Re: Trouble with Sender Authentication
Douglas Otis <[email protected]> Fri, 10 Nov 2006 08:58:33 -0800
| Newsgroups | gmane.ietf.mxcomp |
|---|---|
| Message-ID | <[email protected]> |
On Nov 9, 2006, at 9:24 PM, John Levine wrote: > >>> Could someone kindly point me to workable CSV library so that I >>> could provide Doug with an example of using CSV to generate >>> highier amount of amplification than his assertions about SPF? > > It'll be a challenge. CSV is a single DNS query per message, so > the only things you get to use for amplification are delegation and > CNAMEs. > > I do agree that the DNS threat from SPF is not qualitatively worse > than what we already put up with for CNAMEs. Chaining CNAMEs does not offer the same distributed attack. CNAME chaining uses resources of the attacker. While CNAMEs can be a problem, they represent a threat than can be identified and handled by the affected party. The SPF attack can not be identified and there is no defense possible. I would call that a qualitative difference. -Doug