Re: limitations of reputation, was Spam sent from compromised

Steve Atkins <[email protected]> Sun, 24 Mar 2013 10:12:59 -0700
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On Mar 24, 2013, at 10:07 AM, "Neil Schwartzman" <[email protected]> wrote:

> 
> On Mar 24, 2013, at 9:33 AM, Barry Shein <[email protected]> wrote:
> 
>>> So if we could wave our hands and, say, install a unique PGP or S/MIME
>>> key into every MUA in the world, what practical difference would it
>>> make?
>> 
>> I believe it would help with joe jobs (are they still much of a
>> problem? I haven't seen one in a while) and phishing, knowing that msg
>> from your bank is really from your bank with some confidence.
> 
> SPF and DKIM can DMARC solve the problem of people purloining from domains and sending phish/malware etc.
> 
> They are completely ineffective, of course, for look-alike domains, which are 80-90% of the problem.

Yup. For lookalike domains they'd be an excellent foundation to build something effective
(e.g. a third-party maintained whitelist) on, though.

> Joe jobs are a fairly minor problem. When they happen to a small site, it's a pain (generally limited in number and longevity), and for a large site, say Yahoo! it is very easy to deal with given the tiny proporition of overall email flow they deal with.

+1

Cheers,
  Steve-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org