Standards for exchanging trust information
Yakov Shafranovich <[email protected]> Tue, 16 Mar 2004 18:10:01 -0500
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Organization | SolidMatrix Technologies, Inc. |
| Message-ID | <[email protected]> |
> -------- Original Message -------- > Trust is a contiuum, like everything else related to security. > > Different people will have different levels of trust; having a marketplace > of trust brokers -- each of whom provide different levels and strenghts > based on different factors -- is appropriate. Some people and/or services > will require notarization-based trust, others will be happy knowing that > blacklist-dujour.org doesn't think the sender is scum. > > I don't see what cost has to do with it. The IETF only needs to provide > standardized mechanisms for negotiating trust between end-points. Leave > the brokerage functions (and the implementation costs) to the service > providers who want to enter the market. > This message suggests that perhaps a more generalized standardized mechanism for exchanging trust information might be useful. This sounds like the "accreditation" modified for SPF which Phil Hallam-Baker suggested beforehand. This also sounds like some of the other proposals floating around before like TEOS and Project Lumos. Assume that such standards would be in place, which would allow two parties in a mail transaction to negotiate trust. Would this help the spam problem at all? If yes, should this perhaps be something we should concentrate on? Yakov