Re: Email Web of Trust - Problem Statement

"Peter J. Holzer" <[email protected]> Tue, 9 Mar 2004 00:07:50 +0100
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
On 2004-03-08 17:21:34 -0500, Yakov Shafranovich wrote:
> Mark Baugher wrote:
>
> >At 01:36 PM 3/8/2004, Alan DeKok wrote:
> >
> >>Mark Baugher <[email protected]> wrote:
> >>> The question that pops into my head when reading the problem
> >>> statement is "trusted to do what or to not do what?"
> >>
> >>  The problem in question is spam, so the trust in question should be
> >>related to spam.
> >>
> >>  e.g. "I believe that 75% of the messages from domain FOO are spam".
> >
> >Yes, but it begs the question of what is spam.  One needs a very clear
> >definition of what is spam in order to trust that some domain does or
> >does not originate spam.  And there could be more than one metric such
> >as originating UBE promotions versus nefarious scams to bilk people out
> >of their savings.

Like Alan, I think that for the purposes of a web of trust, the circular
definition "spam is what an entity believes to be spam" is sufficient.

However, this is one reason why I intended the entity to be an
individual sender, not a domain or MTA. A single person tends to have a
relatively consistent opinion of what is or is not spam, and people who
know each other probably have similar opinions. But there is no way all
AOL or hotmail users will agree what spam is.

In any case there should probably at least two dimensions to the trust
metric:

1) I believe that messages from foo are not spam.

2) I agree with foo what spam is.

> >More generally, the trust could be based on a particular policy or set
> >of policies:  A particular domain, for example, might be trusted to
> >adhere to certain antispam policies regarding UBE, authenticating
> >senders, responding to complaints, etc.
> >
> >I think we need to resolve this question before discussing mechanisms.
> >
>
> I was actually thinking of whether a specific domain is trusted to
> provide non-forged data in SMTP, staying away from the definitions of spam.

How do you determine that? It is relatively simple to get an opinion
(either from a user or a program like SpamAssassin) on whether a given
message is spam or not. But whether the return-path is forged or not is
an objective criterium which can not easily be verified. If you get a
message from <[email protected]> from the MTA 143.130.50.112, is that
forged or not?

	hp

--
   _  | Peter J. Holzer    | I think we need two definitions:
|_|_) | Sysadmin WSR       | 1) The problem the *users* want us to solve
| |   | [email protected]         | 2) The problem our solution addresses.
__/   | http://www.hjp.at/ |    -- Phillip Hallam-Baker on spam

[demime 0.99d.1 removed an attachment of type application/pgp-signature]