Re: Last Call: draft-irtf-asrg-dnsbl (DNS Blacklists and Whitelists)

Dave CROCKER <dhc2@dcrocker.net> Mon, 10 November 2008 15:23 UTC

Return-Path: <ietf-bounces@ietf.org>
X-Original-To: ietf-archive@megatron.ietf.org
Delivered-To: ietfarch-ietf-archive@core3.amsl.com
Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id D2F8C3A6A39; Mon, 10 Nov 2008 07:23:01 -0800 (PST)
X-Original-To: ietf@core3.amsl.com
Delivered-To: ietf@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 995DC3A68D7 for <ietf@core3.amsl.com>; Mon, 10 Nov 2008 07:23:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.8
X-Spam-Level:
X-Spam-Status: No, score=-1.8 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, SARE_SUB_RAND_LETTRS4=0.799]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GKgGqFoQTS7D for <ietf@core3.amsl.com>; Mon, 10 Nov 2008 07:22:59 -0800 (PST)
Received: from sbh17.songbird.com (mail.mipassoc.org [IPv6:2001:470:1:76:0:ffff:4834:7146]) by core3.amsl.com (Postfix) with ESMTP id 59EDC3A6A2A for <ietf@ietf.org>; Mon, 10 Nov 2008 07:22:59 -0800 (PST)
Received: from [192.168.0.3] (adsl-67-124-149-194.dsl.pltn13.pacbell.net [67.124.149.194]) (authenticated bits=0) by sbh17.songbird.com (8.13.8/8.13.8) with ESMTP id mAAFMhq4029218 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon, 10 Nov 2008 07:22:44 -0800
Message-ID: <491851C2.1020807@dcrocker.net>
Date: Mon, 10 Nov 2008 07:22:42 -0800
From: Dave CROCKER <dhc2@dcrocker.net>
Organization: Brandenburg InternetWorking
User-Agent: Thunderbird 2.0.0.17 (Windows/20080914)
MIME-Version: 1.0
To: "Steven M. Bellovin" <smb@cs.columbia.edu>
Subject: Re: Last Call: draft-irtf-asrg-dnsbl (DNS Blacklists and Whitelists)
References: <20081107111744.GA31018@nic.fr> <20081107141821.79303.qmail@simone.iecc.com> <45AEC6EF95942140888406588E1A660206A5D881@PACDCEXCMB04.cable.comcast.com> <4914D181.9090605@network-heretics.com> <278E245FD800CC334CA5100F@klensin-asus.icannmeeting.org> <4917BB4B.8000802@att.com> <20081109235116.3ef7e2f2@cs.columbia.edu>
In-Reply-To: <20081109235116.3ef7e2f2@cs.columbia.edu>
X-Virus-Scanned: ClamAV 0.92/8597/Mon Nov 10 03:55:17 2008 on sbh17.songbird.com
X-Virus-Status: Clean
X-Greylist: Sender succeeded SMTP AUTH, not delayed by milter-greylist-4.0 (sbh17.songbird.com [72.52.113.17]); Mon, 10 Nov 2008 07:22:44 -0800 (PST)
Cc: ietf@ietf.org
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
Reply-To: dcrocker@bbiw.net
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
Content-Transfer-Encoding: 7bit
Content-Type: text/plain; charset="us-ascii"; Format="flowed"
Sender: ietf-bounces@ietf.org
Errors-To: ietf-bounces@ietf.org


Steven M. Bellovin wrote:
> My concern is centralization of power.  If used properly, white lists
> are fine.  If used improperly, they're a way to form an email cartel,
> forcing organizations to buy email transit from a member of the inner
> circle.


Steve,

Email reputation lists have been around for a very long time.  The current 
specification codifies this existing practice.  So we have plenty of track 
record to test your concern.

Perhaps you know of some pattern that validates that concern, but I don't.

Such services have always been easy to set up and, indeed, there is a wide range 
of reputation services. (Positive reputation services are more recent so there 
is a smaller set to evaluate... so far.)

A standard reduces switching costs, so that consumers of reputation data are not 
locked in to their current reputation provider.

Hence, standardizing the details for obtaining reputation data -- postivie or 
negative -- ought to mitigate against centralization.

d/
-- 

   Dave Crocker
   Brandenburg InternetWorking
   bbiw.net
_______________________________________________
Ietf mailing list
Ietf@ietf.org
https://www.ietf.org/mailman/listinfo/ietf