Re: limitations of reputation, was Spam sent from compromised
"John Levine" <[email protected]> 23 Mar 2013 17:51:39 -0000
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
> > 2. Identity theft: when a botnet sends spam from Grandma's computer, > > it sends it with Grandma's identity. > >I don't wholly accept this idea that because something isn't perfect >that therefore it's completely useless. That's not what I'm saying. The question is whether the value of more aggressive identity systems would be worth the cost. We already have three fairly widely used identity handles for email, sending IP, SPF bounce domain, and DKIM signature domain. There are elaborate reputation systems built around all three. I note that all three share the characteristic the individual senders don't have to do anything to participate, the identity is handled at the mail server level. So if we could wave our hands and, say, install a unique PGP or S/MIME key into every MUA in the world, what practical difference would it make? - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org