Re: Trouble with Sender Authentication
Julian Mehnle <[email protected]> Wed, 8 Nov 2006 00:27:14 +0000
| Newsgroups | gmane.ietf.mxcomp |
|---|---|
| Message-ID | <[email protected]> |
--nextPart1847150.btYbBVM9Pr Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Content-Disposition: inline Douglas Otis wrote: > On Nov 7, 2006, at 12:02 PM, Julian Mehnle wrote: > >> What is your view about forcing use of different scripts? > > > > I don't understand what you're suggesting here. What do you mean > > by "forcing use of different scripts"? > > Obsoleting existing libraries and related scripts as needed due to > the DDoS potential. The SPF project isn't convinced just yet that there is significant=20 potential for a DoS attack, and if there's any, how real it is, so any=20 statements on consequences would be hypothetical at this time. But trust=20 us, we are taking this seriously. However, we consider it unlikely that=20 obsoleting v=3Dspf1 and the existing libraries would be necessary to=20 mitigate any serious DoS potential. Tightening the limits, perhaps. The problem with your analysis, Doug, is that (1) it attributes several=20 attack vectors to SPF which are really orthogonal, like SMTP's multi-=20 recipient feature or the use of many compromised systems for sending mail,= =20 and (2) with a high probability it overrates both the negative effects=20 (like the victim/attacker traffic ratio) of an attack staged as described,= =20 and the net incentive for doing so in the first place. We are currently investigating the issue further, so expect a thorough=20 analysis from us within the coming weeks. --nextPart1847150.btYbBVM9Pr Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.5 (GNU/Linux) iD8DBQBFUSRowL7PKlBZWjsRAkFVAKCoBctjwZZsPeFIRdFzDssz39mXqgCgi0ul fd5EBs1EhR8E8v6atY/IqQw= =RDzr -----END PGP SIGNATURE----- --nextPart1847150.btYbBVM9Pr--