Re: Email Web of Trust - Problem Statement
Mark Baugher <[email protected]> Mon, 08 Mar 2004 15:40:55 -0800
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
At 02:21 PM 3/8/2004, Yakov Shafranovich wrote: >Mark Baugher wrote: > >>At 01:36 PM 3/8/2004, Alan DeKok wrote: >> >>>Mark Baugher <[email protected]> wrote: >>> > The question that pops into my head when reading the problem statement is >>> > "trusted to do what or to not do what?" >>> >>> The problem in question is spam, so the trust in question should be >>>related to spam. >>> >>> e.g. "I believe that 75% of the messages from domain FOO are spam". >>> >>> Taken over multiple intermediary hops, these numbers give you some >>>probability that any one message is a priori going to be spam. It's >>>not perfect, but it's a start. >> >>Yes, but it begs the question of what is spam. One needs a very clear >>definition of what is spam in order to trust that some domain does or >>does not originate spam. And there could be more than one metric such as >>originating UBE promotions versus nefarious scams to bilk people out of >>their savings. >>More generally, the trust could be based on a particular policy or set of >>policies: A particular domain, for example, might be trusted to adhere >>to certain antispam policies regarding UBE, authenticating senders, >>responding to complaints, etc. >>I think we need to resolve this question before discussing mechanisms. > >I was actually thinking of whether a specific domain is trusted to provide >non-forged data in SMTP, staying away from the definitions of spam. This makes sense to me. The domain is trusted not to forge information envelope data or message contents. Yes? Mark >Yakov