Re: limitations of reputation, was Spam sent from compromised
Barry Shein <[email protected]> Sun, 24 Mar 2013 12:33:06 -0400
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On March 23, 2013 at 17:51 [email protected] (John Levine) wrote: > > > 2. Identity theft: when a botnet sends spam from Grandma's computer, > > > it sends it with Grandma's identity. > > > >I don't wholly accept this idea that because something isn't perfect > >that therefore it's completely useless. > > That's not what I'm saying. The question is whether the value of more > aggressive identity systems would be worth the cost. Ok, I was being absolutist for rhetorical effect. It's a good question. > We already have three fairly widely used identity handles for email, > sending IP, SPF bounce domain, and DKIM signature domain. There are > elaborate reputation systems built around all three. I note that all > three share the characteristic the individual senders don't have to do > anything to participate, the identity is handled at the mail server > level. > > So if we could wave our hands and, say, install a unique PGP or S/MIME > key into every MUA in the world, what practical difference would it > make? I believe it would help with joe jobs (are they still much of a problem? I haven't seen one in a while) and phishing, knowing that msg from your bank is really from your bank with some confidence. My sense is that it may not be a front-line defense but it's something, not the specific implementations but as a concept, people would like: To know with some certainty that the sender is who s/he says they are. Which in the extreme raises issues of anonymity etc. We can block caller-id on our telephones, but I can also refuse to answer any call which doesn't give me caller-id, that's also my right. At least the recipient can use it as a filtering, sorting, or flagging mechanism. I agree that it's questionable what the utility is of knowing that this message touting cheap RX really is from "Cheap RX R US!" Unless we were willing to go the certificate authority route at least as originally conceived -- to get my first SSL cert I had to submit Dun & Bradstreet info for my company and enough info for the CA to check the info really was from a duly authorized officer of the corporation etc. Today I believe you only have to be able to fog a mirror. -- -Barry Shein The World | [email protected] | http://www.TheWorld.com Purveyors to the Trade | Voice: 800-THE-WRLD | Dial-Up: US, PR, Canada Software Tool & Die | Public Access Internet | SINCE 1989 *oo* - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org