Re: 9 reasons for dynamic authorization records

"Alan DeKok" <[email protected]> Fri, 13 Feb 2004 12:32:28 -0500
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
Hadmut Danisch <[email protected]> wrote:
> you're kidding. That's far from reality.

  As originally specified, for companies with employees, it's
perfectly reasonable.

> - Not every ISP or MSP is willing to allow its customers a 
>   VPN connection. 

  (... etc.) Those situations are not "companies with employees", and
the solution I proposed is not expected to work there.

> - Try to open a VPN connection to Hotmail, Yahoo, AOL,GMX,
>   T-Online,...

  For Hotmail, that's what web pages are for.  That was Hotmails
original business.  For the others, they already have their own login
& email system.  We don't need anything more.

> - VPN requires to have a VPN capable device. Every tried to 
>   open a VPN connection from an Airport internet terminal or 
>   an Internet Cafe?

  That's what SSL is for.

> - VPN is encryption, which is not allowed in all legislations 
>   of the world. We need a solution which works everywhere.

  I disagree.  We're supposed to solve technical problems, not
political ones.  Some technical solutions MAY still have people being
unable to communicate because of political issues.  We already know
this.  The Internet does not "route around censorship" when everyone
running the net in a country has been shot.

> - Many people site behind a firewall which will not allow 
>   to open a VPN connection from the LAN to somewhere in the world. 

  That's a political layer issue.  I don't see why *I* should have to
accept spam, just because someone else refuses to use modern
protocols.  I don't want to *force* those people to behave as I want,
but I also don't want to have an anti-spam system designed to permit
their desired behaviour, and to prevent mine.  That's unfair.

  That is probably the single largest problem I've run into when
talking to people about this topic.  Many people are simply unable to
understand that allowing MY desired behaviour does not mean denying
THEIR behaviour.  Their response is often to try to force a design
which permits their behaviour... and denies mine.  When I point out
that this is hypocritical, they don't see why, as it works for them.

> I've already pointed out why DNS updates are not feasible in 
> such cases.

  Then DNS updates are the wrong solution.  Or maybe the problem is
posed incorrectly.

  Alan DeKok.