Re: [Asrg] seeking comments on new RMX article

Michael Rubel <asrg@mikerubel.org> Tue, 06 May 2003 19:14 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA04616 for <asrg-archive@odin.ietf.org>; Tue, 6 May 2003 15:14:32 -0400 (EDT)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h46JN9L20049 for asrg-archive@odin.ietf.org; Tue, 6 May 2003 15:23:09 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h46JN9820046 for <asrg-web-archive@optimus.ietf.org>; Tue, 6 May 2003 15:23:09 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA04568; Tue, 6 May 2003 15:14:01 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19D7v5-0001Wp-00; Tue, 06 May 2003 15:16:07 -0400
Received: from ietf.org ([132.151.1.19] helo=www1.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19D7v4-0001Wm-00; Tue, 06 May 2003 15:16:06 -0400
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h46JKd819908; Tue, 6 May 2003 15:20:39 -0400
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h46JFo819689 for <asrg@optimus.ietf.org>; Tue, 6 May 2003 15:15:50 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA03698 for <asrg@ietf.org>; Tue, 6 May 2003 15:06:42 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19D7o0-0001Tv-00 for asrg@ietf.org; Tue, 06 May 2003 15:08:48 -0400
Received: from entropy.galcit.caltech.edu ([131.215.119.61]) by ietf-mx with esmtp (Exim 4.12) id 19D7nz-0001Ts-00 for asrg@ietf.org; Tue, 06 May 2003 15:08:47 -0400
Received: from localhost (localhost [127.0.0.1]) by entropy.galcit.caltech.edu (Postfix) with ESMTP id 9AB96A; Tue, 6 May 2003 15:10:21 -0400 (EDT)
From: Michael Rubel <asrg@mikerubel.org>
X-X-Sender: mrubel@entropy.galcit.caltech.edu
To: J C Lawrence <claw@kanga.nu>
Cc: "Eric D. Williams" <eric@infobro.com>, "asrg@ietf.org" <asrg@ietf.org>
Subject: Re: [Asrg] seeking comments on new RMX article
In-Reply-To: <4941.1052245041@kanga.nu>
Message-ID: <Pine.LNX.4.44.0305061204030.26063-100000@entropy.galcit.caltech.edu>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Tue, 06 May 2003 12:10:21 -0700

JCL>   BoxA is compromised.
JCL> 
JCL>   The zombie code sucks in a spamming engine (SE).
JCL> 
JCL>   The SE determines the mail configuration of BoxA in terms of
JCL>   appropriate SMTP envelope etc from the registry.
JCL> 
JCL>   BoxA spams away using the stolen credentials from its registry.

J.C.,

Thank you--you've raised a reasonable, cogent objection.

As you note, RMX would not help against this kind of attack, and frankly
neither would any other proposal I'm aware of.  If I can trick your machine
into thinking I'm you, then I can do bad things in your name and thus make
you look bad.

But right now, with SMTP the way it is, I don't even have to break into your
machine to accomplish that.  I can make you look bad with impunity just by
writing your name on the "From:" addresses of emails I send, and there's
nothing you can do about it, even if you are a good, careful sysadmin.

I submit that RMX gives a significant improvement, and it's just simple/easy
enough that people might start using it!

Mike

_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg