Re: [dmarc-ietf] Break SPF response: DKIM Only
Scott Kitterman <sklist@kitterman.com> Thu, 29 February 2024 18:29 UTC
Return-Path: <sklist@kitterman.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9D6BDC1C4DA7 for <dmarc@ietfa.amsl.com>; Thu, 29 Feb 2024 10:29:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.108
X-Spam-Level:
X-Spam-Status: No, score=-7.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=neutral reason="invalid (unsupported algorithm ed25519-sha256)" header.d=kitterman.com header.b="qoirrs8M"; dkim=pass (2048-bit key) header.d=kitterman.com header.b="L8sP5GjS"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7exDthQNMVE2 for <dmarc@ietfa.amsl.com>; Thu, 29 Feb 2024 10:29:31 -0800 (PST)
Received: from interserver.kitterman.com (interserver.kitterman.com [64.20.48.66]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 623D9C1C4DA9 for <dmarc@ietf.org>; Thu, 29 Feb 2024 10:29:31 -0800 (PST)
Received: from interserver.kitterman.com (interserver.kitterman.com [64.20.48.66]) by interserver.kitterman.com (Postfix) with ESMTPS id B490BF8022B; Thu, 29 Feb 2024 13:29:20 -0500 (EST)
DKIM-Signature: v=1; a=ed25519-sha256; c=relaxed/simple; d=kitterman.com; i=@kitterman.com; q=dns/txt; s=201903e; t=1709231346; h=date : from : to : subject : in-reply-to : references : message-id : mime-version : content-type : content-transfer-encoding : from; bh=4r20UpmH9htE9vLECczsb1j6RQ+4m4P7xRTh8gIBvVo=; b=qoirrs8M/5IiKd3MR4tKtiAoT+gkkyhf8lxODckVpC+UTcHrVnEaeu44LEPwKKBFshqjb IeR+9hZIQRE/p0kCw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kitterman.com; i=@kitterman.com; q=dns/txt; s=201903r; t=1709231346; h=date : from : to : subject : in-reply-to : references : message-id : mime-version : content-type : content-transfer-encoding : from; bh=4r20UpmH9htE9vLECczsb1j6RQ+4m4P7xRTh8gIBvVo=; b=L8sP5GjSvT7cSGx6OOqsXBY9CsWzDa+3BLz/OuFYQpW66EypY03JGy0X5NXjz5TnDsqxg jGgFpFDLy8CZCdoFuyEf0fwAjzKpDboUUO7ySjKSOvMFeMEs/QMxD1sZeoUMn7klZPLhUH+ z6cUfhtkMeWkxZeQQwlyb+iJ/sxAOKoy2hMFGkNY0ZGuRW62tUkwHeNa/dJBVwKzgPrUFj1 8haeIFmd2UFBqTV/0qofe1sB2ltwmnEIEjoRBAoQn8gSpVYZkclPypfEYJVHIyt+ynr30tS HiUwfpXeHewXc3ce+xbCnbJENcCMAaKFttMRMJBIM7RDAFswK3JAVQDcxzmQ==
Received: from [127.0.0.1] (mobile-166-170-32-116.mycingular.net [166.170.32.116]) by interserver.kitterman.com (Postfix) with ESMTPSA id 161A1F8010F; Thu, 29 Feb 2024 13:29:06 -0500 (EST)
Date: Thu, 29 Feb 2024 18:29:00 +0000
From: Scott Kitterman <sklist@kitterman.com>
To: dmarc@ietf.org
In-Reply-To: <82939544ff3fc7d16d6df438426a9944@junc.eu>
References: <CAH48ZfxMZzu0YoVOOGgBrhNMMcrZcArpM=ygG7bRZ5fUM1x+zA@mail.gmail.com> <82939544ff3fc7d16d6df438426a9944@junc.eu>
Message-ID: <9B7EB4AC-2AD2-4625-B232-7A13EC779AA0@kitterman.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/HvaVze9N1Bam16qnUfLYwYvybcg>
Subject: Re: [dmarc-ietf] Break SPF response: DKIM Only
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Feb 2024 18:29:35 -0000
On February 29, 2024 6:15:37 PM UTC, Benny Pedersen <me@junc.eu> wrote: >Douglas Foster skrev den 2024-02-29 18:48: >> I am surprised at the lack of feedback about Barry's research link. >> It is a devastating attack on our ability to trust SPF when shared >> infrastructure is involved. As a result of that document, I have >> switched camps and believe that we MUST provide a DKIM-only option for >> DMARC. >> >> The proposed workaround, of using a "?" modifier to force SPF Neutral >> instead of Pass, seems to lack both awareness and implementation, >> since it was not even mentioned in the research document as a >> mitigation. > >spf specs have desided to allow +all and unlimited numbers of ips, there is no way to stop it unless rfc changes it > >even "v=spf1 ip4:0.0.0.0/0 -all" is fully valid > >for maillist is never being dmarc aligned anyway, but direct could be aligned, if not a forwarding host does something, with or without srs > >maybe rfc wise it could help to have a max ips to get spf pass ? > There's no point. As has been discussed for probably 20 years, as soon as you special case any of these kinds of records, people will move to slightly more obscure ways to get the same results. From a protocol perspective there's no surprise here. The security considerations of RFC 4408 explicitly warned about shared infrastructure risks. The challenge is that no one cared. There's no doubt a business opportunity here, but I expect no one will pursue it since it doesn't require AI. Scott K
- [dmarc-ietf] Break SPF response: DKIM Only Douglas Foster
- Re: [dmarc-ietf] Break SPF response: DKIM Only Benny Pedersen
- Re: [dmarc-ietf] Break SPF response: DKIM Only Scott Kitterman
- Re: [dmarc-ietf] Break SPF response: DKIM Only Douglas Foster
- [dmarc-ietf] Fwd: Break SPF response: DKIM Only Chuhan Wang
- Re: [dmarc-ietf] Fwd: Break SPF response: DKIM On… Neil Anuskiewicz
- Re: [dmarc-ietf] Fwd: Break SPF response: DKIM On… Douglas Foster
- Re: [dmarc-ietf] Break SPF response: DKIM Only Richard Clayton