Re: Email Web of Trust - some actual experience

Yakov Shafranovich <[email protected]> Sat, 13 Mar 2004 23:46:49 -0500
Newsgroups gmane.ietf.asrg.smtpverify
Organization SolidMatrix Technologies, Inc.
Message-ID <[email protected]>
Alan DeKok wrote:
> Yakov Shafranovich <[email protected]> wrote:
> 
>>>  If everyone says an MTA has been around for 6 months, you're pretty
>>>sure that either it's not a spammer, or it's in a blacklist somewhere.
>>
>>Then this would only address the issue of hijacked computers. Spam going 
>>through the ISP's mail servers is not addressed by this.
> 
>   Agreed.

I would add that this also addresses the problem of spammers sending 
spam from legit IP space that they bought.

But how would this method is better than other methods for addressing 
the hijacked machines problem? What are the differences?

> 
> 
>>Of course it does make the playing field smaller on one hand, but on
>>the other hand how would new MTAs introduce themselves into the
>>trust network?
> 
> 
>   MTA's need to record, and publish such information.  When taken
> together, that information tells you which MTA's are probably OK, and
> which aren't.
> 

Wouldn't that put any new MTA in a catch-22 situtation: unable to send 
mail until its sufficiently known and unable to be sufficiently known 
since it cannot send mail?

Of course that depends on how the information from this "web of 
reputation" is used by receivers. If this information is used to reject 
email, than it would be a problem. On the other hand, if this 
information is only used to whitelist or give higher ratings to MTAs in 
filtering, it is not as problematic. Of course, past experiences with 
blacklists and how they are used, don't sound too promising. I am 
wondering if there is anybody who has been using SenderBase data in real 
life and how they are using it.

> 
>>I am not saying that is a bad thing, but simply trying to narrow down 
>>the type of spam such system would address.
> 
> 
>   Getting rid of DUL & Blacklists would be useful.  There are many,
> many, fewer IP's in any whitelist than in DUL or Blacklists.
> 
>   The main problem is that it's easy to maintain a DUL or blacklist,
> and much more difficult to maintain a whitelist.

Assuming that they will be used for whitelisting. I can see such web 
being used for blacklisting as well - if you are not in it, then we will 
not accept email from you. Of course, in order for that to happen, the 
web will have to be pretty large and with the possible variations in 
MIB-like modules, that might not happen.

Yakov