[Asrg] Re: New draft on trust-path-discovery (Ono, Kumiko)

gep2@terabites.com Fri, 15 July 2005 20:18 UTC

Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1DtWdJ-0005yM-Fa; Fri, 15 Jul 2005 16:18:05 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1DtWdH-0005xW-E4 for asrg@megatron.ietf.org; Fri, 15 Jul 2005 16:18:03 -0400
Received: from ietf-mx.ietf.org (ietf-mx [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA21490 for <asrg@ietf.org>; Fri, 15 Jul 2005 16:18:00 -0400 (EDT)
From: gep2@terabites.com
Message-Id: <200507152018.QAA21490@ietf.org>
Received: from sccrmhc11.comcast.net ([204.127.202.55]) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1DtX67-0003HH-II for asrg@ietf.org; Fri, 15 Jul 2005 16:47:53 -0400
Date: Fri, 15 Jul 2005 20:17:46 +0000
X-Comment: Sending client does not conform to RFC822 minimum requirements
X-Comment: Date has been added by Maillennium
Received: from WinProxy.anywhere (c-24-0-189-130.hsd1.tx.comcast.net[24.0.189.130]) by comcast.net (sccrmhc11) with SMTP id <2005071520174601100qfqule>; Fri, 15 Jul 2005 20:17:46 +0000
Received: from 192.168.0.114 by 192.168.0.100 (WinProxy); Fri, 15 Jul 2005 15:17:27 -0600
MIME-Version: 1.0
Content-Type: text/plain
Content-Transfer-Encoding: 7bit
To: asrg@ietf.org
X-Mailer: SPRY Mail Version: 04.00.06.17
X-Spam-Score: 0.4 (/)
X-Scan-Signature: f607d15ccc2bc4eaf3ade8ffa8af02a0
Content-Transfer-Encoding: 7bit
Subject: [Asrg] Re: New draft on trust-path-discovery (Ono, Kumiko)
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/asrg>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
Sender: asrg-bounces@ietf.org
Errors-To: asrg-bounces@ietf.org

[quote]

Henning and I wrote up the I-D that proposes a mechanism to find friends
-of-friends and trusted domains, which could be used as a tool to make 
white-list for filtering emails/calls. 

We could not find any WG in the IETF that this draft belongs to, but we 
believe this RG might be interested in this draft. 

Any comments are welcome.

>	Title		: Trust Path Discovery
>	Author(s)	: K. Ono, H. Schulzrinne
>	Filename	: draft-ono-trust-path-discovery-00.txt
>	Pages		: 14
>	Date		: 2005-7-12
>	
>   Chained or transitive trust can be used to determine whether incoming
>   communication is likely to be desirable or not.  We can build a
>   chained trust relationship by introducing friends to out friends, for
>   example.  We propose mechanisms for discovering trust paths and
>   binary responsive trustworthiness.  The trust paths are based on a
>   chain of trust relationships between users, a user and a domain, and
>   domains.  We apply this model to relatively low-value trust
>   establishment, suitable for deciding whether to accept communication
>   requests such as emails, calls, or instant messages from strangers.
>
>A URL for this Internet-Draft is:
>http://www.ietf.org/internet-drafts/draft-ono-trust-path-discovery-00.txt

[end quote]

None of these really work for spam protection, for the simple reason that all it 
takes is for a "reputed/trusted" machine to be taken over by a spambot zombie 
and then you start getting a flood of "trusted" spam.

I recently read on another list that something like 84% of the spam one group 
received (that HAD SPF 'protection') was in fact spam...!  Of course, I've been 
pointing out for more than a year that SPF is stupid because it plain and simple 
DOES NOT SOLVE THE PROBLEM it's being proposed to solve.

I really think it's shameful for these people to claim that these schemes are 
suitable for preventing or controlling spam when in fact they do little or 
nothing at all towards that goal.  :-(

And, again, many of us have a legitimate need to receive unsolicited (or at 
least unexpected) E-mails from folks who will will not have on any kind of 
whitelist.  What I like about MY proposal is that it's content-specific... I am 
willing to accept more advanced forms of mail from specific people, depending on 
who they are;  but I'm willing to accept (subject to it passing approval by an 
additional antispam content filter, of course) at least a restricted subset of 
mail features in a preliminary contact, and that from just about anybody.

Gordon Peterson                  http://personal.terabites.com/
1977-2002  Twenty-fifth anniversary year of Local Area Networking!
Support free and fair US elections!  http://stickers.defend-democracy.org
12/19/98: Partisan Republicans scornfully ignore the voters they "represent".
12/09/00: the date the Republican Party took down democracy in America.



_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg