Re: Last Call: draft-irtf-asrg-dnsbl (DNS Blacklists and Whitelists)

"Chris Lewis" <clewis@nortel.com> Sun, 09 November 2008 06:53 UTC

Return-Path: <ietf-bounces@ietf.org>
X-Original-To: ietf-archive@megatron.ietf.org
Delivered-To: ietfarch-ietf-archive@core3.amsl.com
Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 6C71D3A6803; Sat, 8 Nov 2008 22:53:12 -0800 (PST)
X-Original-To: ietf@core3.amsl.com
Delivered-To: ietf@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 841EC3A6803 for <ietf@core3.amsl.com>; Sat, 8 Nov 2008 22:53:10 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.046
X-Spam-Level:
X-Spam-Status: No, score=-5.046 tagged_above=-999 required=5 tests=[AWL=-0.538, BAYES_00=-2.599, MISSING_HEADERS=1.292, RCVD_IN_DNSWL_MED=-4, SARE_SUB_RAND_LETTRS4=0.799]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kXwP9o2CCyfA for <ietf@core3.amsl.com>; Sat, 8 Nov 2008 22:53:09 -0800 (PST)
Received: from zrtps0kn.nortel.com (zrtps0kn.nortel.com [47.140.192.55]) by core3.amsl.com (Postfix) with ESMTP id 8B4763A63EC for <ietf@ietf.org>; Sat, 8 Nov 2008 22:53:09 -0800 (PST)
Received: from zcarhxs1.corp.nortel.com (zcarhxs1.corp.nortel.com [47.129.230.89]) by zrtps0kn.nortel.com (Switch-2.2.6/Switch-2.2.0) with ESMTP id mA96r1Z06341 for <ietf@ietf.org>; Sun, 9 Nov 2008 06:53:01 GMT
Received: from [47.130.64.220] ([47.130.64.220] RDNS failed) by zcarhxs1.corp.nortel.com with Microsoft SMTPSVC(6.0.3790.3959); Sun, 9 Nov 2008 01:52:46 -0500
Message-ID: <491688BA.7060906@nortel.com>
Date: Sun, 09 Nov 2008 01:52:42 -0500
From: Chris Lewis <clewis@nortel.com>
Organization: Nortel
User-Agent: Thunderbird 2.0.0.17 (Windows/20080914)
MIME-Version: 1.0
CC: ietf@ietf.org
Subject: Re: Last Call: draft-irtf-asrg-dnsbl (DNS Blacklists and Whitelists)
References: <20081108184543.26372.qmail@simone.iecc.com> <4915ED75.9000509@network-heretics.com> <45AEC6EF95942140888406588E1A66020413DD9E@PACDCEXCMB04.cable.comcast.com> <49167AF6.8020101@network-heretics.com>
In-Reply-To: <49167AF6.8020101@network-heretics.com>
X-OriginalArrivalTime: 09 Nov 2008 06:52:46.0278 (UTC) FILETIME=[C59C9E60:01C94237]
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Sender: ietf-bounces@ietf.org
Errors-To: ietf-bounces@ietf.org

Keith Moore wrote:
> Livingood, Jason wrote:
> 
>> Keith - I encourage you to consult with several very large scale email domains around the world to see if they think that DNSxBLs are useful, effective, and in widespread use or not.
> 
> Jason - I encourage you to consult with users whose mail isn't getting
> delivered, and see whether they think DNSBLs are useful and effective,
> or whether their mail is effectively being bounced by third parties who
> aren't accountable for their actions.

DNSBL operators can and do get sued for their actions.  Sometimes
rightfully so.

Further, accountability both for the block and its remediation, rests
mostly with the admin who deploys the filters, whether it be something
they've designed themselves, or choose to delegate to someone else
(whether it be DNSBL, Brightmail filter downloads or A-V signature
downloads etc).  Which in our case is _me_.  I don't get to blame others
for _my_ choices.

So, where's this accountability gap you keep talking about?

I found out what our users thought of DNSBLs when I accidentally turned
off DNSBL queries.  We were flooded with hundreds of complaints  about
the spam.  We get _far_ fewer complaints about false positives we have.

So the real result of your suggestion is clear.  You need to do what
Jason suggests.
_______________________________________________
Ietf mailing list
Ietf@ietf.org
https://www.ietf.org/mailman/listinfo/ietf