Re: asrg - research or die

Steve Atkins <[email protected]> Wed, 20 Mar 2013 13:49:09 -0700
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On Mar 20, 2013, at 1:42 PM, Dotzero <[email protected]> wrote:

> On Wed, Mar 20, 2013 at 4:28 PM, Steve Atkins <[email protected]> wrote:
>> 
>> On Mar 20, 2013, at 1:21 PM, Dotzero <[email protected]> wrote:
>>> 
>>> I think it would be interesting to see a project that examines
>>> phishing/malware emails to determine whether email authentication
>>> (DMARC/SPF/DKIM) or other practices would have prevented the malicious
>>> email from reaching endusers.
>> 
>> I did that briefly, looking at both phishing attempts for, and legitimate mail from
>> one particular company, as seen at my inbox.
>> 
>> The results[1] were not what people wanted to hear, so I didn't bother digging
>> deeper or formalizing the results.
>> 
> 
> ADSP was an experiment gone wrong.

But it's effectiveness at stopping phishing is pretty much the same as DMARC,
so the experience is somewhat relevant.

> 
>> Unless you're in academia, where you justify your existence by publishing
>> papers, there doesn't seem much benefit to doing research that won't affect
>> behaviour.
>> 
> 
> It isn't always easy to determine what will affect behavior.

It's not, no. But you need to consider that when deciding whether to expend
energy and time on research, with no particular goal and no funding.

> 
>> An end goal beyond the (perfectly reasonable) "it'd be interesting" seems
>> like something to consider.
>> 
> 
> The obvious goal would be to determine whether domains such as those
> belonging to banks would afford endusers some modicum of protection by
> adopting the combination of DMARC/DKIM/SPF.I've seen very positive
> results for the domains I have implemented DMARC p=reject for.
> Unfortunately there aren't mant case studies out there for people to
> refer to.

Could you share those positive results? Actually, more importantly than
the actual results is what you decided to measure, and why.

> Having said this, DMARC only addresses specific kinds of abuse.

Defining what those specific kinds are would be part of deciding
what to measure, I guess.

Cheers,
  Steve

-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org