Re: SPF is harmful. Adopt it.
Ian Lance Taylor <[email protected]>
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Message-ID | <[email protected]> |
Jonathan de Boyne Pollard <[email protected]> writes: > First: Recipients can choose to give different priorities to notifications > according to whether they "know" the message stores that those notifications > reference. So a recipient could instruct his/her recipient MUA that it > "knows" AOL's and Sally's message stores. "New" mail on any other message > stores would then be flagged as residing on an "unknown" message store, when > the list of "new" mail is displayed. This is not different from SMTP. > Second: Recipients, and recipient notification owners, can arrange to exchange > information with one another about suspect message stores. Recipients can > also choose to delegate the decision about whom they will pull mail from, to > vetting services. This is not different from SMTP plus RBL and similar systems. > Third: A message store is a server, whereas an SMTP Relay puppet is a client. > The traffic patterns for the two are noticably different. And note that some > organizations _already_ put measures in place to prevent all machines, other > than the ones that they specifically designate, from running public servers. > (Think about it this way: The solution to the "hijacked machine running a > message store to serve up the hijacker's messages" problem is the same as the > solution to the "hijacked machine running an FTP server or an SMB server to > serve up the hijacker's files" problem.) This is a good point. I'll note that I personally run my own web/FTP/SMTP servers on my personal systems, but I admit that that is unusual these days. > Fourth, and perhaps most importantly: Setting up a message store on a hijacked > machine doesn't get the mail delivered and seen. IM2000 is, after all, a > "pull system" and the recipients still have to choose to pull the mail from > the message store. Setting up an SMTP Relay server in a hijacked machine, in > contrast, causes mail to be pushed out to recipients. (Think about it this > way, if you like: A hijacker can _right now_ set up a web server on such a > hijacked machine, publishing web pages of the hijacker's choosing. Yet we > don't hear about an "unsolicited bulk web page" problem.) You may not have heard about it, but I have. You can now reportedly download zombie packages which take over unsuspecting Windows systems, start up porn web sites, and accept credit card numbers, with money flowing back to the originator. These zombie web sites just sit there running on the computers of people with DSL or cable. The computer owners typically notice nothing, except slightly slower available bandwidth. Ian