Re: the introduction problem, was Email and reputation (was Re: Service outages planned for April 25)

Vittorio Bertola <vittorio.bertola@open-xchange.com> Mon, 02 May 2022 10:35 UTC

Return-Path: <vittorio.bertola@open-xchange.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E66BCC157B52 for <ietf@ietfa.amsl.com>; Mon, 2 May 2022 03:35:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=open-xchange.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id D3FAlGgNqW0J for <ietf@ietfa.amsl.com>; Mon, 2 May 2022 03:35:48 -0700 (PDT)
Received: from mx3.open-xchange.com (mx3.open-xchange.com [87.191.57.183]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C3FE2C157B32 for <ietf@ietf.org>; Mon, 2 May 2022 03:35:48 -0700 (PDT)
Received: from imap.open-xchange.com (imap.open-xchange.com [10.20.28.81]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx3.open-xchange.com (Postfix) with ESMTPSA id 36A206A0DA; Mon, 2 May 2022 12:35:45 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=open-xchange.com; s=201705; t=1651487745; bh=aAdSW42bfKiDOVDJEeiUPC2v8unpsstUiRI1KR2bhcU=; h=Date:From:To:In-Reply-To:References:Subject:From; b=r0UyQZRjWYIeblRgUXBBidg5smvP2zKRgIhSlNasebEJqTYnkw4WekthjOqwoqy3g Zg9LvKYnCGObeFjkv/4SlUjkJUtNcharV09KkG6heirdM4My2mRFaamx9+Sd3XkbgY mg5mKknDnURWKYzQAUlv+yDqzrYA5rbCn4xaMP+6bXWH+cM5Htwx9B4+3bTA9zPHwN F92IR4OB27wfZYHhAZTQYFY+NrTxwNK4GdYbt7Ibr3WPOkAO8zV1pGvlh1H33+OZVA KCSUl0CXld9CCaFalRQuEJi8+lIKZXzBREGnw7jRs5XJL5h7yX3N2cr+C+/Nbs1fO8 aunS8NvR7RjMA==
Received: from appsuite-gw1.open-xchange.com ([10.20.28.81]) by imap.open-xchange.com with ESMTPSA id 7pyHCgG0b2K8WAAA3c6Kzw (envelope-from <vittorio.bertola@open-xchange.com>); Mon, 02 May 2022 12:35:45 +0200
Date: Mon, 02 May 2022 12:35:45 +0200
From: Vittorio Bertola <vittorio.bertola@open-xchange.com>
To: John Levine <johnl@taugh.com>, ietf@ietf.org
Message-ID: <626060406.28268.1651487745123@appsuite-gw1.open-xchange.com>
In-Reply-To: <t4f3j1$1mpc$1@gal.iecc.com>
References: <dcc27c29-51f8-c2a4-8ce4-ee1a3c6cb017@nostrum.com> <AAE3C51B-0150-483C-8244-3D60BC31B19A@tzi.org> <2c5df733-0f86-d319-b886-81882328caa9@network-heretics.com> <1870005490.14504.1651151102962@appsuite-gw1.open-xchange.com> <t4f3j1$1mpc$1@gal.iecc.com>
Subject: Re: the introduction problem, was Email and reputation (was Re: Service outages planned for April 25)
MIME-Version: 1.0
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 7bit
X-Priority: 3
Importance: Normal
X-Mailer: Open-Xchange Mailer v7.10.6-Rev14
X-Originating-Client: open-xchange-appsuite
Autocrypt: addr=vittorio.bertola@open-xchange.com; prefer-encrypt=mutual; keydata= mQENBFhFR+UBCACfoywFKBRfzasiiR9/6dwY36eLePXcdScumDMR8qoXvRS55QYDjp5bs+yMq41qWV9 xp/cqryY9jnvHbeF3TsE5yEazpD1dleRbkpElUBpPwXqkrSP8uXO9KkS9KoX6gdml6M4L+F82WpqYC1 uTzOE6HPmhmQ4cGSgoia2jolxAhRpzoYN99/BwpvoZeTSLP5K6yPlMPYkMev/uZlAkMMhelli9IN6yA yxcC0AeHSnOAcNKUr13yXyMlTyi1cdMJ4sk88zIbefxwg3PAtYjkz3wgvP96cNVwAgSt4+j/ZuVaENP pgVuM512m051j9SlspWDHtzrci5pBKKFsibnTelrABEBAAG0NUJlcnRvbGEsIFZpdHRvcmlvIDx2aXR 0b3Jpby5iZXJ0b2xhQG9wZW4teGNoYW5nZS5jb20+iQFABBMBAgAqBAsJCAcGFQoJCAsCBRYCAwEAAp 4BAhsDBYkSzAMABQMAAAAABYJYRUflAAoJEIU2cHmzj8qNaG0H/ROY+suCP86hoN+9RIV66Ej8b3sb8 UgwFJOJMupZfeb9yTIJwE4VQT5lTt146CcJJ5jvxD6FZn1Htw9y4/45pPAF7xLE066jg3OqRvzeWRZ3 IDUfJJIiM5YGk1xWxDqppSwhnKcMOuI72iioWxX0nGQrWxpnWJsjt08IEEwuYucDkul1PHsrLJbTd58 fiMKLVwag+IE1SPHOwkPF6arZQZIfB5ThtOZV+36Jn8Hok9XfeXWBVyPkiWCQYVX39QsIbr0JNR9kQy 4g2ZFexOcTe8Jo12jPRL7V8OqStdDes3cje9lWFLnX05nrfLuE0l0JKWEg8akN+McFXc+oV68h7nu5A Q0EWEVH5QEIAIDKanNBe1uRfk8AjLirflZO291VNkOAeUu+dIhecGnZeQW6htlDinlYOnXhtsY1mK9W PUu+xshDq7lXn2G0LxldYwyJYZaJtDgIKqVqwxfA34Lj27oqPuXwcvGhdCgt0SW/YcalRdAi0/AzUCu 5GSaj2kaGUSnBYYUP4szGJXjaK2psP5toQSCtx2pfSXQ6MaqPK9Zzy+D5xc6VWQRp/iRImodAcPf8fg JJvRyJ8Jla3lKWyvBBzJDg6MOf6Fts78bJSt23X0uPp93g7GgbYkuRMnFI4RGoTVkxjD/HBEJ0CNg22 hoHJondhmKnZVrHEluFuSnW0wBEIYomcPSPB+cAEQEAAYkBMQQYAQIAGwUCWEVH5QIbDAQLCQgHBhUK CQgLAgUJEswDAAAKCRCFNnB5s4/KjdO8B/wNpvWtOpLdotR/Xh4fu08Fd63nnNfbIGIETWsVi0Sbr8i E5duuGaaWIcMmUvgKe/BM0Fpj9X01Zjm90uoPrlVVuQWrf+vFlbalUYVZr51gl5UyUFHk+iAZCAA0WB rsmACKvuV1P7GuiX3UV9b59T9taYJxN3dNFuftrEuvsqHimFtlekUjUwoCekTJdncFusBhwz2OrKhHr WWrEsXkfh0+pURWYAlKlTxvXuI7gAfHEQM+6OnrWvXYtlhd0M1sBPnCjbyG63Qws7Rek9bEWKtH6dA6 dmT2FQT+g1S9Mdf0WkPTQNX0x24dm8IoHuD3KYwX7Svx43Xa17aZnXqUjtj1
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/61f8hcWR_upNG-FT7ZCEM0zzfV8>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 02 May 2022 10:35:53 -0000


