Re: SPF is harmful. Adopt it.
"Peter J. Holzer" <[email protected]>
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Message-ID | <[email protected]> |
On 2004-03-07 17:53:41 -0600, Charles Cazabon wrote: > Peter J. Holzer <[email protected]> wrote: > > > Yes, of course it is. SMTP-based Internet mail is a "store and forward" > > > system. A recipient cannot tell the difference between a hijacked machine > > > running an SMTP Relay puppet and an unknown MTS forwarding mail. IM2000, > > > _not_ being a "store and forward" system, does not have this ambiguity. > > > > I fail to see the difference. > > > > Where exactly is the difference between an unknown MTA sending mail from > > an unknown mail address and an unknown IM2000 agent sending a reference > > to an unknown message store? In both cases the message can be be flagged > > as "suspicious". > > In the former case, you, as the recipient, have already paid the cost of > transporting and storing the message before you can flag it as "suspicious". No. In IM2000, with only the notification, I have only the (possibly forged) sender and the IP address of the message store. This is almost exactly the same information I have in SMTP after the MAIL command (the possibly forged return path, a rather useless host name, and the IP address of the relay). This is before the message is transferred. Sure - if I want to accept the message, mark it up and put it in the mail box, it has to be transferred. But if I only want to act on the same information that an IM2000 notification gives me, I can do so without receiving the message. (And BTW, it would be entirely possible to return a temporary failure until the user accepts the message - forcing the sender to queue it) > With IM2000, you can make that decision /before/ the message is ever > transported to you, and the sender is paying the cost of storing it. > It's a critical difference. No. The cost of storing a spam message is negligible for the sender. After all, it is only one message (not several million, as with SMTP). For the recipient, the cost is not zero: The notification has to be presented to the user, the user has to decide whether he wants to read or discard the message, based on very little information (less than he sees now in his MUA). If he (or his spam filter) needs more information, the message (or a portion of it) has to be retrieved from the message store, at which point the traffic becomes comparable to SMTP (typical spam is tiny). > > I don't see why the "ostracism mechanisms" in IM2000 should be more > > effective than RBLs are now. > > Read Jonathon's use cases. I did. > Perhaps it will become clearer; the mechanisms in > IM2000 are much more effective than RBLs, simply because of the pull nature of > IM2000. I don't see any reason for your claim. RBLs are ineffective, because the targets are too volatile and because they are too susceptible to user errors or sabotage. There is no reason why that should be different for IM2000. It it certainly not any more difficult for a trojan to set up a message store than an SMTP client, IRC client and web server. And in any system where message stores can be reported as spammers, there will be collateral damage. > > It isn't perceived as "unsolicited bulk web pages" by users, because they > > see it in their mailer, but in fact a lot of spam looks very much like spam > > via IM2000 would look like: > > No, you totally missed Jonathon's point. His point was that if some spammer > sets up a website selling his stuff, Joe User doesn't complain about the web > pages. Because he never sees them. But in the case of HTML mails only containing <img>-Tags, he gets the notification and his MUA retrieves the message from a web server. The user isn't even aware that a web server is involved - he only sees the mail. This is exactly what IM2000 is supposed to do, isn't it? So spammers are moving to a IM2000-emulation over SMTP right now, obviously because it is advantagous to them. > Joe User complains about the email he receives (and pays for > receiving) advertising that web page. Right. And in case of IM2000, he will receive the notifications. He will not see a difference to the current situation. It simply doesn't matter to the user whether the MUA retrieves headers and messages from his provider's POP server or from message stores scattered around the world. hp -- _ | Peter J. Holzer | I think we need two definitions: |_|_) | Sysadmin WSR | 1) The problem the *users* want us to solve | | | [email protected] | 2) The problem our solution addresses. __/ | http://www.hjp.at/ | -- Phillip Hallam-Baker on spam
signature.asc
(application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQFATKcffZ+RkG8quy0RAuBhAKCWAEbGW8Id9dW9s+2vYAxEvBfl9wCeIoI0 ZuqmQ+1uAcyiVkbf8X3cVno= =wH5s -----END PGP SIGNATURE-----