Re: [dmarc-ietf] Call for Adoption: DMARC Use of the RFC5322.Sender Header Field

Dave Crocker <dhc@dcrocker.net> Sat, 26 September 2020 13:07 UTC

Return-Path: <dhc@dcrocker.net>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BE19D3A08C6 for <dmarc@ietfa.amsl.com>; Sat, 26 Sep 2020 06:07:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, NICE_REPLY_A=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7ZhnTppVzg7F for <dmarc@ietfa.amsl.com>; Sat, 26 Sep 2020 06:07:02 -0700 (PDT)
Received: from simon.songbird.com (simon.songbird.com [72.52.113.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 024703A08C7 for <dmarc@ietf.org>; Sat, 26 Sep 2020 06:07:01 -0700 (PDT)
Received: from [192.168.0.109] (c-24-130-62-181.hsd1.ca.comcast.net [24.130.62.181]) (authenticated bits=0) by simon.songbird.com (8.14.4/8.14.4/Debian-4.1ubuntu1.1) with ESMTP id 08QDA7Nl000614 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Sat, 26 Sep 2020 06:10:07 -0700
To: Alessandro Vesely <vesely@tana.it>, dmarc@ietf.org
References: <20200815225306.967CC1E9E41D@ary.local> <6089649.VB6F1bvo3X@zini-1880> <159dc0da-0f34-fa71-e20f-89135f14182e@dcrocker.net> <6484002.GchzCIbhPQ@zini-1880> <aa8eb7e5-e16f-e99d-2164-5654ed0024dd@dcrocker.net> <af165f28-fab7-c339-1808-4c14e21631b4@tana.it>
From: Dave Crocker <dhc@dcrocker.net>
Reply-To: dcrocker@bbiw.net
Organization: Brandenburg InternetWorking
Message-ID: <12885242-5aed-ebba-644c-f629aac798ed@dcrocker.net>
Date: Sat, 26 Sep 2020 06:06:54 -0700
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:68.0) Gecko/20100101 Thunderbird/68.12.0
MIME-Version: 1.0
In-Reply-To: <af165f28-fab7-c339-1808-4c14e21631b4@tana.it>
Content-Type: multipart/alternative; boundary="------------08B1047778A67D927E5224B7"
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/a-3PZHqlEhhSY3l8-QuPAEGRARw>
Subject: Re: [dmarc-ietf] Call for Adoption: DMARC Use of the RFC5322.Sender Header Field
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 26 Sep 2020 13:07:06 -0000

On 9/26/2020 3:31 AM, Alessandro Vesely wrote:
> A pointer to a better aimed report circulated on this list:

An unrefereed presentation (not paper) about a single experiment is 
better than a summary of an industry-wide effort that failed?

And the presentation cited SMTP Mail From, as if that were the important 
field to protect. (And it doesn't even mention DKIM.)

Also, the researchers appear not to know about the issue of co-variates. 
(eg, 21% of their subjects had graduate degrees...)

And, for the current discussion, there's the troublesome summary the 
they give about their own study:

> 1. Warning only slightly lowers the click rate
> 2. The absolute click rate is still high

The key words there are "slightly" and "still high".  Prompting the 
question of why anyone would think this study serves as demonstrating 
strong support for the role of end-users in abuse protection?

All of which demonstrates a basic problem with efforts to discuss 
human-related work: difficulties in understanding how to evaluate 
research and research patterns, with a tendency to instead lean on 
confirmation bias.


d/

-- 
Dave Crocker
Brandenburg InternetWorking
bbiw.net