Re: Let's get started
Bryan Campbell <[email protected]> Mon, 21 Jun 2004 10:09:23 -0500
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Organization | STE-MISN |
| Message-ID | <[email protected]> |
O.K. -- That is true . . . BUT, If the zombies are only allowed to relay a certain amount of mail per day through an authorized relay host, and their network throughput / mailstorage capacity is the limiting factor, then IM2000 is still a good idea. The biggest problem that exists today is that anyone, can originate an e-mail to any smtp server if that server is the MX for the target domain. If all smtp clients are forced to use a local authorized relay with capacity limits on originated smtp traffic, then a great deal of these problems go away. It is just that most ISPs do not have the stomach for it. It breaks RFC's. And, it is generally impolite. But, what is more impolite, forcing the insertion of an authorized relay host, or SPAM? Let us just assume for the sake of the discussion that we are going to transparently hi-jack every smtp session as it leaves our networks and force it to an outbound queue/proxy for scanning and originating header insertion. Don't give the smtp client, or subtended server, virus, or worm the chance to send directly to ANY MX host. Force them to talk to your server, or to not talk at all. If their outbound smtp capacity is set to allow only a certain amount of conversations, per minute, hour, day, or total bits of throughput, then at least part of the problem is addressed . . . Not withstanding the IM2000 concept of local outbound message storage. That is just the icing on the cake. As for the zombies . . . We can use the capacity limits to trigger notifications to customers, turn off accounts, and study the smtp flows. Yes, there will be alot of data. Thoughts, rants, insults!? Bryan - Marc Mengel wrote: > Eduardo M. Bragatto wrote: > >> I'm with Sean. I don't think that's a problem with the protocols >> used today. The biggest problem is already known by almost everyone >> involved on this kind of discussion: the receiver's resources being >> used by anyone who want to send a message. > > > I think a lot of the reason interest in IM2000 has dropped off is that > the > *only* thing IM2000 accomplishes is to push the storage cost to the > sender. > > When the senders were *paying* for their sending systems, that was a > reasonable approach to curbing the problem. > > Today, an increasingly large portion of the spam problem is > virus-hijacked systems which have become bulk-email zombies. What > IM2000 would do in that > environment would be to shift the storage cost to these hijacked > machines, > which isn't costing the *originators* of the spam anything. Thus as > long as > we have a large number of internet connected machines which are easy > to break > into, the spam-zombie machines will be out there in large numbers, and > approaches like IM2000 are unfortunately not going to make a big dent > in the > problem. > > Thats my $.02 on the issue. > > On the other hand, there are a fair number of sharp individiuals on > this list > who are at least thinking about these problems, so I keep listening in > case > something that's at least another step in the right direction (which I > think > the IM2000 concept is) comes up. > > Marc > > > -- Bryan Campbell . . . [email protected] STE-MISN 573-775-2111 Key fingerprint: 44AB 0A39 1F4D 0BBE E588 21A7 A4AA B08B AE01 4D39 Key: http://www.misn.com/~bbc/pgp.txt