Re: [Asrg] Re: SPF abused by spammers

Markus Stumpf <maex-lists-spam-ietf-asrg@Space.Net> Fri, 10 September 2004 15:41 UTC

Received: from ietf-mx.ietf.org (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA07412 for <asrg-web-archive@ietf.org>; Fri, 10 Sep 2004 11:41:58 -0400 (EDT)
Received: from megatron.ietf.org ([132.151.6.71]) by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1C5nbI-0000mR-QS for asrg-web-archive@ietf.org; Fri, 10 Sep 2004 11:46:15 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1C5nQU-0003Ol-3m; Fri, 10 Sep 2004 11:35:02 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1C5n6C-0008VZ-8u for asrg@megatron.ietf.org; Fri, 10 Sep 2004 11:14:04 -0400
Received: from ietf-mx.ietf.org (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id LAA05346 for <asrg@ietf.org>; Fri, 10 Sep 2004 11:14:01 -0400 (EDT)
Received: from moebius2.space.net ([195.30.1.100]) by ietf-mx.ietf.org with smtp (Exim 4.33) id 1C5nAH-0000DJ-KP for asrg@ietf.org; Fri, 10 Sep 2004 11:18:18 -0400
Received: (qmail 73279 invoked by uid 1013); 10 Sep 2004 15:14:02 -0000
Date: Fri, 10 Sep 2004 17:14:02 +0200
From: Markus Stumpf <maex-lists-spam-ietf-asrg@Space.Net>
To: Frank Ellermann <nobody@xyzzy.claranet.de>
Subject: Re: [Asrg] Re: SPF abused by spammers
Message-ID: <20040910151402.GN44802@Space.Net>
References: <200409091620.i89GKbd39355@shedevil.annepmitchell.com> <44CFA5B6-027D-11D9-8DB5-000A95AC5778@isipp.com> <20040909212536.GH44802@Space.Net> <4141B4BA.5AE2@xyzzy.claranet.de>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <4141B4BA.5AE2@xyzzy.claranet.de>
User-Agent: Mutt/1.4.1i
Organization: SpaceNet AG, Muenchen, Germany
X-PGP-Fingerprint: 66 F3 75 79 01 D0 B8 5F 1A C7 77 88 4A B6 70 DF
X-Spam-Score: 0.0 (/)
X-Scan-Signature: cd26b070c2577ac175cd3a6d878c6248
Cc: asrg@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/asrg>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
Sender: asrg-bounces@ietf.org
Errors-To: asrg-bounces@ietf.org
X-Spam-Score: 0.0 (/)
X-Scan-Signature: b7b9551d71acde901886cc48bfc088a6

Hoi Frank,

On Fri, Sep 10, 2004 at 04:05:47PM +0200, Frank Ellermann wrote:
> > Microsoft claims IPR (which they did even before the group
> > was chartered, btw, but everyone ignored it).
> 
> Not really,  May 20: draft-atkinson-callerid-00 published.
> May 21: ASRG co-chair resigns.  May 22: IPR complaint filed.

I have a PDF document from Microsoft which is named
"callerid_license.pdf" and is dated "Published: February 20, 2004".
It starts with:
------------------------------------------------------------------------
    Caller ID for E-mail Implementation License

    This document is intended to expand upon the rights that Microsoft
    grants to certain individuals and organizations interested in developing
    and implementing software programs having one or more aspects conformant
    to the Caller ID for E-mail Specification (the "Specification") by
    providing a patent license to the Specification. Copies of the
    technical specifications for the Caller ID for E-mail Specification,
    which include an associated copyright notice and license, can be found at
    http://www.microsoft.com/mscorp/twc/privacy/spam_callerID.mspx.

    Please read this entire document carefully to understand your rights.

    Patent License
    Microsoft believes that it has patent rights (patent(s) and/or pending
    applications(s)) that are necessary for you to license in order to
    make, sell, or distribute software programs that comply with one or
    more aspects of the Caller ID for E-mail Specification.
    [ ... ]
------------------------------------------------------------------------
So it was clear from the beginning that every derivate work that relates
to Caller ID will have an IPR problem and that Microsoft will file a
complaint. Many people stated it, it should be in the archives, but
it was deliberately ignored.

> Sure, there's nothing wrong with spf2.0/mailfrom as long as
> you don't confuse it with the FUSSP.  In theory spf2.0/pra
> could also make sense if they fix their "patented" algorithm
> to read four mail headers for some common cases.

SPF will not solve "the spam problem" and it will not solve "the
phishing problem". It will *try* to solve the problem with domain
forgery and while trying it breaks the whole existing Internet mail
infrastructure by requiring something like half baked SRS.

> > We still don't have "the anti spam solution", but hey,
> > who cares or realizes this.
> 
> I care.  Back to zero bounces / out-of-office / vacation /
> challenges / broken NDRs / Symantec announcing its ignorance
> to the e-mail world at large / etc. per day as it was in 2003.

In which way does SPF protect you from
   out-of-office / vacation / challenges

> > everyone always says "this is the way to go", so nobody
> > asks where the way will really lead to.
> 
> Again not really.  I still like your MTAMARK idea, and it's
> also very interesting to watch SURBL.  And even C/R systems
> could work in combination with a spf2.0/mailfrom PASS.

Maybe I should have been clearer and write:
   > everyone always says "this is the way to go", so journalists don't
   > ask where the way will really lead to.
because they still are under the assumption "MARID will solve the spam
problem". I fully understand they must be disappointed to read the
CipherTrust report.

	\Maex

-- 
SpaceNet AG            | Joseph-Dollinger-Bogen 14 | Fon: +49 (89) 32356-0
Research & Development |       D-80807 Muenchen    | Fax: +49 (89) 32356-299
"The security, stability and reliability of a computer system is reciprocally
 proportional to the amount of vacuity between the ears of the admin"

_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg