RE: CBV
"Seth Goodman" <[email protected]>
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
> From: [email protected] > Sent: Friday, May 07, 2004 3:01 AM > To: [email protected] > Subject: RE: [srs-discuss] CBV > > <...> > Surely, at this point, a simpler and easier solution would be only to > accept PGP signed messages from a verifiable source, and possibly include > a set of permissible source addresses in the PKI infrastructure with each > public key. > > That's what this starts to sound like. PGP has always been on the table as a possibility. Doing a body checksum does move SES a bit closer to a public key system, but so far without the PKI. I don't particularly like this development, either, but I think we should continue the discussion and see where it leads. As far as PGP itself goes, the PKI is a fair amount of baggage and the trust model is not easy to deal with for average users. More importantly, I don't think it solves the original problem we have set out for ourselves. That is, provide a reasonable amount of accountability for senders of email without putting an unreasonable burden on either party, but particularly on the recipients. SPF, SRS and SES all attempt to validate MAIL FROM:. PGP, on the other hand, was meant to verify the RFC2822 headers, protect the message body and allow for public key encryption. It does nothing to authenticate MAIL FROM:, which SPF correctly identified as the first necessary step in providing accountability to senders. Your suggestion of putting permitted sending machines into the PKI is very interesting, but the nature of the PKI makes that information unreliable. Unlike the DNS, anyone can put a cert into the PKI without the domain owner's knowledge or permission. -- Seth Goodman