Re: [Asrg] SPF's helo identity as a reporting target

Alessandro Vesely <vesely@tana.it> Mon, 14 May 2012 14:34 UTC

Return-Path: <vesely@tana.it>
X-Original-To: asrg@ietfa.amsl.com
Delivered-To: asrg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 30BAD21F87E5 for <asrg@ietfa.amsl.com>; Mon, 14 May 2012 07:34:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.603
X-Spam-Level:
X-Spam-Status: No, score=-4.603 tagged_above=-999 required=5 tests=[AWL=0.116, BAYES_00=-2.599, HELO_EQ_IT=0.635, HOST_EQ_IT=1.245, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fPseYzvNlEUt for <asrg@ietfa.amsl.com>; Mon, 14 May 2012 07:34:45 -0700 (PDT)
Received: from wmail.tana.it (mail.tana.it [62.94.243.226]) by ietfa.amsl.com (Postfix) with ESMTP id 184F221F87EA for <asrg@irtf.org>; Mon, 14 May 2012 07:34:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=tana.it; s=test; t=1337006084; bh=5TI5Jbv6F4wVJnnRI444BL9QLapj/cpjogq8SJXk87I=; l=1166; h=Message-ID:Date:From:MIME-Version:To:References:In-Reply-To: Content-Transfer-Encoding; b=W1TmThA7DXLlzPB/yPnHT3nVG7dHpolI4WEDRsrOY44LfilofEe3OT4XEPvpaIYWy yWWQfoNilJhdEzrfVXZGDm5rFAdZx457ShcWHyAlBT65DpJKNKPe/REr0qvH25vuAS gsvlWqLVEvpGGkWryeLH38BAYmVfQ2120/ycucoE=
Received: from [172.25.197.158] (pcale.tana [172.25.197.158]) (AUTH: CRAM-MD5 515, TLS: TLS1.0,256bits,RSA_AES_256_CBC_SHA1) by wmail.tana.it with ESMTPSA; Mon, 14 May 2012 16:34:44 +0200 id 00000000005DC035.000000004FB11804.00003388
Message-ID: <4FB11803.2080401@tana.it>
Date: Mon, 14 May 2012 16:34:43 +0200
From: Alessandro Vesely <vesely@tana.it>
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:12.0) Gecko/20120428 Thunderbird/12.0.1
MIME-Version: 1.0
To: asrg@irtf.org
References: <4FA8FBCA.3050904@tana.it> <4FAE187B.9030902@tana.it> <4FAEA20F.8090302@mustelids.ca> <4FAF85D0.8050305@tana.it> <4FAFFDB6.4020405@mustelids.ca> <4FB00224.7010500@tana.it> <4FB01201.9030209@mustelids.ca> <4FB0CFAD.5040703@tana.it> <4FB110E7.1040803@mustelids.ca>
In-Reply-To: <4FB110E7.1040803@mustelids.ca>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Subject: Re: [Asrg] SPF's helo identity as a reporting target
X-BeenThere: asrg@irtf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
List-Id: Anti-Spam Research Group - IRTF <asrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/options/asrg>, <mailto:asrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/asrg>
List-Post: <mailto:asrg@irtf.org>
List-Help: <mailto:asrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/asrg>, <mailto:asrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Mon, 14 May 2012 14:34:46 -0000

On Mon 14/May/2012 16:19:57 +0200 Chris Lewis wrote:
> On 12-05-14 05:26 AM, Alessandro Vesely wrote:
>
>> There must be loads of national laws that the owner of that zone
>> openly breaks.  Isn't that too much risky from a legal POV,
>> considering its effectiveness is probably less than other kinds
>> of DDoS?
> 
> Who said anything about a deliberate DDOS?  Think of it as spam with
> electronic countermeasures designed to confuse, confound and distract
> the recipients and third parties.

Whatever the intent, I should get your permission before asserting
that your server serves me.  Shouldn't I?  Then, yes, I suppose some
judges still have difficulties understanding Internet protocols.

> Just like they already do.
> 
> "national laws ... openly breaks".  You can say that with a straight
> face considering that 80-90% of all spam already does?

I don't have specific experience, but it seems to me that when
spammers leave enough evidence behind them they can be taken to court.

>>    220 wmail.tana.it ESMTP
> 
> Big enough, the recipient site still loses before the 220.

You're right.  Rejecting is cheap, but still bears a cost.