Re: [dmarc-ietf] DMARC-Compliant Mailing Lists

Douglas Foster <dougfoster.emailstandards@gmail.com> Sat, 09 October 2021 19:32 UTC

Return-Path: <dougfoster.emailstandards@gmail.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1A5D93A0803 for <dmarc@ietfa.amsl.com>; Sat, 9 Oct 2021 12:32:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IM7T1IJXHqS3 for <dmarc@ietfa.amsl.com>; Sat, 9 Oct 2021 12:32:03 -0700 (PDT)
Received: from mail-oo1-xc31.google.com (mail-oo1-xc31.google.com [IPv6:2607:f8b0:4864:20::c31]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 829453A07FF for <dmarc@ietf.org>; Sat, 9 Oct 2021 12:32:03 -0700 (PDT)
Received: by mail-oo1-xc31.google.com with SMTP id w9-20020a4adec9000000b002b696945457so3464649oou.10 for <dmarc@ietf.org>; Sat, 09 Oct 2021 12:32:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=1eEP/2ZlpuIgzmqVL87HZ7QhStIDYHe7tvHSULKniuI=; b=VhaUMh9YfChs33dcqA2e5v3pYSahDAfvDGxhObckY/ef+/ebwVLtjzu326uHTfZvRU x7ySkxp7O4wqUZhVNHgBsBtZf9fnsAqUFaG22Ubh5+LWZRVgM4azjOvS6ll7pjHKB8zX dwzphU4188kZB1zvTtaunicvg5wSwL/AaczC47NjZMHwYZwRwayKK8bgyehdkyPqK8GX CIGueRCbDOAIf4ulG+rDpAv7D0K7A5Vw0wqnTOPtGQL8qxJVsVAeq1nS619WYJ+WzgQq EV40OhATaKbA4H56E5fAztyharbeoWqbuPwssyQuLNOAffu0FY8Wq1mwx67BKSozGzU3 5N4A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=1eEP/2ZlpuIgzmqVL87HZ7QhStIDYHe7tvHSULKniuI=; b=45UtSvx5Nh46ojEBuL1N31AbmpHIGc+i6t2BPcgS/6rR38RE7yalq5MYUaELxm9kaO Ql470wTeKbacNI+pBfRc3f1XRphnmPYH4SVUJUdgjDuh37UZ2c0yJn2eRfQ1Aq1rKCbx SuVkE0L32g29BMo0iA/IHXzSDve4r6Rf7Co3jgXGIxSigsibB9r1/tXzLVlDrPB0pY/O nZIykVyrPRl3toGlVRnUv4r67pufDOGu9F28HgdPDl5gIwuJ6iHoxqSClGEjG0pjtJt3 ZTlUcvCp8GYp5maUNpyhTnQXllpxdZ+P+YMIKmQ/OpIHTFR44/jcsfeRqVIvmdgItDLl M6ZA==
X-Gm-Message-State: AOAM532RuhSkQzVQpO2k6+aeFm3SapTdAWVn0EnXAiegu5RrrAv0u/pU GJK424lpbFsgq7c2V8Aao5LNobjjgOKZ5UhbybgelMjV
X-Google-Smtp-Source: ABdhPJwtCnJUmdCCt+tEQIHtTX9u08aaqrtTvguktgehDCUA4M1K6yWIfPQiUx2h6vug8BokkPnELezkELmVF+41+lc=
X-Received: by 2002:a4a:a442:: with SMTP id w2mr13140686ool.44.1633807921979; Sat, 09 Oct 2021 12:32:01 -0700 (PDT)
MIME-Version: 1.0
References: <20211006233727.24C1429DC897@ary.qy> <56B7A1D4-B683-47D3-8871-2A1F283FA464@wordtothewise.com> <c1e199f1-0c91-9c39-1479-e9ba76af493e@tana.it> <2290129.80B3yH0EHm@zini-1880> <b0091b5c70d7b18bebdabc5752bee162@junc.eu> <CAH48ZfzL_2dfcK1AYj9m2KBeYNA1CE1iYevDGvGuqz4DaT=R6w@mail.gmail.com> <41BDE3F2-71D4-469F-8D2D-621A275EA853@kitterman.com> <CAH48Zfy1AFsxzmVSzAxQrUvc8bf6ZKockwJ=0yw=iyKn-oG0ig@mail.gmail.com> <a876b564-c900-10c1-d454-4fff750f2158@spamtrap.tnetconsulting.net>
In-Reply-To: <a876b564-c900-10c1-d454-4fff750f2158@spamtrap.tnetconsulting.net>
From: Douglas Foster <dougfoster.emailstandards@gmail.com>
Date: Sat, 09 Oct 2021 15:31:51 -0400
Message-ID: <CAH48ZfzBEmXVCBPiOJpg-qd_wqLy6hESy9tmEkdLjZNuGPd+LQ@mail.gmail.com>
To: IETF DMARC WG <dmarc@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000d221ea05cdf08c58"
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/9q2XjK91eumzSg-QMPmfdb7x3uU>
Subject: Re: [dmarc-ietf] DMARC-Compliant Mailing Lists
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 09 Oct 2021 19:32:09 -0000

Yes, savvy users could use the proxy to establish offline
communication, but it is not what most users would do, so the lure for bad
actors is real.

Our previous discussion about online stalking was very much in mind when I
wrote the specification.   Because of the proxy mechanism, stalking can be
stopped by (a) the list operator preventing messages from the stalker's
real address to the victim's alias address, or (b) the system operator
evicting the stalker from the list, or (c) the victim leaving the list.
 In any of these scenarios, the harassment is stopped immediately, as long
as the stalker does not have the real email address of his target.   In the
absence of such measures, the best defense is to use a separate email
address for each list in which one participates.

Doug Foster




On Sat, Oct 9, 2021 at 12:35 PM Grant Taylor <gtaylor=
40tnetconsulting.net@dmarc.ietf.org> wrote:

> On 10/9/21 6:05 AM, Douglas Foster wrote:
> > The substantive argument is the problem of trust in list operators.   My
> > proposal made list infrastructure significantly more complex, and
> > allowed list operators to intercept member-to-member communication.
> >   This creates an incentive for nation-state intelligence agencies and
> > big tech privacy violators to move into management of lists.
>
> I believe that it makes the list operator effectively a communications
> proxy.  Nothing states that two parties need to use the proxy for any
> more than the minimum communications necessary to establish direct
> communications.  I also believe that this is a well established
> communications bootstrap method;  eBay, Craigslist, various dating
> sites, etc. tend to provide a way for people to say things like "please
> email me at my main email address".
>
>
>
> --
> Grant. . . .
> unix || die
>
> _______________________________________________
> dmarc mailing list
> dmarc@ietf.org
> https://www.ietf.org/mailman/listinfo/dmarc
>