Re: SPF is harmful. Adopt it.
Jonathan de Boyne Pollard <[email protected]>
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Organization | Wack's Wicks Works |
| Message-ID | <[email protected]> |
ILT> Why can't the spammer set up a zombie outgoing mail store on ILT> a hacked system, just as spammers today set up zombie e-mail ILT> relay stations on hacked systems? He can. But there are several important differences. First: Recipients can choose to give different priorities to notifications according to whether they "know" the message stores that those notifications reference. So a recipient could instruct his/her recipient MUA that it "knows" AOL's and Sally's message stores. "New" mail on any other message stores would then be flagged as residing on an "unknown" message store, when the list of "new" mail is displayed. Second: Recipients, and recipient notification owners, can arrange to exchange information with one another about suspect message stores. Recipients can also choose to delegate the decision about whom they will pull mail from, to vetting services. Third: A message store is a server, whereas an SMTP Relay puppet is a client. The traffic patterns for the two are noticably different. And note that some organizations _already_ put measures in place to prevent all machines, other than the ones that they specifically designate, from running public servers. (Think about it this way: The solution to the "hijacked machine running a message store to serve up the hijacker's messages" problem is the same as the solution to the "hijacked machine running an FTP server or an SMB server to serve up the hijacker's files" problem.) Fourth, and perhaps most importantly: Setting up a message store on a hijacked machine doesn't get the mail delivered and seen. IM2000 is, after all, a "pull system" and the recipients still have to choose to pull the mail from the message store. Setting up an SMTP Relay server in a hijacked machine, in contrast, causes mail to be pushed out to recipients. (Think about it this way, if you like: A hijacker can _right now_ set up a web server on such a hijacked machine, publishing web pages of the hijacker's choosing. Yet we don't hear about an "unsolicited bulk web page" problem.)