Re: limitations of reputation, was Spam sent from compromised
"Neil Schwartzman" <[email protected]> 24 Mar 2013 10:07:33 -0700
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On Mar 24, 2013, at 9:33 AM, Barry Shein <[email protected]> wrote: >> So if we could wave our hands and, say, install a unique PGP or S/MIME >> key into every MUA in the world, what practical difference would it >> make? > > I believe it would help with joe jobs (are they still much of a > problem? I haven't seen one in a while) and phishing, knowing that msg > from your bank is really from your bank with some confidence. SPF and DKIM can DMARC solve the problem of people purloining from domains and sending phish/malware etc. They are completely ineffective, of course, for look-alike domains, which are 80-90% of the problem. Joe jobs are a fairly minor problem. When they happen to a small site, it's a pain (generally limited in number and longevity), and for a large site, say Yahoo! it is very easy to deal with given the tiny proporition of overall email flow they deal with.
smime.p7s
(application/pkcs7-signature, 4 KB) - not displayed