Re: Let's get started

Bryan Campbell <[email protected]> Mon, 21 Jun 2004 10:09:23 -0500
Newsgroups gmane.mail.im2000
Organization STE-MISN
Message-ID <[email protected]>
O.K.  --  That is true . . . BUT,   If the zombies are only allowed to 
relay a certain amount of mail per day through an authorized relay host, 
and their network throughput / mailstorage capacity is the limiting 
factor, then IM2000 is still a good idea.

The biggest problem that exists today is that anyone, can originate an 
e-mail to any smtp server if that server is the MX for the target domain.

If all smtp clients are forced to use a local authorized relay with 
capacity limits on originated smtp traffic, then a great deal of these 
problems go away.  It is just that most ISPs do not have the stomach for 
it.  It breaks RFC's.  And, it is generally impolite. 

But, what is more impolite, forcing the insertion of an authorized relay 
host, or SPAM?

Let us just assume for the sake of the discussion that we are going to 
transparently hi-jack every smtp session as it leaves our networks and 
force it to an outbound queue/proxy for scanning and originating header 
insertion.  Don't give the smtp client, or subtended server, virus, or 
worm the chance to send directly to ANY MX host.  Force them to talk to 
your server, or to not talk at all.

If their outbound smtp capacity is set to allow only a certain amount of 
conversations, per minute, hour, day, or total bits of throughput, then 
at least part of the problem is addressed . . . Not withstanding the 
IM2000 concept of local outbound message storage.  That is just the 
icing on the cake.

As for the zombies . . . We can use the capacity limits to trigger 
notifications to customers, turn off accounts, and study the smtp 
flows.  Yes, there will be alot of data.

Thoughts, rants, insults!?

Bryan -


Marc Mengel wrote:

> Eduardo M. Bragatto wrote:
>
>>     I'm with Sean. I don't think that's a problem with the protocols 
>> used today. The biggest problem is already known by almost everyone 
>> involved on this kind of discussion: the receiver's resources being 
>> used by anyone who want to send a message.
>
>
> I think a lot of the reason interest in IM2000 has dropped off is that 
> the
> *only* thing IM2000 accomplishes is to push the storage cost to the 
> sender.
>
> When the senders were *paying* for their sending systems, that was a 
> reasonable approach to curbing the problem.
>
> Today, an increasingly large portion of the spam problem is 
> virus-hijacked systems which have become bulk-email zombies.  What 
> IM2000 would do in that
> environment would be to shift the storage cost to these hijacked 
> machines,
> which isn't costing the *originators* of the spam anything.  Thus as 
> long as
> we have a large number of internet connected machines which are easy 
> to break
> into, the spam-zombie machines will be out there in large numbers, and 
> approaches like IM2000 are unfortunately not going to make a big dent 
> in the
> problem.
>
> Thats my $.02 on the issue.
>
> On the other hand, there are a fair number of sharp individiuals on 
> this list
> who are at least thinking about these problems, so I keep listening in 
> case
> something that's at least another step in the right direction (which I 
> think
> the IM2000 concept is) comes up.
>
> Marc
>
>
>

-- 

Bryan Campbell . . . [email protected]

STE-MISN	573-775-2111

Key fingerprint:  44AB 0A39 1F4D 0BBE E588  21A7 A4AA B08B AE01 4D39
Key:  http://www.misn.com/~bbc/pgp.txt