Email and reputation (was Re: Service outages planned for April 25)

Vittorio Bertola <vittorio.bertola@open-xchange.com> Thu, 28 April 2022 13:05 UTC

Return-Path: <vittorio.bertola@open-xchange.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B580DC15E6C7 for <ietf@ietfa.amsl.com>; Thu, 28 Apr 2022 06:05:09 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=open-xchange.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DjeoQpyizJ8j for <ietf@ietfa.amsl.com>; Thu, 28 Apr 2022 06:05:05 -0700 (PDT)
Received: from mx3.open-xchange.com (mx3.open-xchange.com [87.191.57.183]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 84C4DC15E41B for <ietf@ietf.org>; Thu, 28 Apr 2022 06:05:05 -0700 (PDT)
Received: from imap.open-xchange.com (imap.open-xchange.com [10.20.28.81]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx3.open-xchange.com (Postfix) with ESMTPSA id 0A0226A0D2; Thu, 28 Apr 2022 15:05:03 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=open-xchange.com; s=201705; t=1651151103; bh=Wl1MhOQtWRKGJgz4X8UXNg+UWYn48n53fOFIvDTiRrQ=; h=Date:From:To:Cc:In-Reply-To:References:Subject:From; b=7HuWt8Ah6AyhdzUssPGnGd7LN5AZZ/wBjCeGC4IEWJiQZwvFlCl8bxuV854lWidsM DpbX8dERCd1nb0tlt5gz3ZVlPfKJc8qzD6oEYbMCJNEHWkgNQgj4zWA3Ma0lLrQTNK Vzg8UWoV5yzRMYCe0JJ77c4G6k2mHc/Vli8nXOCKpAi2GzBCOHL1it+wM7VOQuLfOV tpg/YsuwL7HtROsV2XV8ZbtACbAb9H4HgeKnhLXh6KwYY9UBGWgbLZo9GdwNteHF6k aHTAMrH//m6rhMZEWAj28Lua37JFdg9W9GB8PkxjX6NttTw+QfuieHF49yRlRMmBi3 og0eWA0aWsVpQ==
Received: from appsuite-gw1.open-xchange.com ([10.20.28.81]) by imap.open-xchange.com with ESMTPSA id 6TXyAP+QamLZPgAA3c6Kzw (envelope-from <vittorio.bertola@open-xchange.com>); Thu, 28 Apr 2022 15:05:03 +0200
Date: Thu, 28 Apr 2022 15:05:02 +0200
From: Vittorio Bertola <vittorio.bertola@open-xchange.com>
To: Keith Moore <moore@network-heretics.com>, Carsten Bormann <cabo@tzi.org>
Cc: ietf@ietf.org
Message-ID: <1870005490.14504.1651151102962@appsuite-gw1.open-xchange.com>
In-Reply-To: <2c5df733-0f86-d319-b886-81882328caa9@network-heretics.com>
References: <dcc27c29-51f8-c2a4-8ce4-ee1a3c6cb017@nostrum.com> <66aebf8b-2835-d572-ad00-eb2df514a157@nostrum.com> <626A610B.9050508@btconnect.com> <A449287A-CDA4-4173-8691-7049488FD130@ietf.org> <664edff3-3690-995f-1c1e-ce3e6c5c1eae@network-heretics.com> <44D37C5A-74E0-4C2E-AB5D-E0AA2F846331@tzi.org> <38f9687c-293d-e5db-7796-0de4939c64bf@network-heretics.com> <AAE3C51B-0150-483C-8244-3D60BC31B19A@tzi.org> <2c5df733-0f86-d319-b886-81882328caa9@network-heretics.com>
Subject: Email and reputation (was Re: Service outages planned for April 25)
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="----=_Part_14502_2011526165.1651151102948"
