Re: [dmarc-ietf] Looking for degrees of freedom with Intermediaries - Effort and Policy
Douglas Otis <doug.mtview@gmail.com> Wed, 20 May 2015 05:18 UTC
Return-Path: <doug.mtview@gmail.com>
X-Original-To: dmarc@ietfa.amsl.com
Delivered-To: dmarc@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 66EE41B357F for <dmarc@ietfa.amsl.com>; Tue, 19 May 2015 22:18:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.7
X-Spam-Level:
X-Spam-Status: No, score=0.7 tagged_above=-999 required=5 tests=[BAYES_50=0.8, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pzkNWsdQEjH8 for <dmarc@ietfa.amsl.com>; Tue, 19 May 2015 22:17:58 -0700 (PDT)
Received: from mail-qk0-x233.google.com (mail-qk0-x233.google.com [IPv6:2607:f8b0:400d:c09::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 948A21B2DC4 for <dmarc@ietf.org>; Tue, 19 May 2015 22:17:58 -0700 (PDT)
Received: by qkgx75 with SMTP id x75so24996541qkg.1 for <dmarc@ietf.org>; Tue, 19 May 2015 22:17:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=message-id:date:from:user-agent:mime-version:to:subject:references :in-reply-to:content-type:content-transfer-encoding; bh=GqS355J/Nrh7xVeW4Jg4JVZ3qw5nUvUpIdQ6lrihCTg=; b=YJy/3c3Tq4KSdTw44cQnw7RwDmCYnofx8sNTYbQzaMTE9DbewYLC+bU8hoZlUK/MW3 dX8ZQY1GhXiX+x5zUT/RP7YilOpJKdSVaorxuuhEUdO4EeQleiv6W2bExw8tnRzxlFlz ATqsyIanFcxhfiNauv851zv/vZ14+IRh9FKUOnIoQNo0SE9ChXUGonffT9N0svWDDGpV +BeqaGqlm+S1isGXxJHlm1AW2bA/sR3RCCVZv6in/KKfd//uaGO0mMewvedRzVVtouTe ThhuNj6XUin34utAM71RNVS2u9RaT8CXR/gFTrHAP9VNHyFWpmv1QFuwyPi4Ot4pgOt+ lgtA==
X-Received: by 10.55.20.215 with SMTP id 84mr66979635qku.51.1432099077884; Tue, 19 May 2015 22:17:57 -0700 (PDT)
Received: from US-DOUGO-MAC.local (107-0-5-6-ip-static.hfc.comcastbusiness.net. [107.0.5.6]) by mx.google.com with ESMTPSA id g184sm10490244qhc.6.2015.05.19.22.17.56 (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 19 May 2015 22:17:56 -0700 (PDT)
Message-ID: <555C1903.2050403@gmail.com>
Date: Tue, 19 May 2015 22:17:55 -0700
From: Douglas Otis <doug.mtview@gmail.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.10; rv:31.0) Gecko/20100101 Thunderbird/31.7.0
MIME-Version: 1.0
To: dmarc@ietf.org
References: <20150520032528.63043.qmail@ary.lan>
In-Reply-To: <20150520032528.63043.qmail@ary.lan>
Content-Type: text/plain; charset="windows-1252"
Content-Transfer-Encoding: 7bit
Archived-At: <http://mailarchive.ietf.org/arch/msg/dmarc/zZSPg9ORPed6BATjD9aVCEBdNTc>
Subject: Re: [dmarc-ietf] Looking for degrees of freedom with Intermediaries - Effort and Policy
X-BeenThere: dmarc@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "Domain-based Message Authentication, Reporting, and Compliance \(DMARC\)" <dmarc.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/dmarc>, <mailto:dmarc-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/dmarc/>
List-Post: <mailto:dmarc@ietf.org>
List-Help: <mailto:dmarc-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/dmarc>, <mailto:dmarc-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 May 2015 05:18:00 -0000
On 5/19/15 8:25 PM, John Levine wrote: >> The challenge here is that the second signer may not have anything to do with >> the message. Since, except for From, only invisible parts of the message are >> signed, the signature could be applied to almost any email. Using the >> reputation of the second signer's domain is not substantially different than >> using the reputation of an unauthenticated identity. I don't see how that >> helps. > The second signer has at least enough to do with the message that it > has a real message in hand with permission to re-sign. > > Remember the problem that got us here in the first place: AOL and > Yahoo had security