Re: Scope of SMTP Verify
"Peter J. Holzer" <[email protected]> Mon, 8 Mar 2004 23:44:57 +0100
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
On 2004-03-08 16:46:10 -0500, Alan DeKok wrote: > "Peter J. Holzer" <[email protected]> wrote: > > > - Is this machine an MTA which will accept mail, too. > > > If not, why am I accepting mail from it? > > > > Inbound and outbound MTAs are often different machines (just to state > > the obvious). > > Yes. But they should be under the same administrative domain, and > should be verifiably related. ACK. > > > Why is it not using it's own MTA to send mail? > > > > What is "it's own MTA"? The designated outgoing MTA for the domain in > > the return path? > > Pretty much. MUA's should use MTA's to send mail to MTA's. Your > MUA shouldn't be using SMTP to talk to my MTA. It isn't. In fact I don't know any MUA which sends mail directly to the recipient's MX. That doesn't mean none exist, but they are pretty rare. So this seems to be a bit of a red herring. The more common case is that someone sets up an MTA on a PC and does not configure it to relay through their ISP's smarthost. That doesn't make the MTA a MUA. Also worms, spambots, etc. are not MUAs (they don't interact with a user). > > > > 2) The identity of the sender of a message. > > > > > > This has privacy issues. > > > > Yes, but it is also the most interesting information to verify. > > If you use it, privacy advocates will scream, making the system less > likely to be deployed or used. It depends on the definition of "identity". If there is a 1:1 mapping between identities and persons, I agree. But that doesn't have to be the case. As an example, say an "identity" is a mailbox, and the verification method is a PGP key. You can create any number of mailboxes at various freemail providers and a PGP key for each of them. If you sign messages with the corresponding keys, each recipient can verify that the mails come from the purported sender, and all your identities can be part of a web of trust, but there is no way to link your various identities together, at least not any easier than now. At least in theory the privacy problem isn't larger. In practice a published web of trust is a lot easier to analyse than SMTP connections scattered over the internet. BTW: As a recipient I decide whose mail I read. If I accept only signed mails, that's my decision, and no privacy advocate can force me to accept other mails. I don't do that now for mail, but I won't answer the phone if there is no caller-id. hp -- _ | Peter J. Holzer | I think we need two definitions: |_|_) | Sysadmin WSR | 1) The problem the *users* want us to solve | | | [email protected] | 2) The problem our solution addresses. __/ | http://www.hjp.at/ | -- Phillip Hallam-Baker on spam [demime 0.99d.1 removed an attachment of type application/pgp-signature]