Re: [Asrg] seeking comments on new RMX article

Dave Crocker <dhc@dcrocker.net> Sun, 04 May 2003 14:14 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA00986 for <asrg-archive@odin.ietf.org>; Sun, 4 May 2003 10:14:25 -0400 (EDT)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h44ELvd10913 for asrg-archive@odin.ietf.org; Sun, 4 May 2003 10:21:57 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h44ELu810910 for <asrg-web-archive@optimus.ietf.org>; Sun, 4 May 2003 10:21:56 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA00937; Sun, 4 May 2003 10:13:54 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19CKHZ-00015Q-00; Sun, 04 May 2003 10:16:01 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19CKHZ-00015M-00; Sun, 04 May 2003 10:16:01 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h44EJY810835; Sun, 4 May 2003 10:19:34 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h44EId810808 for <asrg@optimus.ietf.org>; Sun, 4 May 2003 10:18:39 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id KAA00574 for <asrg@ietf.org>; Sun, 4 May 2003 10:10:21 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19CKE9-00014d-00 for asrg@ietf.org; Sun, 04 May 2003 10:12:29 -0400
Received: from songbird.com ([208.184.79.7] helo=joy.songbird.com ident=root) by ietf-mx with esmtp (Exim 4.12) id 19CKE3-00014T-00 for asrg@ietf.org; Sun, 04 May 2003 10:12:23 -0400
Received: from bbprime.brandenburg.com (208.184.79.252.songbird.com [208.184.79.252] (may be forged)) by joy.songbird.com (8.11.6/8.11.6) with ESMTP id h44ECQN11220; Sun, 4 May 2003 07:12:26 -0700
From: Dave Crocker <dhc@dcrocker.net>
X-Mailer: The Bat! (v1.63 Beta/6) Personal
Organization: Brandenburg InternetWorking
X-Priority: 3 (Normal)
Message-ID: <197812365059.20030504065659@brandenburg.com>
To: Mike Rubel <asrg@mikerubel.org>
CC: asrg@ietf.org
Subject: Re: [Asrg] seeking comments on new RMX article
In-Reply-To: <Pine.LNX.4.44.0305031506070.30758-100000@tamale.caltech.edu>
References: <Pine.LNX.4.44.0305031506070.30758-100000@tamale.caltech.edu>
MIME-Version: 1.0
Content-type: text/plain; charset="us-ascii"
Content-transfer-encoding: 7bit
Content-Transfer-Encoding: 7bit
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Sun, 04 May 2003 06:56:59 -0700
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

Mike,

MR> I have written a new article to help explain RMX records, and would
MR> sincerely appreciate any feedback or comments you might have on it.  The
MR> article here can be found here:

The premise of the scheme is in the following text:

MR> Detecting a forgery begins by realizing that email systems never
MR> legitimately use third-party relays anymore.

What this therefore asserts is that the domain name in a From field is
always tied to a fixed set of originating MTAs.

The presumption is incorrect.

For a variety of reasons -- notably for some mobile users -- the
originating MTA may well be unable to know the set of valid domains
sending from it.  That is, some mobile users must be able to
spontaneously post through different MTAs.

This highlights an important requirement for evaluating proposals:  What
*valid* scenarios does it prevent?

d/
--
 Dave Crocker <mailto:dcrocker@brandenburg.com>
 Brandenburg InternetWorking <http://www.brandenburg.com>
 Sunnyvale, CA  USA <tel:+1.408.246.8253>, <fax:+1.866.358.5301>


_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg