Re: limitations of reputation, was Spam sent from compromised

Barry Shein <[email protected]> Sun, 24 Mar 2013 12:33:06 -0400
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On March 23, 2013 at 17:51 [email protected] (John Levine) wrote:
 > > > 2.  Identity theft: when a botnet sends spam from Grandma's computer,
 > > > it sends it with Grandma's identity.
 > >
 > >I don't wholly accept this idea that because something isn't perfect
 > >that therefore it's completely useless.
 > 
 > That's not what I'm saying.  The question is whether the value of more
 > aggressive identity systems would be worth the cost.

Ok, I was being absolutist for rhetorical effect. It's a good
question.

 > We already have three fairly widely used identity handles for email,
 > sending IP, SPF bounce domain, and DKIM signature domain.  There are
 > elaborate reputation systems built around all three.  I note that all
 > three share the characteristic the individual senders don't have to do
 > anything to participate, the identity is handled at the mail server
 > level.
 > 
 > So if we could wave our hands and, say, install a unique PGP or S/MIME
 > key into every MUA in the world, what practical difference would it
 > make?

I believe it would help with joe jobs (are they still much of a
problem? I haven't seen one in a while) and phishing, knowing that msg
from your bank is really from your bank with some confidence.

My sense is that it may not be a front-line defense but it's
something, not the specific implementations but as a concept, people
would like: To know with some certainty that the sender is who s/he
says they are.

Which in the extreme raises issues of anonymity etc.

We can block caller-id on our telephones, but I can also refuse to
answer any call which doesn't give me caller-id, that's also my right.

At least the recipient can use it as a filtering, sorting, or flagging
mechanism.

I agree that it's questionable what the utility is of knowing that
this message touting cheap RX really is from "Cheap RX R US!"

Unless we were willing to go the certificate authority route at least
as originally conceived -- to get my first SSL cert I had to submit
Dun & Bradstreet info for my company and enough info for the CA to
check the info really was from a duly authorized officer of the
corporation etc.

Today I believe you only have to be able to fog a mirror.


-- 
        -Barry Shein

The World              | [email protected]           | http://www.TheWorld.com
Purveyors to the Trade | Voice: 800-THE-WRLD        | Dial-Up: US, PR, Canada
Software Tool & Die    | Public Access Internet     | SINCE 1989     *oo*
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org