Re: How is XMPP better than SMTP for spam prevention?

Torsten Bronger <[email protected]>
Newsgroups gmane.network.jabber.user
Organization Phoenix Foundation
Message-ID <[email protected]>
Hallöchen!

Let me turn into devil's advocate for this thread.  :-)

Peter Saint-Andre writes:

> [...]
>
> 1. In XMPP, the sender's address is not asserted by the sender's
> client but instead is stamped by the sender's server. [...]
>
> 2. In XMPP, servers check each other's identities, either through
> a DNS-based "dialback" protocol (RFC 3920 / XEP-0220) or real
> server certificates. [...]
>
> 3. So far, server dialback has been sufficient to prevent most
> address spoofing on the network, but we have a certificate
> authority in place (visit https://www.xmpp.net/ for details) and
> we could fairly easily upgrade the network to certificate-based
> authentication between servers if needed.

Okay, but what do you do with this information?  Maintaining
blacklists?  See below.

> 4. XMPP is pure XML, and attackers can't easily attach malware
> like scripts and viruses to Jabber messages.  [...]

If XMPP becomes more important in daily communication, it will be
also more intensively used to transfer binary data.  The same
happened to email in its history.  So it will be the same as with
email: sane client implementations must save us rather than the
protocol itself.  By the way, malware-via-http-link and phishing
works for XMPP, too.

> 5. A great deal of email spam (or spam+malware) is directed against
> a single platform: Outlook running on Windows.  [...]

I don't think so.  While I strongly dislike the use of Outlook, it
is not the bad Outlook anymore from four years ago.  The most recent
UPS virus email hit a couple of Thunderbird-using collegues.  If you
really want to start the malicious attachment, no email client can
help you.

> 6. In IM systems, people are accustomed to sharing presence /
> adding someone to their buddy list. [...]

Subscription requests are enough for spammers.

> 7. All XMPP server codebases have rate limiting in place to
> prevent a single client from sending a large number of messages
> [...] in a short period of time.

Then generate a lot of pseudo users in a spamming server.

> [...]
>
> 9. IM systems have traditionally been quite fragmented (and in
> many ways still are -- as witness ICQ, AIM, MSN, Yahoo!, Skype,
> etc.) so there isn't the expectation that you'll necessarily be
> able to send a message to any random person on the Internet. [...]

As long as a message costs hardly a milli-lira, it is not
significant to spammers whether they reach X people, or
X/<number-of-networks>.  In (their) worst case, they lose only one
order of magnitude, so the spam model still scales very well.

> [...]
>
> However, XMPP does not need to be perfect. You don't need to be
> the fastest antelope in the herd to avoid being eaten by the lion,
> you just need to be faster than the slow antelope who get caught.

Well, I don't think that the anti-spam plan should be built on the
existence of other less spam-proof networks, not even partly.
Besides, lions will not only focus on the slow antelope but also on
the fat one.  And we want XMPP to become fat, don't we?  ;-)


Sorry but I'm not convinced.  This sounds like a mixture of
hoping-for-the-best and application of SMTP anti-spam techniques
that have turned out to be rather wasteful.

However, I see one advantage over SMTP, namely that there's still an
almost completely non-commercial community that has some sort of
central authority (XSF).  So: Make a server whitelist!
https://www.xmpp.net/ is the first step in this direction.  Only
servers on this list make S2S traffic.  Then, you need an automatic
tool for measuring spam, something like the SpamAssassin -- not for
filtering but only for measurements.  So it needn't be perfect.  And
every server that sends spam above a threshold is first warned and
then removed from the list.

This would break the potential benefit for spammerd by *several*
orders of magnitude, and then it is not worth it anymore.

[SMTP can't do it because a) there is no significant authority and
b) Hotmail, Gmail, GMX etc can't sell their products anymore if
there is no spam.]

Maybe you had this in mind with your points 1-3, however, I didn't
see it there.

Tschö,
Torsten.

-- 
Torsten Bronger, aquisgrana, europa vetus
                   Jabber ID: [email protected]

_______________________________________________
This is JUser -- a mailing list for end users of Jabber clients.

Don't like email? Try the forum:
http://www.jabberforum.org/forumdisplay.php?f=21

To unsubscribe, send email to 
[email protected]
or go to the following web 
page, scroll all the way down, 
and type in your email address:

http://mail.jabber.org/mailman/listinfo/juser
_______________________________________________
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.