Re: Email Web of Trust - Problem Statement

Mark Baugher <[email protected]> Wed, 10 Mar 2004 13:27:02 -0800
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
At 09:06 AM 3/10/2004, Alan DeKok wrote:
>Mark Baugher <[email protected]> wrote:
> > 1. Has the group considered supporting a common policy as a basis for the
> > web?  Otherwise, there needs to be some language to represent a particular
> > member's policy.  Member A rates mail according to criteria x, y, z while
> > Member B uses v, w, x.  This seems intractable to me.
>
>   Agreed.  So we don't try to solve it.  There are still numbers which
>we can publish which are emperically verifiable, useful, and not
>readily available on the net today.  The question is what those
>numbers are...

So is the member of the web of trust like a maven, who passes judgement on 
the goodness of a domain based on its own idiosyncratic evaluation of that 
particular domain?  Does the domain get rated on some common or peculiar 
scale such as "good," "bad," or "ugly?"  Or is there something close to a 
MIB of standardized counters?  (I'm sorry if I am missing some information 
that I should have gleaned from some previous asrg comments).


> > 2. Why not focus on mail operators as members of the web of trust rather
> > than users since there are far fewer (millions rather than billions?) of
> > operators than users, and it is the operators that can most reliably
> > support such a thing.
>
>   The web of trust would explicitly avoid users or operators.  We're
>talking about MTAs.

Ok, thanks.


> > 3. How is the web of trust realized cryptographically?  Or is it?
>
>   I don't believe it needs to be.

I think it might owing to the very bad consequences of smtp name or domain 
spoofing.  Today, if someone sends my management a pornographic 
advertisement using my personal email address, it is virtually 
non-fault.  But empirical numbers that can be spoofed might worsen the 
attack on my internet identities.

Mark


>   Alan DeKok.