Re: SPF is harmful. Adopt it.

"Peter J. Holzer" <[email protected]>
Newsgroups gmane.mail.im2000
Message-ID <[email protected]>
On 2004-03-07 17:53:41 -0600, Charles Cazabon wrote:
> Peter J. Holzer <[email protected]> wrote:
> > > Yes, of course it is.  SMTP-based Internet mail is a "store and forward"
> > > system.  A recipient cannot tell the difference between a hijacked machine
> > > running an SMTP Relay puppet and an unknown MTS forwarding mail.  IM2000,
> > > _not_ being a "store and forward" system, does not have this ambiguity.
> > 
> > I fail to see the difference.
> > 
> > Where exactly is the difference between an unknown MTA sending mail from
> > an unknown mail address and an unknown IM2000 agent sending a reference
> > to an unknown message store? In both cases the message can be be flagged
> > as "suspicious".
> 
> In the former case, you, as the recipient, have already paid the cost of
> transporting and storing the message before you can flag it as "suspicious".

No. In IM2000, with only the notification, I have only the (possibly
forged) sender and the IP address of the message store. This is almost
exactly the same information I have in SMTP after the MAIL command (the
possibly forged return path, a rather useless host name, and the IP
address of the relay). This is before the message is transferred. Sure -
if I want to accept the message, mark it up and put it in the mail box,
it has to be transferred. But if I only want to act on the same
information that an IM2000 notification gives me, I can do so without
receiving the message. (And BTW, it would be entirely possible to
return a temporary failure until the user accepts the message - forcing
the sender to queue it)

> With IM2000, you can make that decision /before/ the message is ever
> transported to you, and the sender is paying the cost of storing it.
> It's a critical difference.

No. The cost of storing a spam message is negligible for the sender.
After all, it is only one message (not several million, as with SMTP). 

For the recipient, the cost is not zero: The notification has to be
presented to the user, the user has to decide whether he wants to read
or discard the message, based on very little information (less than he
sees now in his MUA). If he (or his spam filter) needs more information,
the message (or a portion of it) has to be retrieved from the message
store, at which point the traffic becomes comparable to SMTP (typical
spam is tiny).

> > I don't see why the "ostracism mechanisms" in IM2000 should be more
> > effective than RBLs are now.
> 
> Read Jonathon's use cases.

I did.

> Perhaps it will become clearer; the mechanisms in
> IM2000 are much more effective than RBLs, simply because of the pull nature of
> IM2000.

I don't see any reason for your claim. RBLs are ineffective, because the
targets are too volatile and because they are too susceptible to user
errors or sabotage. There is no reason why that should be different for
IM2000. It it certainly not any more difficult for a trojan to set up a
message store than an SMTP client, IRC client and web server. And in any
system where message stores can be reported as spammers, there will be
collateral damage.

> > It isn't perceived as "unsolicited bulk web pages" by users, because they
> > see it in their mailer, but in fact a lot of spam looks very much like spam
> > via IM2000 would look like:
> 
> No, you totally missed Jonathon's point.  His point was that if some spammer
> sets up a website selling his stuff, Joe User doesn't complain about the web
> pages.

Because he never sees them. But in the case of HTML mails only
containing <img>-Tags, he gets the notification and his MUA retrieves
the message from a web server. The user isn't even aware that a web
server is involved - he only sees the mail. This is exactly what IM2000
is supposed to do, isn't it? So spammers are moving to a
IM2000-emulation over SMTP right now, obviously because it is
advantagous to them. 

> Joe User complains about the email he receives (and pays for
> receiving) advertising that web page.

Right. And in case of IM2000, he will receive the notifications. He will
not see a difference to the current situation. It simply doesn't matter
to the user whether the MUA retrieves headers and messages from his
provider's POP server or from message stores scattered around the world. 

	hp

-- 
   _  | Peter J. Holzer    | I think we need two definitions:
|_|_) | Sysadmin WSR       | 1) The problem the *users* want us to solve
| |   | [email protected]         | 2) The problem our solution addresses.
__/   | http://www.hjp.at/ |    -- Phillip Hallam-Baker on spam
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQFATKcffZ+RkG8quy0RAuBhAKCWAEbGW8Id9dW9s+2vYAxEvBfl9wCeIoI0
ZuqmQ+1uAcyiVkbf8X3cVno=
=wH5s
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.