Re: Why SRS really sucks

"Stuart D. Gathman" <[email protected]> Mon, 27 Mar 2006 15:02:19 -0500 (EST)
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
On Mon, 27 Mar 2006, Tom Lahti wrote:

> >I hate to tell you this, but we block specific users all the time -
> >irrespective of SRS.  When '[email protected]' (to take a recent example) sends
> >us hundreds of spam, into the blacklist he goes.  There is no
> >reason for us to block legit yahoo users just because of one
> >miscreant.  If a bunch of users whose cryptic localpart begins
> >with 'SRS' start spamming us - into the blacklist they go.
> 
> Yes, of course.  But you are not assigning SEMANTICS to "simon", you 
> are just dropping it.  You are not trying to determine that "si" 
> means something and "mon" means something else, which is what 
> "assigning semantics" means.

Exactly.  And we are not assigning semantics when we notice that
local parts beginning with 'SRS' from a particular domain are all
spam.  It is just a pattern that we blacklist.

> To do THAT -- to rip apart the local part of a MAIL FROM: that is not 
> in your own domain and try to determine what parts of it mean, is the 
> RFC violation.

Of course!  We don't know the hashkey, and can't even certain whether
the signature is valid!  Perhaps the braindead ISP is actually
an old fashioned open-relay, and the spammers are adding the SRS
coding to make the spam pass SPF and look like it is coming from
the ISP.

-- 
	      Stuart D. Gathman <[email protected]>
    Business Management Systems Inc.  Phone: 703 591-0911 Fax: 703 591-6154
"Confutatis maledictis, flammis acribus addictis" - background song for
a Microsoft sponsored "Where do you want to go from here?" commercial.