failures that let crooks steal zillions of address > books, who then used botnets to send spam to AOL and Yahoo users that > appeared to be from other AOL and Yahoo users that they knew. The > actual source of the mail had nothing to do with AOL or Yahoo, or any > system that had ever gotten mail from AOL or Yahoo. > > The double signing hack limits the opportunity for trouble to mail > systems that have a recent real message in hand. While I can > certainly imagine spammy scenarios, it's hard to imagine ones that > wouldn't be fairly easy to detect and shut down. If nothing else, if > the original sender gets spam reports about double signed mail (there > are FBLs that key on DKIM signature) it can tell who's screwing > around and stop putting conditional signatures on mail to them. Dear John, I receive similar levels of spoofed friends who once had accounts with Yahoo and AOL. The phishing now tends to depend on the look and feel of the Display name rather than having an exact domain. In these cases DMARC offers little to no value. Mediators could apply a policy suitable for blocking input failing an initial hop from the DMARC domain. Any subsequent policy would then need to carve out exceptions for mediator domains that their DMARC feedback should clearly identify. Once a two stage policy scheme is facilitated that only the DMARC domain can monitor via their feedback, then only the DMARC domain would be able to spoof one of their own users. If someone cheated, the exceptions to permit these mediators could be immediately retracted. The daisy-chain alternative you proposed provides a DMARC domain less ability to stop bad actors and causes far greater change to email infrastructure for little benefit. A similar regimentation scheme will be needed. I still think this should be published as Sha-1 hash labels, but that optimization seems to make people think it is too complex. People need to think of it like a box of chocolates, you never know what you are going to get. Whatever the answer, it is authoritatively delicious. :^) Regards, Douglas Otis
- [dmarc-ietf] Looking for degrees of freedom with … Dave Crocker
- Re: [dmarc-ietf] Looking for degrees of freedom w… Hector Santos
- Re: [dmarc-ietf] Looking for degrees of freedom w… Terry Zink
- Re: [dmarc-ietf] Looking for degrees of freedom w… Hector Santos
- Re: [dmarc-ietf] Looking for degrees of freedom w… Douglas Otis
- Re: [dmarc-ietf] Looking for degrees of freedom w… Kurt Andersen (b)
- Re: [dmarc-ietf] Looking for degrees of freedom w… Hector Santos
- Re: [dmarc-ietf] Looking for degrees of freedom w… Scott Kitterman
- Re: [dmarc-ietf] Looking for degrees of freedom w… Hector Santos
- Re: [dmarc-ietf] Looking for degrees of freedom w… Stephen J. Turnbull
- Re: [dmarc-ietf] Looking for degrees of freedom w… Scott Kitterman
- Re: [dmarc-ietf] Looking for degrees of freedom w… Murray S. Kucherawy
- Re: [dmarc-ietf] Looking for degrees of freedom w… Stephen J. Turnbull
- Re: [dmarc-ietf] Looking for degrees of freedom w… Rolf E. Sonneveld
- Re: [dmarc-ietf] Looking for degrees of freedom w… Douglas Otis
- Re: [dmarc-ietf] Looking for degrees of freedom w… Terry Zink
- Re: [dmarc-ietf] Looking for degrees of freedom w… Murray S. Kucherawy
- Re: [dmarc-ietf] Looking for degrees of freedom w… Douglas Otis
- Re: [dmarc-ietf] Looking for degrees of freedom w… Terry Zink
- Re: [dmarc-ietf] Looking for degrees of freedom w… Murray S. Kucherawy
- Re: [dmarc-ietf] Looking for degrees of freedom w… Dave Crocker
- Re: [dmarc-ietf] Looking for degrees of freedom w… Scott Kitterman
- Re: [dmarc-ietf] Looking for degrees of freedom w… Murray S. Kucherawy
