Re: limitations of reputation, was Spam sent from compromised
Steve Atkins <[email protected]> Sun, 24 Mar 2013 10:12:59 -0700
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On Mar 24, 2013, at 10:07 AM, "Neil Schwartzman" <[email protected]> wrote: > > On Mar 24, 2013, at 9:33 AM, Barry Shein <[email protected]> wrote: > >>> So if we could wave our hands and, say, install a unique PGP or S/MIME >>> key into every MUA in the world, what practical difference would it >>> make? >> >> I believe it would help with joe jobs (are they still much of a >> problem? I haven't seen one in a while) and phishing, knowing that msg >> from your bank is really from your bank with some confidence. > > SPF and DKIM can DMARC solve the problem of people purloining from domains and sending phish/malware etc. > > They are completely ineffective, of course, for look-alike domains, which are 80-90% of the problem. Yup. For lookalike domains they'd be an excellent foundation to build something effective (e.g. a third-party maintained whitelist) on, though. > Joe jobs are a fairly minor problem. When they happen to a small site, it's a pain (generally limited in number and longevity), and for a large site, say Yahoo! it is very easy to deal with given the tiny proporition of overall email flow they deal with. +1 Cheers, Steve- This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org