Re: [Asrg] CRI Header

Yakov Shafranovich <research@solidmatrix.com> Sun, 15 June 2003 05:40 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id BAA11852 for <asrg-archive@odin.ietf.org>; Sun, 15 Jun 2003 01:40:07 -0400 (EDT)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h5F5dcv22704 for asrg-archive@odin.ietf.org; Sun, 15 Jun 2003 01:39:38 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h5F5dcm22701 for <asrg-web-archive@optimus.ietf.org>; Sun, 15 Jun 2003 01:39:38 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id BAA11845; Sun, 15 Jun 2003 01:39:36 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19RQCi-0001kE-00; Sun, 15 Jun 2003 01:37:24 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19RQCh-0001kB-00; Sun, 15 Jun 2003 01:37:23 -0400
Received: from optimus.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h5F331a13300; Sat, 14 Jun 2003 23:03:01 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h5F32am13290 for <asrg@optimus.ietf.org>; Sat, 14 Jun 2003 23:02:36 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id XAA10171 for <asrg@ietf.org>; Sat, 14 Jun 2003 23:02:32 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19RNkj-0001J3-00 for asrg@ietf.org; Sat, 14 Jun 2003 23:00:21 -0400
Received: from 000-234-731.area5.spcsdns.net ([68.27.156.36] helo=68.27.156.36) by ietf-mx with smtp (Exim 4.12) id 19RNkh-0001J0-00 for asrg@ietf.org; Sat, 14 Jun 2003 23:00:20 -0400
Message-Id: <5.2.0.9.2.20030614225651.00bb7ff8@std5.imagineis.com>
X-Sender: research@solidmatrix.com
X-Mailer: QUALCOMM Windows Eudora Version 5.2.0.9
To: waltdnes@waltdnes.org, ASRG list <asrg@ietf.org>
From: Yakov Shafranovich <research@solidmatrix.com>
Subject: Re: [Asrg] CRI Header
In-Reply-To: <20030613215842.GA5964@m433>
References: <5.2.0.9.2.20030612142712.00b53008@std5.imagineis.com> <MBEKIIAKLDHKMLNFJODBOEBEFIAA.eric@purespeed.com> <01C32D56.08AC8FF0.eric@infobro.com> <MBEKIIAKLDHKMLNFJODBOEBEFIAA.eric@purespeed.com> <5.2.0.9.2.20030612142712.00b53008@std5.imagineis.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
X-MimeHeaders-Plugin-Info: v2.03.00
X-GCMulti: 1
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Sat, 14 Jun 2003 23:02:12 -0400

At 05:58 PM 6/13/2003 -0400, waltdnes@waltdnes.org wrote:

>On Thu, Jun 12, 2003 at 02:32:47PM -0400, Yakov Shafranovich wrote
> > At 10:50 PM 6/10/2003 -0400, waltdnes@waltdnes.org wrote:
>
> > >  2) Yes, I realize that the ISP's MTA will have to keep state
> > >information regarding the luser's preferences.  However, it comes down
> > >to either a) ISP's server doing it (maybe luser enters pre-emptive
> > >             whitelist/blocklist via web interface), or
> > >          b) luser administering it on his own MUA (Aunt Ethel or your
> > >             parents, yeah sure)
> >
> > Privacy issues are a big concern here. Keep in mind that in the
> > USA, this information can be subpoened by many parties ranging from
> > the RIAA seeking copyright pirates to the FBI via the FBIS. Some
> > approaches here such as using checksums, one way functions,
> > cryptography, etc. are needed.
>
>   Given those powers, I'd subpeona the ISP's logs instead, or at least a
>subset generated by grepping for the suspect's email address as the
>destination.
[..]

ISP logs are not around for very long, whitelists for C/R systems are. 
Plus, ISP logs might be congregated for thousands and thousands of 
customers, while email preferences are unique per user and more easily 
identifiable. 

_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg