Re: [dmarc-ietf] Two new fields in aggregate reports

Chris Wedgwood <cw@f00f.org> Fri, 25 October 2019 16:56 UTC

Return-Path: <cw@f00f.org>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 41D01120992 for <dmarc@ietfa.amsl.com>; Fri, 25 Oct 2019 09:56:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.301
X-Spam-Level:
X-Spam-Status: No, score=-4.301 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=f00f.org
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uXIdResZvEED for <dmarc@ietfa.amsl.com>; Fri, 25 Oct 2019 09:56:29 -0700 (PDT)
Received: from proxima.stupidest.org (proxima.stupidest.org [IPv6:2600:1f14:f95:d300:5e8c:4452:4d34:d242]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4D79412098B for <dmarc@ietf.org>; Fri, 25 Oct 2019 09:56:29 -0700 (PDT)
Received: from aether.stupidest.org (tunnel-proxima-aether.stupidest.org [10.0.1.5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by proxima.stupidest.org (Postfix) with ESMTPS id 4709HZ6WFGz8K8; Fri, 25 Oct 2019 16:56:26 +0000 (UTC)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=f00f.org; s=m2016a; t=1572022586; bh=gQ6JLwso8ForZ8j5LNhhob1fCFMMz0D8JXYyrw08ZhQ=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: In-Reply-To; b=gMaj/wDJ38r1R41myygse2GRB56MnlTnXjGgyI5wRmZrPEV4FmqGWS/eSHqXdRCek cSzRAJBF0h09pzOll3mhcInenRsD49UE232c4jZT0gHEr1W6zOEX/AV30KfdCk+Wzc EgEH3qEpp+42KT1+cMc2muWzwRvA9sIUjlxhcl3BeVO7bcn6rU5ZWMpnbmLIhjlGRc GTwXDqvCAIUngbWqzrHspI7SLvUlOn6E8l1myReq7y/Ir13ZNdenfsiYrB7YHSXSk5 JncMK9Eovl/1aqL6XQzkVy383qX1duMRGbkr2Y6HKxJIDJs4AkjerJNavvuJJcxZm+ mYFHQ7ssTg1wA==
Received: by aether.stupidest.org (Postfix, from userid 10000) id 4709HZ52hkz9KQZw; Fri, 25 Oct 2019 09:56:26 -0700 (PDT)
Date: Fri, 25 Oct 2019 09:56:26 -0700
From: Chris Wedgwood <cw@f00f.org>
To: Alessandro Vesely <vesely@tana.it>
Cc: Brandon Long <blong@google.com>, "dmarc@ietf.org" <dmarc@ietf.org>
Message-ID: <20191025165626.GF12745@aether.stupidest.org>
References: <2c9f5a36-105f-22bd-2029-cb66867355c2@tana.it> <CABa8R6uJeP2HRb3G0WrGBYkDTXDhJFmbLV92_fqV1ikw7Zk0Zg@mail.gmail.com> <cccc028b-fd4b-513e-2cb9-2b458793a40e@tana.it>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <cccc028b-fd4b-513e-2cb9-2b458793a40e@tana.it>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dmarc/f4HC9bdkno0KHH_X7a9b0ngiaDQ>
Subject: Re: [dmarc-ietf] Two new fields in aggregate reports
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 25 Oct 2019 16:56:30 -0000

> Correct.  However, it is an average, so a spammer would have a hard
> time trying to work out the detail of how the receiver's score is
> computed.

[randomly] permute the input, seen 1000s of messages and look at how
the score varies ... repeat ...