Re: Trouble with Sender Authentication

Julian Mehnle <[email protected]> Wed, 8 Nov 2006 00:27:14 +0000
Newsgroups gmane.ietf.mxcomp
Message-ID <[email protected]>
--nextPart1847150.btYbBVM9Pr
Content-Type: text/plain;
  charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Content-Disposition: inline

Douglas Otis wrote:
> On Nov 7, 2006, at 12:02 PM, Julian Mehnle wrote:
> >> What is your view about forcing use of different scripts?
> >
> > I don't understand what you're suggesting here.  What do you mean
> > by "forcing use of different scripts"?
>
> Obsoleting existing libraries and related scripts as needed due to
> the DDoS potential.

The SPF project isn't convinced just yet that there is significant=20
potential for a DoS attack, and if there's any, how real it is, so any=20
statements on consequences would be hypothetical at this time.  But trust=20
us, we are taking this seriously.  However, we consider it unlikely that=20
obsoleting v=3Dspf1 and the existing libraries would be necessary to=20
mitigate any serious DoS potential.  Tightening the limits, perhaps.

The problem with your analysis, Doug, is that (1) it attributes several=20
attack vectors to SPF which are really orthogonal, like SMTP's multi-=20
recipient feature or the use of many compromised systems for sending mail,=
=20
and (2) with a high probability it overrates both the negative effects=20
(like the victim/attacker traffic ratio) of an attack staged as described,=
=20
and the net incentive for doing so in the first place.

We are currently investigating the issue further, so expect a thorough=20
analysis from us within the coming weeks.


--nextPart1847150.btYbBVM9Pr
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.5 (GNU/Linux)

iD8DBQBFUSRowL7PKlBZWjsRAkFVAKCoBctjwZZsPeFIRdFzDssz39mXqgCgi0ul
fd5EBs1EhR8E8v6atY/IqQw=
=RDzr
-----END PGP SIGNATURE-----

--nextPart1847150.btYbBVM9Pr--