Re: [Fwd: [Asrg] Re: Documents for LMAP BOF]
Philip Miller <[email protected]> Sun, 08 Feb 2004 20:44:04 -0500
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
Yakov Shafranovich wrote: > Philip Miller wrote: >> Hadmut Danisch wrote: >>> On Sun, Feb 08, 2004 at 05:45:19PM -0500, Yakov Shafranovich wrote: > .... >>> Because a malicous admin (spammer's admins are malicous by definition) >>> could still send tons of mail with forged sender addresses. If you tie >>> it with a domain, the malicous admin is forced to use the own domain >>> name as the sender address. Unfortunately, the spam is still spam. >> >> This is all that LMAP was really meant to solve. The early discussion >> drafts simply said 'we want to prevent joe jobs. Unfortunately, it >> gets extended and extended, until it's not good at anything. >> >>> But it is a good protection in case the admin is not malicious. It >>> stops those tons of worm and virus messages with forged sender >>> addresses. >> >> This is also a good, and more importantly cheap and easy, goal to >> implement. >> >> I think that any LMAP draft should handle these cases first and >> foremost, and anything further is icing on the cake. >> > The current draft > (http://asrg.kavi.com/apps/group_public/download.php/31/draft-irtf-asrg-lmap-discussion-00.txt) > addresses four cases of forgery (section 2.1): > 1. Senders of junk email (the largest category of spam), often forges > return addresses. > 2. In account fraud, also known as ``phishing'', a sender poses as a > person or organization with whom the recipient has a business > relationship, or would like to have a business relationship. > 3. In a ``joe job,'' a sender sends out abusive mail and forges the > address of an unrelated party. > 4. Viruses, trojans, worms, and related automated malware use forged > return addresses to trick recipients into accepting or opening messages > with hostile active content. In terms of the data in the message, cases 2 and 3 can be conflated. Case 1 usually is similar, but doesn't require that the forged domain have a reputation. The only big difference is that 2 and 3 need not only a valid domain, but a valid domain with a reputation to uphold. LMAP does not prevent spammers using their own domains, even from allowing open transmission as that domain. Case 4 is another thing entirely, because virus authors will find a way around this easily enough, at least until LMAP and authentication by unstored credentials are enforced. So, although we really want to say this targets case 1, because this is the anti-SPAM research group, not the anti-joe-phishing research group, 2 and 3 are the cases we're in a really good position to address. Should this thread be continued solely on the smtp-verify sublist? Philip Miller