Re: 9 reasons for dynamic authorization records

Hadmut Danisch <[email protected]> Fri, 13 Feb 2004 23:25:08 +0100
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
On Fri, Feb 13, 2004 at 01:31:15PM -0800, Jeff Silverman wrote:
> It seems to me that there are two parts to question here.  I think the 
> first part is "What do we want to do"? and the second part is "How do we 
> want to do it".   I think the answer to the first part is "We want to 
> build some sort of sender authorization mechanism that is robust, 
> effective, easy-to-use, supports mobile users, is legal in all 
> jurisdictions, and free of any intellectual property entanglements".  
> Please correct me if I am wrong.
> 
> For the second part, there seems to be three camps: "Modify DNS to 
> support this", "Implement it using a web server", and "Build something 
> completely new".


Very good point, good summary. Let's start from here. :-)




> Although I despise Microsoft with a passion, I don't see how the leak of 
> the source code or the ASN.1 changes the urgency of the problem.  The 
> SPAMmers are able to SPAM effectively without resorting to breaking and 
> entering.  This is an urgent problem.  And yet, as somebody pointed out, 
> we really have only one chance to get this thing right, so let us move 
> cautiously, with rigorous testing.


Fully agreed. There are plenty of security holes in Microsoftware.
And most of them are urgent. So no need to hurry. We'll easily 
find another urgent Microsoft hole just in time when we need one.
;-)



> Have I captured the gist of the discussion or am I missing
> something?


Captured very well. Thanks.

regards
Hadmut