Re: Email Web of Trust - Problem Statement

"Peter J. Holzer" <[email protected]> Wed, 10 Mar 2004 10:26:30 +0100
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
On 2004-03-09 22:26:42 -0800, Mark Baugher wrote:
> Your explanation seems to roughly correspond with John Levine's web
> page.  I have a few more questions.
>
> 1. Has the group considered supporting a common policy as a basis for the
> web?

Not so fast, we've only been discussing that for about a week :-)

The question has been raised, but I don't think there is consensus yet.

> Otherwise, there needs to be some language to represent a particular
> member's policy.

Not necessarily. If two members have different policies they will find
that their results are different and will not trust each other to a high
degree. They don't need to know the details of their policy for that.

> Member A rates mail according to criteria x, y, z while
> Member B uses v, w, x.  This seems intractable to me.  I can almost hear
> the argument that it would be too difficult to define such a common policy,
> but any entity that rates mail is implementing a policy.  There might be
> multiple webs based on distinct policies for characterizing mail.

I expect that there would be members with similar policies would cluster
together in a web of trust. Distinct webs may be a possibility, but I
doubt it would give better results.


> 2. Why not focus on mail operators as members of the web of trust rather
> than users since there are far fewer (millions rather than billions?) of
> operators than users, and it is the operators that can most reliably
> support such a thing.

That has also already been suggested. My impression is that currently
more people are leaning in favour of that than individual users.

It certainly has the advantage of resulting in a far smaller and more
manageable web. It may also be easier to deploy (although I'm not sure
of that).

The downside is that it may be too coarse: Large ISPs have a mixture of
customers. Some of them will be spammers, some will be careless and get
hijacked, some will distribute viruses and worms. Even if the ISP is
careful and reacts promptly to incidents, there will always be some
noise level which result in relatively low trust in that provider, which
wil penalize all its users.


> 3. How is the web of trust realized cryptographically?  Or is it?

It isn't because it doesn't exist yet :-). I think it should be. My idea
was to use PGP as the model, and just add new signature flags.

	hp

--
   _  | Peter J. Holzer    | I think we need two definitions:
|_|_) | Sysadmin WSR       | 1) The problem the *users* want us to solve
| |   | [email protected]         | 2) The problem our solution addresses.
__/   | http://www.hjp.at/ |    -- Phillip Hallam-Baker on spam

[demime 0.99d.1 removed an attachment of type application/pgp-signature]