Re: [Asrg] Re: RMX Records

Hadmut Danisch <hadmut@danisch.de> Tue, 04 March 2003 23:35 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA15409 for <asrg-archive@odin.ietf.org>; Tue, 4 Mar 2003 18:35:30 -0500 (EST)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h24NkCE24670 for asrg-archive@odin.ietf.org; Tue, 4 Mar 2003 18:46:12 -0500
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h24NkC524667 for <asrg-web-archive@optimus.ietf.org>; Tue, 4 Mar 2003 18:46:12 -0500
Received: from www1.ietf.org (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA15381; Tue, 4 Mar 2003 18:34:59 -0500 (EST)
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h24Nj6524584; Tue, 4 Mar 2003 18:45:06 -0500
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h24NiL524520 for <asrg@optimus.ietf.org>; Tue, 4 Mar 2003 18:44:21 -0500
Received: from sklave3.rackland.de (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id SAA15310 for <Asrg@ietf.org>; Tue, 4 Mar 2003 18:33:07 -0500 (EST)
Received: from sodom (uucp@localhost) by sklave3.rackland.de (8.12.8/8.12.8/Debian-1) with BSMTP id h24NZ7i3024946; Wed, 5 Mar 2003 00:35:07 +0100
Received: from sodom.home.danisch.de (localhost [127.0.0.1]) by sodom.home.danisch.de (8.12.8/8.12.8/Debian-1) with ESMTP id h24NYIuB018298 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 5 Mar 2003 00:34:18 +0100
Received: (from hadmut@localhost) by sodom.home.danisch.de (8.12.8/8.12.8/Debian-1) id h24NYI2q018296; Wed, 5 Mar 2003 00:34:18 +0100
From: Hadmut Danisch <hadmut@danisch.de>
To: Vernon Schryver <vjs@calcite.rhyolite.com>
Cc: Asrg@ietf.org
Subject: Re: [Asrg] Re: RMX Records
Message-ID: <20030304233418.GA17958@danisch.de>
References: <004001c2e292$f4374280$4d9cf140@rtr.com> <200303042259.h24MxpJH001648@calcite.rhyolite.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <200303042259.h24MxpJH001648@calcite.rhyolite.com>
User-Agent: Mutt/1.4i
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Wed, 05 Mar 2003 00:34:18 +0100

On Tue, Mar 04, 2003 at 03:59:51PM -0700, Vernon Schryver wrote:
> 
> That is true only provided you still meet the design goals served by
> the existing solutions. 

Insecurity and forgeability have never ever been a design goal
of SMTP. That's a disadvantage, but not a design goal. It has also 
never been a design goal of telnet to make plaintext passwords
available to eavesdroppers.

We cannot fix any security hole as long as we insist on still
fulfilling a so called "design goal" which states insecurity.


Keep in mind the SMTP as we know it was designed more than 20 years
ago (Jon Postels RFC 821 dates from August 1982). In 1982 and before, 
there were almost no security considerations in context of internet
protocols, especially for e-mail. The security business developed in
the 90's. Plain SMTP is one of the last dinosaurs of the pre-security 
era still alive. 

Security didn't play any role in the design of SMTP. Even if it did,
after more than 20 years of progress in internet protocols and
security, such an age-old design goal would require some revision. 

So that so called "design goal" is neither existing nor really relevant.

Hadmut




_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg