Re: Why SRS really sucks

"Johann Steigenberger" <[email protected]> Tue, 28 Mar 2006 17:11:53 +0000 (UTC)
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
Hi Julian,
 
>> The domainowner must have the chance to prevent forwarding,
>> if he likes to do so ....
 
>even if the forwarder rewrites the sender address to their own domain? 
>Are you kidding? This is simply not possible. Information can always be 
>copied and "forwarded". You'll never be able to prevent that!
 
>> And if you continue saying SRS is necessary for any reason,
>> i have to tell you that i wish there were a parameter like NOFORWARD,
>> which could be added to SPF.
 
>That would be pointless, just like the various "no-copy" bits in the TV 
>broadcasting or storage medium industry. Such a thing can only work if 
>ALL devices honor it, i.e. non-compliant devices are outlawed.
 
I don“t think so:
 
Getting an SRS Mail you always have an envelope-from like this:
SRS*=*[email protected]
 
If SPF would in such a scenario check the initial domain in the localpart
(in our example forwardet-domain.com) too,
and not only the domainpart (forwarder.com), and it found that the forwarder
did against the domainowners direction, this would clearly be an indicator
to
blacklist the forwarder for SRS-Abuse.
 
This would logically work ...
 
Yes i know, Tom Lathi will tell me that this would violate RFCs ....
But: SRS itself is violating the RFCs too :-)
Or is there anyone which want to tell me that someone using SRS will take a
standard NDR ???
 
:-))) 
 
i  think seriously not after all those "SRS is soo cool to prevent faked NDR
 Stories :-)
 
-- 
 
Johann Steigenberger 
Blacklistmaster at UCEPROTECT-Network 
http://www.uceprotect.net