RE: CBV
"Seth Goodman" <[email protected]>
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
> From: Mark Shewmaker > Sent: Friday, May 07, 2004 3:48 AM > > > On Fri, 2004-05-07 at 04:00, [email protected] wrote: > > > > Surely, at this point, a simpler and easier solution would be only to > > accept PGP signed messages from a verifiable source, and > > possibly include > > a set of permissible source addresses in the PKI infrastructure > > with each > > public key. > > > > That's what this starts to sound like. > > Hand-waving argument written at 4am here: > > Even while suggesting the two types of checksums for SES, I have similar > misgivings, but: > > o SES has the VERP-ish you-can-reject-bad-bounces feature that SPF by > itself doesn't have. > o SES has other flaws. > > I am curious what happens to SES if all its "other flaws" can be > reasonably addressed, because right now SES and SPF, in my mind at > least, mesh with each other but somewhat uncomfortably. That's what we're all curious about and why I believe it is worth discussing. > > Seeing the way Seth (I think it was Seth) looked at SRS and found that > doing something similar from the get-go (SES) gets you a lot of SPF-ish > advantages and the VERP-ish feature, I'm hoping that an SES tweaked > enough to address its admitted shortcomings can help him or someone else > figure out a better way it can mesh with spf. It was David Woodhouse, as far as I know, that first realized that the SRS signature by itself allowed you to reject bogus bounces. I share your hope that by investigating this approach, we can figure out a more optimal overall solution, whatever it looks like. > > To me SES looks like a necessary puzzle piece that just doesn't quite > fit into the SPF scheme of things for reasons I can neither quite put my > finger on nor understand how to correct. I have the possibly irrational > notion that figuring out a solution to the SES flaws (which seems > tantalizingly close at hand) can help in understanding the puzzle piece. > > That's why I'm hoping we can find good solutions to the SES things > talked about in this thread. Lightweight sender authentication really is a puzzle. Each of the systems we are discussing solve parts of the problem, but so far, none of them does the whole thing and each has some undesirable baggage. > > Sp, for the moment I'm pushing aside the fact that these suggestions > sound eerily reminiscent to PK-type solutions, but expect to have to > come back to it later. > > (I hope this makes sense!) It certainly does to me. -- Seth Goodman