Re: Why SRS really sucks
Julian Mehnle <[email protected]> Mon, 3 Apr 2006 12:46:28 +0000
| Newsgroups | gmane.mail.spam.srs.general |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Johann Steigenberger wrote: > Julian Mehnle wrote: > > Challenge/response systems are broken by design (and if UCEPROTECT does > > that kind of thing, it is, too). And even then, they will usually not > > require manual entry of envelope sender addresses. > > UCEPROTECT does not make challenge response .... > You have whitelists and blacklists followed by your policy. > > If something for ever reason can not get thru your policy, > then your mail is rejected. > for e.G. We make a decision on smtp dialog after rcpt to: > RCPT TO: [email protected] > 550 Your mail was rejected, because your Server has no PTR. To have an > exception made for you emailaddress contact us using the form on ... > > So you see not we send the NDR, the System which tried to deliver will > do that ... Thats no challenge response ... Well, yes, it is. The instruction in the SMTP response to enter the e-mail address manually is the challenge, and the original sender entering his e-mail address manually into the form is the response. A challenge does not have to be a generated bounce to be a challenge. A response does not have to be a reply message to be a response. It may be a _different_form_ of C/R, but it is still C/R. > As soon as your reciever System uses Envelope data for deciding if or if > not to accept your mail you will always loose by using SRS Only if your goal is to reject as much mail as possible, legitimate or not. But then you could just as well reject _all_ mail you receive, and no longer have to worry about someone trying to comply with -- and thus "bypass" -- your security measures. Look, complying with security measures isn't the same thing as bypassing them. Doing SRS is "complying with", not "bypassing" SPF. > > SRS does not fake envelope sender addresses. If you believe that, then > > you have understood _neither_ the point of SRS _nor_ that of SPF. > > I have understood what it does ... And i found SPF is cool. > But modifying anything in envelope is logically considered as a fake to > me... So if I take your message and resend it with all the headers unmodified, just using my own envelope sender, then it is a fake? No, it isn't! It is a perfectly legal case of the layer separation between RFC 2821 and RFC 2822. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.2.2 (GNU/Linux) iD8DBQFEMRklwL7PKlBZWjsRAra0AJ41MM/PhZPIV2Svlr3b6gHbCxWNiACfV6OV 3NM1elxX6THGqS28wBZ7WME= =t37S -----END PGP SIGNATURE-----