RE: CBV

"Seth Goodman" <[email protected]>
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
> From: Mark Shewmaker
> Sent: Friday, May 07, 2004 3:48 AM
>
>
> On Fri, 2004-05-07 at 04:00, [email protected] wrote:
> >
> > Surely, at this point, a simpler and easier solution would be only to
> > accept PGP signed messages from a verifiable source, and
> > possibly include
> > a set of permissible source addresses in the PKI infrastructure
> > with each
> > public key.
> >
> > That's what this starts to sound like.
>
> Hand-waving argument written at 4am here:
>
> Even while suggesting the two types of checksums for SES, I have similar
> misgivings, but:
>
>  o SES has the VERP-ish you-can-reject-bad-bounces feature that SPF by
>    itself doesn't have.
>  o SES has other flaws.
>
> I am curious what happens to SES if all its "other flaws" can be
> reasonably addressed, because right now SES and SPF, in my mind at
> least, mesh with each other but somewhat uncomfortably.

That's what we're all curious about and why I believe it is worth
discussing.

>
> Seeing the way Seth (I think it was Seth) looked at SRS and found that
> doing something similar from the get-go (SES) gets you a lot of SPF-ish
> advantages and the VERP-ish feature, I'm hoping that an SES tweaked
> enough to address its admitted shortcomings can help him or someone else
> figure out a better way it can mesh with spf.

It was David Woodhouse, as far as I know, that first realized that the SRS
signature by itself allowed you to reject bogus bounces.  I share your hope
that by investigating this approach, we can figure out a more optimal
overall solution, whatever it looks like.

>
> To me SES looks like a necessary puzzle piece that just doesn't quite
> fit into the SPF scheme of things for reasons I can neither quite put my
> finger on nor understand how to correct.  I have the possibly irrational
> notion that figuring out a solution to the SES flaws (which seems
> tantalizingly close at hand) can help in understanding the puzzle piece.
>
> That's why I'm hoping we can find good solutions to the SES things
> talked about in this thread.

Lightweight sender authentication really is a puzzle.  Each of the systems
we are discussing solve parts of the problem, but so far, none of them does
the whole thing and each has some undesirable baggage.

>
> Sp, for the moment I'm pushing aside the fact that these suggestions
> sound eerily reminiscent to PK-type solutions, but expect to have to
> come back to it later.
>
> (I hope this makes sense!)

It certainly does to me.

--

Seth Goodman
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.