Re: Why SRS really sucks

"Johann Steigenberger" <[email protected]> Mon, 3 Apr 2006 12:26:47 +0000 (UTC)
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
--------------Boundary-00=_SVB5QL80000000000000
Content-Type: Text/Plain;
  charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

>Challenge/response systems are broken by design (and if UCEPROTECT does =
=0D
>that kind of thing, it is, too). And even then, they will usually not =0D
>require manual entry of envelope sender addresses.=0D
=0D
UCEPROTECT does not make challenge response ....=0D
You have whitelists and blacklists followed by your policy.=0D
=0D
If something for ever reason can not get thru your policy,=0D
then your mail is rejected.=0D
for e.G.=0D
We make a decision on smtp dialog after rcpt to:=0D
=0D
RCPT TO: [email protected]=0D
550 Your mail was rejected, because your Server has no PTR. To have an
exception made for you emailaddress contact us using the form on ...=0D
=0D
So you see not we send the NDR, the System which tried to deliver will do
that ...=0D
Thats no challenge response ...=0D
=0D
If that user enters his emailadress at the form, it becomes whitelisted, so
it will pass next time ...=0D
=0D
We know many Systems out there which do similair things=0D
As soon as your reciever System uses Envelope data for deciding if or if not
to accept your=0D
mail you will always loose by using SRS=0D
 =0D
>> SRS makes that also impossible for senders .... thats the consequence of=
=0D
>> faking envelope datas ...=0D
=0D
>SRS does not fake envelope sender addresses. If you believe that, then you=
 =0D
>have understood _neither_ the point of SRS _nor_ that of SPF.=0D
=0D
I have understood what it does ...=0D
And i found SPF is cool.=0D
But modifying anything in envelope is logically considered as a fake to me..
.=0D
Every technology which modifies envelope data is poorly designed ....=0D
=0D
-- =0D
=0D
Johann Steigenberger =0D
Blacklistmaster at UCEPROTECT-Network =0D
http://www.uceprotect.net=20

-------
To unsubscribe, change your address, or temporarily deactivate your subscri=
ption,=20
please go to http://v2.listbox.com/member/[email protected]=
x.com

--------------Boundary-00=_SVB5QL80000000000000
Content-Type: Text/HTML;
  charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<HTML><HEAD>
<META http-equiv=3DContent-Type content=3D"text/html; charset=3Diso-8859-1">
<META content=3D"IncrediMail 1.0" name=3DGENERATOR>
<!--IncrdiXMLRemarkStart>
<IncrdiX-Info>
<X-FID>FLAVOR00-NONE-0000-0000-000000000000</X-FID>
<X-FVER></X-FVER>
<X-CNT>;</X-CNT>
</IncrdiX-Info>
<IncrdiXMLRemarkEnd-->
</HEAD>
<BODY style=3D"BACKGROUND-POSITION: 0px 0px; FONT-SIZE: 12pt; MARGIN: 5px 1=
0px 10px; FONT-FAMILY: Arial" bgColor=3D#ffffff background=3D"" scroll=3Dye=
s ORGYPOS=3D"0" X-FVER=3D"3.0">
<TABLE id=3DINCREDIMAINTABLE cellSpacing=3D0 cellPadding=3D2 width=3D"100%"=
 border=3D0>
<TBODY>
<TR>
<TD id=3DINCREDITEXTREGION style=3D"FONT-SIZE: 12pt; CURSOR: auto; FONT-FAM=
ILY: Arial" width=3D"100%">
<DIV>&gt;Challenge/response systems are broken by design (and if UCEPROTECT=
 does <BR>&gt;that kind of thing, it is, too). And even then, they will usu=
ally not <BR>&gt;require manual entry of envelope sender addresses.<BR></DI=
V>
<DIV>UCEPROTECT does not make challenge response ....</DIV>
<DIV>You have whitelists and&nbsp;blacklists followed by your policy.</DIV>
<DIV>&nbsp;</DIV>
<DIV>If something for ever reason can not get thru your policy,</DIV>
<DIV>then your mail is rejected.</DIV>
<DIV>for e.G.</DIV>
<DIV>We make a decision on smtp dialog after rcpt to:</DIV>
<DIV>&nbsp;</DIV>
<DIV>RCPT TO: <A href=3D"mailto:[email protected]">[email protected]=
m</A></DIV>
<DIV>550 Your mail was rejected, because your Server has no PTR. To have an=
 exception made for you emailaddress contact us using the form on ...</DIV>
<DIV>&nbsp;</DIV>
<DIV>So you see not we send the NDR, the System which tried to deliver will=
 do that ...</DIV>
<DIV>Thats no challenge response ...</DIV>
<DIV>&nbsp;</DIV>
<DIV>If that user enters his emailadress at the form, it becomes whiteliste=
d, so it will pass next time ...</DIV>
<DIV>&nbsp;</DIV>
<DIV>We know many Systems out there which do similair things</DIV>
<DIV>As soon as your reciever System uses Envelope data for deciding if or =
if not to accept your</DIV>
<DIV>mail you will always loose by using SRS</DIV>
<DIV>&nbsp;<BR>&gt;&gt; SRS makes that also impossible for senders .... tha=
ts the consequence of<BR>&gt;&gt; faking envelope datas ...<BR><BR>&gt;SRS =
does not fake envelope sender addresses. If you believe that, then you <BR>=
&gt;have understood _neither_ the point of SRS _nor_ that of SPF.<BR></DIV>
<DIV>I have understood what it does ...</DIV>
<DIV>And i found SPF is cool.</DIV>
<DIV>But modifying anything in envelope is logically considered as a fake t=
o me....</DIV>
<DIV>Every technology which modifies envelope data is poorly designed ....<=
/DIV>
<DIV>&nbsp;</DIV>
<DIV>-- <BR><BR>Johann Steigenberger <BR>Blacklistmaster at UCEPROTECT-Netw=
ork <BR><A title=3Dhttp://www.uceprotect.net href=3D"http://www.uceprotect.=
net/">http://www.uceprotect.net</A> <BR><BR></DIV></TD></TR>
<TR>
<TD id=3DINCREDIFOOTER width=3D"100%">
<TABLE cellSpacing=3D0 cellPadding=3D0 width=3D"100%">
<TBODY>
<TR>
<TD width=3D"100%"></TD>
<TD id=3DINCREDISOUND vAlign=3Dbottom align=3Dmiddle></TD>
<TD id=3DINCREDIANIM vAlign=3Dbottom align=3Dmiddle></TD></TR></TBODY></TAB=
LE></TD></TR></TBODY></TABLE><HR>
To unsubscribe, change your address, or temporarily deactivate your subscri=
ption,=20
please go to <A HREF=3D"http://v2.listbox.com/member/?listname=3Dsrs-discus=
[email protected]">http://v2.listbox.com/member/[email protected]=
istbox.com</A>
</BODY></HTML>
--------------Boundary-00=_SVB5QL80000000000000--