Re: Email Web of Trust - Problem Statement

Mark Baugher <[email protected]> Thu, 11 Mar 2004 14:46:50 -0800
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
At 02:02 PM 3/10/2004, Alan DeKok wrote:
>Mark Baugher <[email protected]> wrote:
> > So is the member of the web of trust like a maven, who passes judgement on
> > the goodness of a domain based on its own idiosyncratic evaluation of that
> > particular domain?
>
>   Yup.  We cannot realistically expect anything else.

How about a MIB definition:  Let's say the peers who make up the "web of trust"
run the same protocol for authorizing incoming mail.  The protocol, whatever
it is, has counters for messages that are received but rejected as junk,
along with the address or name associated with the source.  The peers trust
each other to maintain these counters according to the MIB specification.

Mark


> >  Does the domain get rated on some common or peculiar scale such as
> > "good," "bad," or "ugly?"
>
>   The idea is to have a suggested ranking which can be (somewhat)
>empirically validated.
>
> > Today, if someone sends my management a pornographic advertisement
> > using my personal email address, it is virtually non-fault.  But
> > empirical numbers that can be spoofed might worsen the attack on my
> > internet identities.
>
>   Then they're not useful numbers to measure.
>
>   Since IP addresses are difficult to spoof (as compared to domains in
>SMTP), it would be best to key off of IP addresses.
>
>   Alan DeKok.