Re: Re: Why SRS really sucks

David Woodhouse <[email protected]> Mon, 03 Apr 2006 14:53:54 +0100
Newsgroups gmane.mail.spam.srs.general
Message-ID <[email protected]>
On Mon, 2006-04-03 at 13:30 +0000, Julian Mehnle wrote:
> So all e-mail aliases and mailing lists are 'fake' addresses?  Is a 
> postmaster@ address 'fake' because it is forwarded to some real person's 
> address?  Does my work address become fake while I'm on vacation just 
> because it gets forwarded to someone else?  I don't think this definition 
> of 'fake' is very helpful.

'virtual' is a better word, perhaps. Where you cross the line between
'virtual' and 'fake' is subjective. I don't think there's any point in
us trying to _agree_ on precisely where that line is -- and there's no
point in you haranguing Johann about it either. 

He seems to think, and I certainly _do_ think, that mangling the
reverse-path of a mail in transit constitutes 'faking' the reverse-path.
That doesn't mean that either he or I don't understand SRS and SPF,
which is what you suggested.

Your analogy of resending, where you deliberately reintroduced the mail
to the system, perhaps shows a misunderstanding on your part... but in
fact I think you were just being disingenuous.

> What problem?

Er, the problem which led to SRS being invented in the first place?

> I know you're going to reply: "The problem that SPF rejects forwarded mail 
> w/o the sender address rewritten", but that is one of the fundamental 
> points of SPF. 

Well, yes -- I suppose I might have answered that in another context.
The reply above seemed more pertinent though.

It would be very dishonest to claim that to break forwarding is one of
the fundamental _goals_ of SPF.

SPF wasn't invented specifically to stop standard forwarding -- it was
invented to stop _forgery_. It is an unfortunate technical detail that
SPF is unable to tell normal forwarding from 'forgery', as some
forgery-prevention schemes can. 

Some people have therefore chosen to declare that their definition of
'forgery' includes such normal forwarding behaviour, just because SPF
can't tell the difference. That doesn't really help much in the real
world, though.

>  If you don't want that to happen to the mail you send, 
> don't publish SPF.  However if you _do_ want it, there is no problem.  
> Please accept that there are people who do not want their mail to be 
> forwarded w/o the envelope sender address rewritten.  (Like me and many 
> others, Johann seems to belong to that crowd.)

I accept that there are many people who want many things, not all of
them realistic. I give no credence to their desires -- if they send mail
to my users by SMTP, then I will behave in the manner for which there is
decades of precedent. If that user has a .forward file or other similar
mechanism set up, that will include forwarding the mail _intact_, unless
the recipient domain is specifically listed in my list of known-broken
recipients.

I can't really tell if Johann belongs to that crowd -- I've seen only
two emails from him that I recall, and one of those was HTML so I didn't
pay much attention to it. He certainly doesn't seem to be keen on SRS,
because he considers it to be fakery. But I certainly won't argue with
you about what we think Johann might think. If he wants us to know that,
he can state it himself.

-- 
dwmw2