Re: limitations of reputation, was Spam sent from compromised

"John Levine" <[email protected]> 23 Mar 2013 17:51:39 -0000
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
> > 2.  Identity theft: when a botnet sends spam from Grandma's computer,
> > it sends it with Grandma's identity.
>
>I don't wholly accept this idea that because something isn't perfect
>that therefore it's completely useless.

That's not what I'm saying.  The question is whether the value of more
aggressive identity systems would be worth the cost.

We already have three fairly widely used identity handles for email,
sending IP, SPF bounce domain, and DKIM signature domain.  There are
elaborate reputation systems built around all three.  I note that all
three share the characteristic the individual senders don't have to do
anything to participate, the identity is handled at the mail server
level.

So if we could wave our hands and, say, install a unique PGP or S/MIME
key into every MUA in the world, what practical difference would it
make?

-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org