Re: asrg - research or die

Dotzero <[email protected]> Wed, 20 Mar 2013 16:42:15 -0400
Newsgroups gmane.ietf.asrg
Message-ID <CAJ4XoYchj28VMQOWcOc-tyJA5_o3qL-BkqB9GvjydiDUScd3oQ@mail.gmail.com>
On Wed, Mar 20, 2013 at 4:28 PM, Steve Atkins <[email protected]> wrote:
>
> On Mar 20, 2013, at 1:21 PM, Dotzero <[email protected]> wrote:
>
>> On Wed, Mar 20, 2013 at 1:58 PM, Barry Shein <[email protected]> wrote:
>>>
>>>
>>> But even focusing on "what would be research? what would be progress
>>> (on the problem at hand)?"  would be more productive than "what is
>>> spam?"
>>>
>>
>> I think it would be interesting to see a project that examines
>> phishing/malware emails to determine whether email authentication
>> (DMARC/SPF/DKIM) or other practices would have prevented the malicious
>> email from reaching endusers.
>
> I did that briefly, looking at both phishing attempts for, and legitimate mail from
> one particular company, as seen at my inbox.
>
> The results[1] were not what people wanted to hear, so I didn't bother digging
> deeper or formalizing the results.
>

ADSP was an experiment gone wrong.

> Unless you're in academia, where you justify your existence by publishing
> papers, there doesn't seem much benefit to doing research that won't affect
> behaviour.
>

It isn't always easy to determine what will affect behavior.

> An end goal beyond the (perfectly reasonable) "it'd be interesting" seems
> like something to consider.
>

The obvious goal would be to determine whether domains such as those
belonging to banks would afford endusers some modicum of protection by
adopting the combination of DMARC/DKIM/SPF.I've seen very positive
results for the domains I have implemented DMARC p=reject for.
Unfortunately there aren't mant case studies out there for people to
refer to.

Having said this, DMARC only addresses specific kinds of abuse.

> Cheers,
>   Steve
>
> [1] Flipping a coin was a better phishing filter, both in terms of false
> positives and false negatives, than DKIM+ADSP.
>
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org