 
> so, but this doesn't make you feel better. Blaming is slow and expensive.
> 
> With the sender approach only one machine could send messages from 
> @danisch.de. That's much better. 
> 

So the entire intent of LMAP is to reduce forgery of sender addresses. 
However, since it addresses only the SMTP level of the email 
transaction, it does not stop forgery of the mail content itself. Plus 
viruses can still figure out how to use the right domain that the user 
himself uses with a different address. What it does do is give spammers 
more hoops to jump through.

What I still do not understand with reputation and accreditation 
services is why the same concept of "reject from unknown domains" cannot 
be applied to IP addresses. The same way in a LMAP world we can reject 
email or filter it because of lack of reputation or accreditation, can 
be done with IP addresses, without a need for any protocol changes.

Yakov
-------
Yakov Shafranovich / asrg <at> shaftek.org
SolidMatrix Technologies, Inc. / research <at> solidmatrix.com
"Among all our enemies / The ones to be most feared are often the 
smallest" (Jean de la Fontaine)
-------