Re: Operations requirement: no hop-by-hop

Paul Hoffman / IMC <[email protected]> Sun, 15 Feb 2004 17:02:36 -0800
Newsgroups gmane.mail.ng
Message-ID <p0602042abc55bff1ab1a@[63.202.92.153]>
At 1:17 AM +0100 2/16/04, Iljitsch van Beijnum wrote:
>On 15-feb-04, at 22:58, Paul Hoffman / IMC wrote:
>
>>Trying to get back to making this a requirements discussion, you 
>>are saying that it is a requirement that the transport mechanism 
>>validate policy before delivery.
>
>Why would you transport something that you don't want to have in the 
>first place?

Wrong question. The correct question is "is putting the policy 
mechanism in the transport a better idea than putting it at the 
endpoints?". You say yes; I say no.

>  I don't think we can assume that policy validation is more 
>expensive than transport as a general rule so transporting anyway 
>would be preferable.

I agree: we can't assume either way. What we can assume is that 
putting policy in the middle is more dangerous than putting it at the 
edge. The danger might be worth the value of lower transmissions, but 
I don't think so.

>>>I don't want to have messages transmitted to me that I know I 
>>>don't want to see. Especially when they're big.
>
>>Of course. The cost is that you will refuse some messages that you 
>>might have actually wanted
>
>That's ok as long as this situation is communicated back to the 
>sender so the sender can take appropriate action.

You may find that OK; others may not.

>>Further, the infrastructure that you require is much more prone to 
>>silently dropping mail than today's is.
>
>Why?

Whenever you put policy in the middle, it gets over-used. The 
Internet is rife with examples that we should learn from.

>But I think the mistake we've both been making in this discussion is 
>to treat every message as an independent event. It would be good to 
>consider having to set up a relationship between the sender and 
>recipient first (which could be relatively complex and time 
>consuming) and then be able to check whether the sender is 
>authorized to send messages of a certain type by looking if there is 
>a valid reference to a valid relationship. This check could be 
>relatively fast and simple.

If your requirement is that there be full authentication before 
communication, fine. My requirement is that I can communicate with 
people who I cannot authenticate ahead of time.

--Paul Hoffman, Director
--Internet Mail Consortium