- Re: [dmarc-ietf] Looking for degrees of freedom w… Terry Zink
- Re: [dmarc-ietf] Looking for degrees of freedom w… Murray S. Kucherawy
- Re: [dmarc-ietf] Looking for degrees of freedom w… Terry Zink
- Re: [dmarc-ietf] Looking for degrees of freedom w… Murray S. Kucherawy
- Re: [dmarc-ietf] Looking for degrees of freedom w… Terry Zink
- Re: [dmarc-ietf] Looking for degrees of freedom w… Douglas Otis
- Re: [dmarc-ietf] Looking for degrees of freedom w… Hector Santos
- Re: [dmarc-ietf] Looking for degrees of freedom w… Murray S. Kucherawy
- Re: [dmarc-ietf] Looking for degrees of freedom w… Terry Zink
- Re: [dmarc-ietf] Looking for degrees of freedom w… Rolf E. Sonneveld
- Re: [dmarc-ietf] Looking for degrees of freedom w… Steven M Jones
- Re: [dmarc-ietf] Looking for degrees of freedom w… Rolf E. Sonneveld
- Re: [dmarc-ietf] A-R header, was Looking for degr… John Levine
- Re: [dmarc-ietf] Looking for degrees of freedom w… Murray S. Kucherawy
- Re: [dmarc-ietf] Looking for degrees of freedom w… Murray S. Kucherawy
- Re: [dmarc-ietf] Looking for degrees of freedom w… Murray S. Kucherawy
- Re: [dmarc-ietf] Looking for degrees of freedom w… John Levine
- Re: [dmarc-ietf] Looking for degrees of freedom w… Douglas Otis
- Re: [dmarc-ietf] Looking for degrees of freedom w… Scott Kitterman
- Re: [dmarc-ietf] Looking for degrees of freedom w… John Levine
- Re: [dmarc-ietf] Looking for degrees of freedom w… Scott Kitterman
- Re: [dmarc-ietf] Looking for degrees of freedom w… Douglas Otis
- Re: [dmarc-ietf] Looking for degrees of freedom w… Stephen J. Turnbull
- Re: [dmarc-ietf] Looking for degrees of freedom w… Stephen J. Turnbull
- Re: [dmarc-ietf] Looking for degrees of freedom w… Stephen J. Turnbull
- Re: [dmarc-ietf] Looking for degrees of freedom w… Stephen J. Turnbull
- [dmarc-ietf] Weaker single author signature Hector Santos
- Re: [dmarc-ietf] Looking for degrees of freedom w… Rolf E. Sonneveld
- Re: [dmarc-ietf] Looking for degrees of freedom w… Rolf E. Sonneveld
- Re: [dmarc-ietf] Looking for degrees of freedom w… Scott Kitterman
- Re: [dmarc-ietf] Looking for degrees of freedom w… Hector Santos
- Re: [dmarc-ietf] Looking for degrees of freedom w… Terry Zink
- Re: [dmarc-ietf] Looking for degrees of freedom w… Murray S. Kucherawy
- Re: [dmarc-ietf] Weaker single author signature Terry Zink
- Re: [dmarc-ietf] Weaker single author signature Douglas Otis
- Re: [dmarc-ietf] Looking for degrees of freedom w… Terry Zink
- Re: [dmarc-ietf] Weaker single author signature Terry Zink
- Re: [dmarc-ietf] Weaker single author signature Douglas Otis
- Re: [dmarc-ietf] Weaker single author signature Hector Santos
- Re: [dmarc-ietf] Weaker single author signature Murray S. Kucherawy
- Re: [dmarc-ietf] Weaker single author signature John Levine
- Re: [dmarc-ietf] Weaker single author signature MH Michael Hammer (5304)
- Re: [dmarc-ietf] Weaker single author signature Terry Zink
- Re: [dmarc-ietf] Weaker single author signature John R Levine
- Re: [dmarc-ietf] Weaker single author signature Murray S. Kucherawy
- Re: [dmarc-ietf] Weaker single author signature Murray S. Kucherawy
- Re: [dmarc-ietf] Weaker single author signature Douglas Otis
- Re: [dmarc-ietf] Weaker single author signature John Levine
- Re: [dmarc-ietf] Weaker single author signature Stephen J. Turnbull
- Re: [dmarc-ietf] Weaker single author signature Stephen J. Turnbull
- Re: [dmarc-ietf] Weaker single author signature Hector Santos
- Re: [dmarc-ietf] Weaker single author signature John Levine
- Re: [dmarc-ietf] Weaker single author signature Stephen J. Turnbull
- Re: [dmarc-ietf] Weaker single author signature John R Levine
- Re: [dmarc-ietf] Weaker single author signature Stephen J. Turnbull