Re: Let's try to be productive...
"John Levine" <[email protected]> 6 Jan 2014 17:49:33 -0000
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
>What has changed recently in the spam-o-verse? >What is likely to change in the near future? Seems like reasonable questions. >1. ICANN is injecting over 1,000 new TLDs. Many have already been >added to the DNS root but aren't in general use yet such as .CEO, >.EMAIL, .HOUSE, etc. I doubt we'll see many of them in spam. About half are private corporate vanity domains (one is a personal vanity domain), the rest are all likely to cost two or three times as much as .com or .org. I can't tell how many of them will turn up in URLs; we can expect companies with vanity TLDs to use them, but that's only a few hundred of the millions of commercial domains. >2. The net is moving to IPv6. > >One example is this vastly expands the IP blacklisting and IP mobility >landscape. Yeah, that's the interesting one. We all seem to agree that the minimum granularity for blacklisting will be /64, although there are hosting companies who made poor decisions and put all the customers in a rack in the same /64. My inclination is to say tough luck. For whitelisting, it really should be individual IPs, although people have some odd ideas about mail servers with auto-configured addresses. There's also long running arguments about whether v6 mail servers need rDNS (non-server hosts won't) and whether to be fussier about authentication of mail that arrives over v6. So far v6 mail has been pretty easy to filter. I just got my v6 IP filtering code working last week although I've been accepting v6 mail for a year. >3. Internationalization - ICANN is approving new scripts for TLDs and >host names (SLDs etc) such as Chinese, Arabic, Cyrillic, etc. A lot of >work has gone on in recent years in this area but now these are going >live. > >One obvious and well-discussed problem is homograph fraud. ICANN has a huge and complex set of rules about IDN languages and character sets that make homographs in 2LDs pretty unlikely, You can have homographs at lower levels, but you can have "microsoft" and "google" at lower levels, too. >For example using a Cyrillic code point (character) which looks like >an ASCII or Latin-1 'o' but can be delegated to a different owner such >as microsoft.com vs (replace the 'o's with Cyrillic 'o's). And >punycode and all that (does it help?) The language rules make that impossible to register. There are a few homographs in .com grandfathered from before the language rules were (mostly) debugged but they seem to be harmless. >4. Social networking. Sigh. Yes. >6. Changes in legislation and court decisions? Always a moving target. See http://www.inboxproject.org/ R's, John - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org