Re: Devilish: Forget about DNS

Jeff_Silverman <[email protected]> Mon, 9 Feb 2004 11:26:50 -0800 (PST)
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <Pine.LNX.4.44.0402091121150.24528-100000@angel>
On Mon, 9 Feb 2004, Hadmut Danisch wrote:

> On Mon, Feb 09, 2004 at 01:33:21PM -0500, Yakov Shafranovich wrote:
> >
> > Perhaps we should just reformulate the problem as:
> > 
> > How do we introduce sender authentication into the email system?
> >
> 
> Exactly. But until now, by far too many time was wasted to 
> dance around the problem how to find workaround for the 
> flaws and limitations of DNS.
> 
> DNS is made for finding IP addresses for domain names. That's what we
> should use it for.
> 
> DNS is not made for transporting other information hidden in it's 
> record types by violation of their meaning. That's what we should 
> not use it for.
> 
> Hadmut
> 

So why not use kerberos, which was designed to authenticate things?

I have been having a discussion with Yakov on this idea on the side, and 
Yakov raises the (serious and valid) objections that a bad guy could 
create his/her own evil authentication server.  Alternatively, a 
centralized authentication server has the potential of being taken over 
by an organization with corrupt business practices (I won't name names 
here).  More thought is required as to how the authentication server would 
authenticate an E_mail sender, but this problem might be a "real world" 
problem that any authentication may have to deal with.  

The "trusted 3rd party kerberos or kerberos-like authentication server"  
idea is not fully cooked yet, and I would appreciate a wider discussion of
some of the pros and cons.


Many thanks,



Jeff