Re: Scope of SMTP Verify

"Peter J. Holzer" <[email protected]> Mon, 8 Mar 2004 23:44:57 +0100
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
On 2004-03-08 16:46:10 -0500, Alan DeKok wrote:
> "Peter J. Holzer" <[email protected]> wrote:
> > >   - Is this machine an MTA which will accept mail, too.
> > >     If not, why am I accepting mail from it?
> >
> > Inbound and outbound MTAs are often different machines (just to state
> > the obvious).
>
>   Yes.  But they should be under the same administrative domain, and
> should be verifiably related.

ACK.

> > >     Why is it not using it's own MTA to send mail?
> >
> > What is "it's own MTA"? The designated outgoing MTA for the domain in
> > the return path?
>
>   Pretty much.  MUA's should use MTA's to send mail to MTA's.  Your
> MUA shouldn't be using SMTP to talk to my MTA.

It isn't. In fact I don't know any MUA which sends mail directly to the
recipient's MX. That doesn't mean none exist, but they are pretty rare.
So this seems to be a bit of a red herring.

The more common case is that someone sets up an MTA on a PC and does not
configure it to relay through their ISP's smarthost. That doesn't make
the MTA a MUA. Also worms, spambots, etc. are not MUAs (they don't
interact with a user).



> > > > 2) The identity of the sender of a message.
> > >
> > >   This has privacy issues.
> >
> > Yes, but it is also the most interesting information to verify.
>
>   If you use it, privacy advocates will scream, making the system less
> likely to be deployed or used.

It depends on the definition of "identity". If there is a 1:1 mapping
between identities and persons, I agree. But that doesn't have to be
the case.

As an example, say an "identity" is a mailbox, and the verification
method is a PGP key.

You can create any number of mailboxes at various freemail providers and
a PGP key for each of them. If you sign messages with the corresponding
keys, each recipient can verify that the mails come from the purported
sender, and all your identities can be part of a web of trust, but there
is no way to link your various identities together, at least not any
easier than now.

At least in theory the privacy problem isn't larger. In practice a
published web of trust is a lot easier to analyse than SMTP connections
scattered over the internet.

BTW: As a recipient I decide whose mail I read. If I accept only signed
mails, that's my decision, and no privacy advocate can force me to
accept other mails. I don't do that now for mail, but I won't answer the
phone if there is no caller-id.

	hp

--
   _  | Peter J. Holzer    | I think we need two definitions:
|_|_) | Sysadmin WSR       | 1) The problem the *users* want us to solve
| |   | [email protected]         | 2) The problem our solution addresses.
__/   | http://www.hjp.at/ |    -- Phillip Hallam-Baker on spam

[demime 0.99d.1 removed an attachment of type application/pgp-signature]