Re: [Asrg] [ASRG] SMTP pull anyone?

Douglas Otis <dotis@mail-abuse.org> Tue, 18 August 2009 20:45 UTC

Return-Path: <dotis@mail-abuse.org>
X-Original-To: asrg@core3.amsl.com
Delivered-To: asrg@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id B2FD628C356 for <asrg@core3.amsl.com>; Tue, 18 Aug 2009 13:45:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.675
X-Spam-Level:
X-Spam-Status: No, score=-5.675 tagged_above=-999 required=5 tests=[AWL=0.924, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2VB-MJDFo9BU for <asrg@core3.amsl.com>; Tue, 18 Aug 2009 13:45:56 -0700 (PDT)
Received: from harry.mail-abuse.org (harry.mail-abuse.org [168.61.5.27]) by core3.amsl.com (Postfix) with ESMTP id 5FDA128C36C for <asrg@irtf.org>; Tue, 18 Aug 2009 13:45:55 -0700 (PDT)
Received: from SJC-Office-NAT-214.mail-abuse.org (gateway1.sjc.mail-abuse.org [168.61.5.81]) by harry.mail-abuse.org (Postfix) with ESMTP id 6C8E8A9443A for <asrg@irtf.org>; Tue, 18 Aug 2009 20:45:46 +0000 (UTC)
Message-ID: <4A8B12FA.6090203@mail-abuse.org>
Date: Tue, 18 Aug 2009 13:45:46 -0700
From: Douglas Otis <dotis@mail-abuse.org>
User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.5; en-US; rv:1.9.1.1) Gecko/20090715 Thunderbird/3.0b3
MIME-Version: 1.0
To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
References: <922a897b0908170253k60c0d57dh5e593c78f9137fab@mail.gmail.com> <4A8ADB9D.5080004@billmail.scconsult.com> <4A8AE22C.7030300@nortel.com>
In-Reply-To: <4A8AE22C.7030300@nortel.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Subject: Re: [Asrg] [ASRG] SMTP pull anyone?
X-BeenThere: asrg@irtf.org
X-Mailman-Version: 2.1.9
Precedence: list
Reply-To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
List-Id: Anti-Spam Research Group - IRTF <asrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/listinfo/asrg>, <mailto:asrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/asrg>
List-Post: <mailto:asrg@irtf.org>
List-Help: <mailto:asrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/asrg>, <mailto:asrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Tue, 18 Aug 2009 20:45:56 -0000

On 8/18/09 10:17 AM, Chris Lewis wrote:
> Bill Cole wrote:
>
>> I don't see how this reduces the effort required on the receiving side in
>> comparison to currently common practices.
>
> Precisely - in fact, it increases the work the receiver has to do,
> probably substantially.

As accepted IP addresses are reduced, there will be increased abuse of 
existing services, that were likely exposed through information gleaned 
from compromised computers.  This will eventually move the problem to 
the point where the IP address of the client offers fewer clues about a 
message source.  Without some simply means to identify undesired 
messages, the sheer volume of undesired email will provide a growing 
burden.  Especially when content filtering must be deployed.  It is hard 
to imagine a more resource intensive strategy.

> Consider: the offer/callback approach is identical to SMTP up to the
> DATA keyword.

Not if MUA or specialized MDAs gather the messages marked as desired. A 
selection based upon the offers should reduce the overhead considerably.

> The "offer" would have to have more-or-less the same information as the
> pre-DATA SMTP information in normal SMTP.

No. Unlike that of an SMTP exchange, when reference information is not 
valid, the reference does not work.  This removes the validation steps.

-Doug