Re: [Asrg] seeking comments on new RMX article

Dave Crocker <dhc@dcrocker.net> Tue, 06 May 2003 17:39 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA00887 for <asrg-archive@odin.ietf.org>; Tue, 6 May 2003 13:39:12 -0400 (EDT)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h46Hlll12477 for asrg-archive@odin.ietf.org; Tue, 6 May 2003 13:47:47 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h46Hll812474 for <asrg-web-archive@optimus.ietf.org>; Tue, 6 May 2003 13:47:47 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA00856; Tue, 6 May 2003 13:38:42 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19D6Qp-0000w8-00; Tue, 06 May 2003 13:40:47 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19D6Qp-0000w5-00; Tue, 06 May 2003 13:40:47 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h46Hk4812373; Tue, 6 May 2003 13:46:04 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h46Hjp812331 for <asrg@optimus.ietf.org>; Tue, 6 May 2003 13:45:51 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id NAA00794 for <asrg@ietf.org>; Tue, 6 May 2003 13:36:45 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19D6Ox-0000uj-00 for asrg@ietf.org; Tue, 06 May 2003 13:38:51 -0400
Received: from songbird.com ([208.184.79.7] helo=joy.songbird.com ident=root) by ietf-mx with esmtp (Exim 4.12) id 19D6Ow-0000uf-00 for asrg@ietf.org; Tue, 06 May 2003 13:38:50 -0400
Received: from bbprime.brandenburg.com (208.184.79.252.songbird.com [208.184.79.252] (may be forged)) by joy.songbird.com (8.11.6/8.11.6) with ESMTP id h46HdLN13247; Tue, 6 May 2003 10:39:21 -0700
From: Dave Crocker <dhc@dcrocker.net>
X-Mailer: The Bat! (v1.63 Beta/6) Personal
Reply-To: Dave Crocker <dcrocker@brandenburg.com>
Organization: Brandenburg InternetWorking
X-Priority: 3 (Normal)
Message-ID: <19744716058.20030506103859@brandenburg.com>
To: Hadmut Danisch <hadmut@danisch.de>
CC: asrg@ietf.org
Subject: Re: [Asrg] seeking comments on new RMX article
In-Reply-To: <20030506161903.GA1469@danisch.de>
References: <Pine.LNX.4.44.0305051946590.11255-100000@tamale.caltech.edu> <200305060550.h465olHn011387@calcite.rhyolite.com> <2335175049.20030506075958@brandenburg.com> <20030506161903.GA1469@danisch.de>
MIME-Version: 1.0
Content-type: text/plain; charset="us-ascii"
Content-transfer-encoding: 7bit
Content-Transfer-Encoding: 7bit
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Tue, 06 May 2003 10:38:59 -0700
Content-Transfer-Encoding: 7bit
Content-Transfer-Encoding: 7bit

Hadmut,

Thanks for exploring my comparison in some detail.

>> ps.  It strikes me that the RMX proposal is conceptually similar to the
>> old IDENT specification w

HD> IDENT was useless, because the peer machine itself gives any random
HD> answer. IDENT was useful as long as there were a few big UNIX and VMS
HD> machines where hundreds of users logged in but hadn't have root
HD> access.

Even then, it was not useful, because by the time it was proposed, there
were not a few big time-shared system.

However, the belief that it would have been useful under those
circumstances is based on the view that the administrator of the
timesharing system was independent of the person running the
applications AND that administrator could be expected to be trustworthy.

And therein lies the same, serious problem with RMX.


HD> In contrast, RMX doesn't ask the sending MTA, which could be the
HD> attacker, but a third party, which can be relied on since the query
HD> path doesn't depend on the incoming SMTP connection.

The reason that I refer to RMX as a point solution, rather than
something with a real potential for getting at the core of spam, is
because it "only" attempts to deal with From-field spoofing.

Spoofing is bad, but it is not at all the core problem with spam.

Spam is about content policies and author policies. RMX does nothing
about either of these.

Eliminate all spoofing and you are left with massive amounts of spam.

And, by the way, in the off-chance that RMX actually does achieve
wide-scale deployment, the folks who are currently doing spoofing will
simply move on to other techniques.

Note that there is nothing to prevent a spammer from hosting an MTA and
creating RMX records.  They might not be able to do that for aol.com but
they CAN do it for a0l.biz, supposedly-honest.net, and an infinite
number of other domains.

Like IDENT, RMX relies on a model of strict, system-wide control.
Unfortunately, the diversity of the net means that it is essentially
impossible to enforce the kinds of controls that are required by such
proposals.


HD> Again, please inform yourself before posting.

I will return the favor, by suggesting that folks inform themselves
about the realities of Internet-scale operations, Internet-scale
deployment physics, and Internet-scale spammer adaptability.

Then, perhaps, we will not be presented with localized, near-term
proposals that will have no impact on large-scale, long-term spamming.


d/
--
 Dave Crocker <mailto:dcrocker@brandenburg.com>
 Brandenburg InternetWorking <http://www.brandenburg.com>
 Sunnyvale, CA  USA <tel:+1.408.246.8253>, <fax:+1.866.358.5301>

_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg