Standards for exchanging trust information

Yakov Shafranovich <[email protected]> Tue, 16 Mar 2004 18:10:01 -0500
Newsgroups gmane.ietf.asrg.smtpverify
Organization SolidMatrix Technologies, Inc.
Message-ID <[email protected]>
> -------- Original Message --------
> Trust is a contiuum, like everything else related to security.
> 
> Different people will have different levels of trust; having a marketplace
> of trust brokers -- each of whom provide different levels and strenghts
> based on different factors -- is appropriate. Some people and/or services
> will require notarization-based trust, others will be happy knowing that
> blacklist-dujour.org doesn't think the sender is scum.
> 
> I don't see what cost has to do with it. The IETF only needs to provide
> standardized mechanisms for negotiating trust between end-points. Leave
> the brokerage functions (and the implementation costs) to the service
> providers who want to enter the market.
> 

This message suggests that perhaps a more generalized standardized 
mechanism for exchanging trust information might be useful. This sounds 
like the "accreditation" modified for SPF which Phil Hallam-Baker 
suggested beforehand. This also sounds like some of the other proposals 
floating around before like TEOS and Project Lumos.

Assume that such standards would be in place, which would allow two 
parties in a mail transaction to negotiate trust. Would this help the 
spam problem at all? If yes, should this perhaps be something we should 
concentrate on?

Yakov