Re: [Asrg] 6 - Yahoo Domain Keys

"Alan DeKok" <aland@ox.org> Wed, 19 May 2004 23:57 UTC

Received: from optimus.ietf.org (www.iesg.org [132.151.1.19]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id TAA29920 for <asrg-archive@odin.ietf.org>; Wed, 19 May 2004 19:57:52 -0400 (EDT)
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 1BQai5-0005MM-GC for asrg-archive@odin.ietf.org; Wed, 19 May 2004 19:42:53 -0400
Received: (from exim@localhost) by www1.ietf.org (8.12.8/8.12.8/Submit) id i4JNgrGk020598 for asrg-archive@odin.ietf.org; Wed, 19 May 2004 19:42:53 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 1BQadX-0003cG-9m for asrg-web-archive@optimus.ietf.org; Wed, 19 May 2004 19:38:11 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id TAA29074 for <asrg-web-archive@ietf.org>; Wed, 19 May 2004 19:38:09 -0400 (EDT)
Received: from ietf-mx.ietf.org ([132.151.6.1] helo=ietf-mx) by ietf-mx with esmtp (Exim 4.32) id 1BQadV-00047d-Hm for asrg-web-archive@ietf.org; Wed, 19 May 2004 19:38:09 -0400
Received: from exim by ietf-mx with spam-scanned (Exim 4.12) id 1BQacW-00041H-00 for asrg-web-archive@ietf.org; Wed, 19 May 2004 19:37:08 -0400
Received: from optimus.ietf.org ([132.151.1.19]) by ietf-mx with esmtp (Exim 4.12) id 1BQacK-0003vV-00 for asrg-web-archive@ietf.org; Wed, 19 May 2004 19:36:56 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 1BQaN1-0008FM-Un; Wed, 19 May 2004 19:21:07 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 1BQaLD-0007hZ-3d for asrg@optimus.ietf.org; Wed, 19 May 2004 19:19:15 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id TAA28099 for <asrg@ietf.org>; Wed, 19 May 2004 19:19:13 -0400 (EDT)
Received: from ietf-mx.ietf.org ([132.151.6.1] helo=ietf-mx) by ietf-mx with esmtp (Exim 4.32) id 1BQaLB-0001oa-Fp for asrg@ietf.org; Wed, 19 May 2004 19:19:13 -0400
Received: from exim by ietf-mx with spam-scanned (Exim 4.12) id 1BQaKF-0001iA-00 for asrg@ietf.org; Wed, 19 May 2004 19:18:15 -0400
Received: from newgiles.striker.ottawa.on.ca ([205.150.200.131] helo=mail.nitros9.org) by ietf-mx with esmtp (Exim 4.12) id 1BQaJm-0001bU-00 for asrg@ietf.org; Wed, 19 May 2004 19:17:47 -0400
Received: from newgiles.nitros9.org (localhost [127.0.0.1]) by mail.nitros9.org (Postfix) with ESMTP id 04F9E16CC4 for <asrg@ietf.org>; Wed, 19 May 2004 19:23:04 -0400 (EDT)
From: Alan DeKok <aland@ox.org>
To: asrg@ietf.org
Subject: Re: [Asrg] 6 - Yahoo Domain Keys
In-Reply-To: Your message of "Wed, 19 May 2004 18:14:52 EDT." <16555.56412.585254.961521@world.std.com>
Message-Id: <20040519232304.04F9E16CC4@mail.nitros9.org>
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/mail-archive/working-groups/asrg/>
Date: Wed, 19 May 2004 19:23:03 -0400
X-Spam-Checker-Version: SpamAssassin 2.60 (1.212-2003-09-23-exp) on ietf-mx.ietf.org
X-Spam-Status: No, hits=0.9 required=5.0 tests=AWL,DOMAIN_BODY autolearn=no version=2.60

Barry Shein <bzs@world.std.com> wrote:
> As far as I can tell spammers have now become domain registries and
> just generate random-appearing, generated domains like www.fxbrezd.com
> (or, more often, .info or .somecountryyoudon'twanttoknowmoreabout.)
> For example, these whacko domains usually have functioning MX's.
> 
> Which means they can just as easily set up SPF or Domain Key or
> similar services for those randomly generated domains.

  <shrug> Blacklist the DNS IP.

> Also, much spam from hijacked PCs seems to use the hijacked
> PC's host, as in wasteofoxygen@dyn-83-155-31-99.ppp.tiscali.fr
> 
> That sort of thing will get around these SPF/YDK approaches, right?

  Yes and no.  It depends on how it's implemented.

> Again, I don't know for a fact that this is completely useless
> technology (like proof-of-work which is useless technology), but I
> think it's only potentially useful against certain types of scams,
> domain forgeries with malicious intent, in a very weak way, and as
> such really has little to nothing to do with spam per se except
> inasmuch as we can rationalize that ``anything which comes via email
> and might harm or annoy me'' is hereby spam.=

  Is there a better suggestion on the table?

  This isn't to say we should do something nonsensical, simply because
it's better than nothing.  But it does have some applicability, a
number of domains are implementing it, and the implementors are strong
proponents.

  Alan DeKok.

_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg