spammers using SPF more than anyone else

Adam Back <[email protected]>
Newsgroups gmane.mail.spam.hashcash
Message-ID <[email protected]>
http://it.slashdot.org/it/04/09/03/1825214.shtml?tid=111&tid=95&tid=218

> SPF and Sender ID (SID) aren't nearly as effective as we expected
> them to be when combatting spam. The reason? Spammers are able to
> publish their own records, too. 'Spammers are now better than
> companies at reporting the source of their e-mail,' says Paul Judge,
> noted spam researcher and CipherTrust CTO.

I've been trying to tell people this, now can say "told you so".  SPF
just forces spammers to jump through SPF hoops it doesn't stop them
spamming.  But you can't charge individuals much for SPF hoops,
therefore spammers can create SPF hoops just fine.

It turns out they can in fact create them more reliably than everyone
else at present.

Other nice quotes (from the article):

> three times more spam passes SPF checks than fails it,

> 34 percent more [SPF marked msggs] are spam than legitimate e-mail

About the only good thing you could say about SPF is that if it got to
100% deployment, CAMRAM's current Sender address keyed whitelisting
would be less risky.

But at the cost of breaking many current email scenarios, and adding
to roaming users config headaches I think it's a net loss.

And domainkeys (or CAMRAM's discussed header signature based
whitelists) if deployed 100% could achieve the same more simply.

Adam
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.