Re: [taugh.com-johnl] Re: Problems with SPF, solutions, and a
"Peter J. Holzer" <[email protected]> Mon, 8 Mar 2004 20:13:09 +0100
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
On 2004-03-03 18:45:27 +0100, Hadmut Danisch wrote: > On Wed, Mar 03, 2004 at 10:42:40AM -0500, John R Levine wrote: > > > > > > It allows to limit the number of mails sent (e.g. per day or after > > > business hours) by a PC or to detect if an PC is sending an unusual > > > amount of mails. There is a solution to this. > > > > Of course. ISPs need to do that now. But I don't see how LMAP makes any > > difference, because they already know what their network ranges are. > > > I'm not talking about ISPs. I'm talking about plain corporate > networks. Many people still require that every/many PCs in the > network are able to send e-mail. I don't think that in many corporate networks it is a *requirement* that any PC can connect to any MTA on the internet. It is often allowed because either there is no security policy at all (especially in small firms) or because the policy is "we allow all outgoing connections because there is no harm and it is more convenient". Normally, PCs are configured to send all mails to a smart host, so people won't even notice if they cannot connect to other MTAs. The smart host can do rate limiting. > On the other hand it should not be able to send thousands of > spam or worm messages. > > Dynamic authorization allows to do that and to detect whether such > a PC is sending more than e.g. 20 mails a day or more than 5 mails > after business hours. I very much doubt that a firm which doesn't block port 25 outgoing on their firewall will set up a dynamic authorization scheme. A few may, but those are the geeks who are in full control of their network anyway and won't have a spam or worm problem. For the zillions of clueless users at home or in small firms that is too complicated. Their ISP might, but the ISP could also block port 25 and force them to use their smarthost (unless they pay for "server internet access"). > > We know who the spammer-friendly providers are now. See > > http://www.spamhaus.org/rokso. Why will LMAP make any difference? > > Because today there is nothing which would allow to recognize that > a mail came from those spammers. ROKSO lists IP addresses of relays. > With LMAP, this will be possible. > That's why LMAP will make the difference. hp -- _ | Peter J. Holzer | I think we need two definitions: |_|_) | Sysadmin WSR | 1) The problem the *users* want us to solve | | | [email protected] | 2) The problem our solution addresses. __/ | http://www.hjp.at/ | -- Phillip Hallam-Baker on spam [demime 0.99d.1 removed an attachment of type application/pgp-signature]