Re: Email Web of Trust - Problem Statement

Mark Baugher <[email protected]> Wed, 10 Mar 2004 20:16:33 -0800
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
At 01:26 AM 3/10/2004, Peter J. Holzer wrote:
>On 2004-03-09 22:26:42 -0800, Mark Baugher wrote:
> > Your explanation seems to roughly correspond with John Levine's web
> > page.  I have a few more questions.
> >
> > 1. Has the group considered supporting a common policy as a basis for the
> > web?
>
>Not so fast, we've only been discussing that for about a week :-)
>
>The question has been raised, but I don't think there is consensus yet.
>
> > Otherwise, there needs to be some language to represent a particular
> > member's policy.
>
>Not necessarily. If two members have different policies they will find
>that their results are different and will not trust each other to a high
>degree. They don't need to know the details of their policy for that.

How do they discover that their policies are different?  How are policies 
expressed and then compared to determine similarity or difference?

Mark


> > Member A rates mail according to criteria x, y, z while
> > Member B uses v, w, x.  This seems intractable to me.  I can almost hear
> > the argument that it would be too difficult to define such a common policy,
> > but any entity that rates mail is implementing a policy.  There might be
> > multiple webs based on distinct policies for characterizing mail.
>
>I expect that there would be members with similar policies would cluster
>together in a web of trust. Distinct webs may be a possibility, but I
>doubt it would give better results.
>
>
> > 2. Why not focus on mail operators as members of the web of trust rather
> > than users since there are far fewer (millions rather than billions?) of
> > operators than users, and it is the operators that can most reliably
> > support such a thing.
>
>That has also already been suggested. My impression is that currently
>more people are leaning in favour of that than individual users.
>
>It certainly has the advantage of resulting in a far smaller and more
>manageable web. It may also be easier to deploy (although I'm not sure
>of that).
>
>The downside is that it may be too coarse: Large ISPs have a mixture of
>customers. Some of them will be spammers, some will be careless and get
>hijacked, some will distribute viruses and worms. Even if the ISP is
>careful and reacts promptly to incidents, there will always be some
>noise level which result in relatively low trust in that provider, which
>wil penalize all its users.
>
>
> > 3. How is the web of trust realized cryptographically?  Or is it?
>
>It isn't because it doesn't exist yet :-). I think it should be. My idea
>was to use PGP as the model, and just add new signature flags.
>
>         hp
>
>--
>    _  | Peter J. Holzer    | I think we need two definitions:
>|_|_) | Sysadmin WSR       | 1) The problem the *users* want us to solve
>| |   | [email protected]         | 2) The problem our solution addresses.
>__/   | http://www.hjp.at/ |    -- Phillip Hallam-Baker on spam
>
>[demime 0.99d.1 removed an attachment of type application/pgp-signature]