Re: Trouble with Sender Authentication

Douglas Otis <[email protected]> Fri, 10 Nov 2006 08:58:33 -0800
Newsgroups gmane.ietf.mxcomp
Message-ID <[email protected]>

On Nov 9, 2006, at 9:24 PM, John Levine wrote:

>
>>> Could someone kindly point me to workable CSV library so that I  
>>> could provide Doug with an example of using CSV to generate  
>>> highier amount of amplification than his assertions about SPF?
>
> It'll be a challenge.  CSV is a single DNS query per message, so  
> the only things you get to use for amplification are delegation and  
> CNAMEs.
>
> I do agree that the DNS threat from SPF is not qualitatively worse  
> than what we already put up with for CNAMEs.

Chaining CNAMEs does not offer the same distributed attack.  CNAME  
chaining uses resources of the attacker.  While CNAMEs can be a  
problem, they represent a threat than can be identified and handled  
by the affected party.  The SPF attack can not be identified and  
there is no defense possible.  I would call that a qualitative  
difference.

-Doug