Re: Why SRS really sucks
"Johann Steigenberger" <[email protected]> Mon, 3 Apr 2006 12:26:47 +0000 (UTC)
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
--------------Boundary-00=_SVB5QL80000000000000 Content-Type: Text/Plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable >Challenge/response systems are broken by design (and if UCEPROTECT does = =0D >that kind of thing, it is, too). And even then, they will usually not =0D >require manual entry of envelope sender addresses.=0D =0D UCEPROTECT does not make challenge response ....=0D You have whitelists and blacklists followed by your policy.=0D =0D If something for ever reason can not get thru your policy,=0D then your mail is rejected.=0D for e.G.=0D We make a decision on smtp dialog after rcpt to:=0D =0D RCPT TO: [email protected]=0D 550 Your mail was rejected, because your Server has no PTR. To have an exception made for you emailaddress contact us using the form on ...=0D =0D So you see not we send the NDR, the System which tried to deliver will do that ...=0D Thats no challenge response ...=0D =0D If that user enters his emailadress at the form, it becomes whitelisted, so it will pass next time ...=0D =0D We know many Systems out there which do similair things=0D As soon as your reciever System uses Envelope data for deciding if or if not to accept your=0D mail you will always loose by using SRS=0D =0D >> SRS makes that also impossible for senders .... thats the consequence of= =0D >> faking envelope datas ...=0D =0D >SRS does not fake envelope sender addresses. If you believe that, then you= =0D >have understood _neither_ the point of SRS _nor_ that of SPF.=0D =0D I have understood what it does ...=0D And i found SPF is cool.=0D But modifying anything in envelope is logically considered as a fake to me.. .=0D Every technology which modifies envelope data is poorly designed ....=0D =0D -- =0D =0D Johann Steigenberger =0D Blacklistmaster at UCEPROTECT-Network =0D http://www.uceprotect.net=20 ------- To unsubscribe, change your address, or temporarily deactivate your subscri= ption,=20 please go to http://v2.listbox.com/member/[email protected]= x.com --------------Boundary-00=_SVB5QL80000000000000 Content-Type: Text/HTML; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable <HTML><HEAD> <META http-equiv=3DContent-Type content=3D"text/html; charset=3Diso-8859-1"> <META content=3D"IncrediMail 1.0" name=3DGENERATOR> <!--IncrdiXMLRemarkStart> <IncrdiX-Info> <X-FID>FLAVOR00-NONE-0000-0000-000000000000</X-FID> <X-FVER></X-FVER> <X-CNT>;</X-CNT> </IncrdiX-Info> <IncrdiXMLRemarkEnd--> </HEAD> <BODY style=3D"BACKGROUND-POSITION: 0px 0px; FONT-SIZE: 12pt; MARGIN: 5px 1= 0px 10px; FONT-FAMILY: Arial" bgColor=3D#ffffff background=3D"" scroll=3Dye= s ORGYPOS=3D"0" X-FVER=3D"3.0"> <TABLE id=3DINCREDIMAINTABLE cellSpacing=3D0 cellPadding=3D2 width=3D"100%"= border=3D0> <TBODY> <TR> <TD id=3DINCREDITEXTREGION style=3D"FONT-SIZE: 12pt; CURSOR: auto; FONT-FAM= ILY: Arial" width=3D"100%"> <DIV>>Challenge/response systems are broken by design (and if UCEPROTECT= does <BR>>that kind of thing, it is, too). And even then, they will usu= ally not <BR>>require manual entry of envelope sender addresses.<BR></DI= V> <DIV>UCEPROTECT does not make challenge response ....</DIV> <DIV>You have whitelists and blacklists followed by your policy.</DIV> <DIV> </DIV> <DIV>If something for ever reason can not get thru your policy,</DIV> <DIV>then your mail is rejected.</DIV> <DIV>for e.G.</DIV> <DIV>We make a decision on smtp dialog after rcpt to:</DIV> <DIV> </DIV> <DIV>RCPT TO: <A href=3D"mailto:[email protected]">[email protected]= m</A></DIV> <DIV>550 Your mail was rejected, because your Server has no PTR. To have an= exception made for you emailaddress contact us using the form on ...</DIV> <DIV> </DIV> <DIV>So you see not we send the NDR, the System which tried to deliver will= do that ...</DIV> <DIV>Thats no challenge response ...</DIV> <DIV> </DIV> <DIV>If that user enters his emailadress at the form, it becomes whiteliste= d, so it will pass next time ...</DIV> <DIV> </DIV> <DIV>We know many Systems out there which do similair things</DIV> <DIV>As soon as your reciever System uses Envelope data for deciding if or = if not to accept your</DIV> <DIV>mail you will always loose by using SRS</DIV> <DIV> <BR>>> SRS makes that also impossible for senders .... tha= ts the consequence of<BR>>> faking envelope datas ...<BR><BR>>SRS = does not fake envelope sender addresses. If you believe that, then you <BR>= >have understood _neither_ the point of SRS _nor_ that of SPF.<BR></DIV> <DIV>I have understood what it does ...</DIV> <DIV>And i found SPF is cool.</DIV> <DIV>But modifying anything in envelope is logically considered as a fake t= o me....</DIV> <DIV>Every technology which modifies envelope data is poorly designed ....<= /DIV> <DIV> </DIV> <DIV>-- <BR><BR>Johann Steigenberger <BR>Blacklistmaster at UCEPROTECT-Netw= ork <BR><A title=3Dhttp://www.uceprotect.net href=3D"http://www.uceprotect.= net/">http://www.uceprotect.net</A> <BR><BR></DIV></TD></TR> <TR> <TD id=3DINCREDIFOOTER width=3D"100%"> <TABLE cellSpacing=3D0 cellPadding=3D0 width=3D"100%"> <TBODY> <TR> <TD width=3D"100%"></TD> <TD id=3DINCREDISOUND vAlign=3Dbottom align=3Dmiddle></TD> <TD id=3DINCREDIANIM vAlign=3Dbottom align=3Dmiddle></TD></TR></TBODY></TAB= LE></TD></TR></TBODY></TABLE><HR> To unsubscribe, change your address, or temporarily deactivate your subscri= ption,=20 please go to <A HREF=3D"http://v2.listbox.com/member/?listname=3Dsrs-discus= [email protected]">http://v2.listbox.com/member/[email protected]= istbox.com</A> </BODY></HTML> --------------Boundary-00=_SVB5QL80000000000000--