RE: CBV
Mark Shewmaker <[email protected]>
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 2004-05-07 at 04:00, [email protected] wrote: > > Surely, at this point, a simpler and easier solution would be only to > accept PGP signed messages from a verifiable source, and possibly include > a set of permissible source addresses in the PKI infrastructure with each > public key. > > That's what this starts to sound like. Hand-waving argument written at 4am here: Even while suggesting the two types of checksums for SES, I have similar misgivings, but: o SES has the VERP-ish you-can-reject-bad-bounces feature that SPF by itself doesn't have. o SES has other flaws. I am curious what happens to SES if all its "other flaws" can be reasonably addressed, because right now SES and SPF, in my mind at least, mesh with each other but somewhat uncomfortably. Seeing the way Seth (I think it was Seth) looked at SRS and found that doing something similar from the get-go (SES) gets you a lot of SPF-ish advantages and the VERP-ish feature, I'm hoping that an SES tweaked enough to address its admitted shortcomings can help him or someone else figure out a better way it can mesh with spf. To me SES looks like a necessary puzzle piece that just doesn't quite fit into the SPF scheme of things for reasons I can neither quite put my finger on nor understand how to correct. I have the possibly irrational notion that figuring out a solution to the SES flaws (which seems tantalizingly close at hand) can help in understanding the puzzle piece. That's why I'm hoping we can find good solutions to the SES things talked about in this thread. Sp, for the moment I'm pushing aside the fact that these suggestions sound eerily reminiscent to PK-type solutions, but expect to have to come back to it later. (I hope this makes sense!) -- Mark Shewmaker [email protected]