> Il 29/04/2022 00:13 John Levine <johnl@taugh.com> ha scritto:
>  
> According to Vittorio Bertola  <vittorio.bertola@open-xchange.com>:
> >I see this as one of the many manifestations of possibly the biggest shortcoming in the original design of the Internet's architecture, i.e. not having an
> >"identity layer" taking care of user authentication and information sharing in a uniform way below all application protocols
> 
> While that might be useful for other reasons, it wouldn't solve the
> spam problem. It just replaces the spam problem with the introduction
> problem, with a side helping of the identity theft problem. There is
> no reason to believe those are easier than the spam problem.

You could still accept email from strangers, if you wanted, and it would be no worse than today. What a standard identification system would do is that it would allow you to attribute and share reputation correctly, so it would be much easier to avoid false positives (because you can be sure that email that claims to come from your friend actually comes from your friend) and it would be easier to prevent your spam filters from attributing bad reputation to the wrong entities, making them more reliable.

Then, of course, the problem becomes whether and how it is possible to actually have a secure and global identification system.

> PS: Please don't say e-postage.

I don't think I ever said so :)

-- 
Vittorio Bertola | Head of Policy & Innovation, Open-Xchange
vittorio.bertola@open-xchange.com 
Office @ Via Treviso 12, 10144 Torino, Italy