Email Web of Trust - Defining the metrics

Yakov Shafranovich <[email protected]> Tue, 16 Mar 2004 00:44:42 -0500
Newsgroups gmane.ietf.asrg.smtpverify
Organization SolidMatrix Technologies, Inc.
Message-ID <[email protected]>
Mark Baugher wrote:
>> which is extensible via something like the MIB mechanism AND a base 
>> MIB-like RFC defining neutral data points such as length of time MTA 
>> is transmitting, average volume, etc. This way everyone can use the 
>> base neutral data points and extend the web to include other things 
>> they might be interested in.
> 
> 
> I guess we can start defining it.  The antispam MIB is wide open and can 
> be any number of things.  In the simplest case, it might be the number 
> of times an MUA explicitly rejected a message from a bona fide source 
> following user inspection.  There are all sorts of attacks to be 
> considered including collusion among users, Sybils, etc.  And there is 
> the problem of ensuring sufficient system integrity such that false 
> positives don't smirch the reputation of mail senders.
> 

Are we talking about defining an SNMP MIB, or creating a similar 
MIB-like mechanism?

Also, while SNMP MIBs can be good for metrics, I am not sure if passing 
around trust information via SNMP will work. Of course, I am not an 
expert in SNMP at all so I will have to do some more reading on this.

> 
>> As a side note, I am not a big expert in SNMP but in theory can it be 
>> used to provide information about MTAs?
> 
> 
> http://www.faqs.org/rfcs/rfc2789.html
> 

I really really never expected something like this to exist. But it does 
  although I wonder how often it is actually used. Once again, I am very 
impressed by the wealth of technical information in the RFCs and the IETF.

Yakov