X-Priority: 3
Importance: Normal
X-Mailer: Open-Xchange Mailer v7.10.6-Rev14
X-Originating-Client: open-xchange-appsuite
Autocrypt: addr=vittorio.bertola@open-xchange.com; prefer-encrypt=mutual; keydata= mQENBFhFR+UBCACfoywFKBRfzasiiR9/6dwY36eLePXcdScumDMR8qoXvRS55QYDjp5bs+yMq41qWV9 xp/cqryY9jnvHbeF3TsE5yEazpD1dleRbkpElUBpPwXqkrSP8uXO9KkS9KoX6gdml6M4L+F82WpqYC1 uTzOE6HPmhmQ4cGSgoia2jolxAhRpzoYN99/BwpvoZeTSLP5K6yPlMPYkMev/uZlAkMMhelli9IN6yA yxcC0AeHSnOAcNKUr13yXyMlTyi1cdMJ4sk88zIbefxwg3PAtYjkz3wgvP96cNVwAgSt4+j/ZuVaENP pgVuM512m051j9SlspWDHtzrci5pBKKFsibnTelrABEBAAG0NUJlcnRvbGEsIFZpdHRvcmlvIDx2aXR 0b3Jpby5iZXJ0b2xhQG9wZW4teGNoYW5nZS5jb20+iQFABBMBAgAqBAsJCAcGFQoJCAsCBRYCAwEAAp 4BAhsDBYkSzAMABQMAAAAABYJYRUflAAoJEIU2cHmzj8qNaG0H/ROY+suCP86hoN+9RIV66Ej8b3sb8 UgwFJOJMupZfeb9yTIJwE4VQT5lTt146CcJJ5jvxD6FZn1Htw9y4/45pPAF7xLE066jg3OqRvzeWRZ3 IDUfJJIiM5YGk1xWxDqppSwhnKcMOuI72iioWxX0nGQrWxpnWJsjt08IEEwuYucDkul1PHsrLJbTd58 fiMKLVwag+IE1SPHOwkPF6arZQZIfB5ThtOZV+36Jn8Hok9XfeXWBVyPkiWCQYVX39QsIbr0JNR9kQy 4g2ZFexOcTe8Jo12jPRL7V8OqStdDes3cje9lWFLnX05nrfLuE0l0JKWEg8akN+McFXc+oV68h7nu5A Q0EWEVH5QEIAIDKanNBe1uRfk8AjLirflZO291VNkOAeUu+dIhecGnZeQW6htlDinlYOnXhtsY1mK9W PUu+xshDq7lXn2G0LxldYwyJYZaJtDgIKqVqwxfA34Lj27oqPuXwcvGhdCgt0SW/YcalRdAi0/AzUCu 5GSaj2kaGUSnBYYUP4szGJXjaK2psP5toQSCtx2pfSXQ6MaqPK9Zzy+D5xc6VWQRp/iRImodAcPf8fg JJvRyJ8Jla3lKWyvBBzJDg6MOf6Fts78bJSt23X0uPp93g7GgbYkuRMnFI4RGoTVkxjD/HBEJ0CNg22 hoHJondhmKnZVrHEluFuSnW0wBEIYomcPSPB+cAEQEAAYkBMQQYAQIAGwUCWEVH5QIbDAQLCQgHBhUK CQgLAgUJEswDAAAKCRCFNnB5s4/KjdO8B/wNpvWtOpLdotR/Xh4fu08Fd63nnNfbIGIETWsVi0Sbr8i E5duuGaaWIcMmUvgKe/BM0Fpj9X01Zjm90uoPrlVVuQWrf+vFlbalUYVZr51gl5UyUFHk+iAZCAA0WB rsmACKvuV1P7GuiX3UV9b59T9taYJxN3dNFuftrEuvsqHimFtlekUjUwoCekTJdncFusBhwz2OrKhHr WWrEsXkfh0+pURWYAlKlTxvXuI7gAfHEQM+6OnrWvXYtlhd0M1sBPnCjbyG63Qws7Rek9bEWKtH6dA6 dmT2FQT+g1S9Mdf0WkPTQNX0x24dm8IoHuD3KYwX7Svx43Xa17aZnXqUjtj1
Archived-At: <https://mailarchive.ietf.org/arch/msg/ietf/yqNyAVR6NASkBU7nCHuLY4T1XM4>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.34
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 28 Apr 2022 13:05:09 -0000

> Il 28/04/2022 13:39 Keith Moore <moore@network-heretics.com> ha scritto:
> 
> 
> 
> On 4/28/22 07:27, Carsten Bormann wrote:
> 
> > 
> > > 
> > > While large players can create problems, the problem is certainly not limited to one "large player".   Why, for example, do "players" of any size feel the need to manually maintain lists of IP addresses of any color?
> > > 
> > 
> > Because this appears to them to be a viable strategy for mitigating a fundamentally (outside FUSSP) unsolvable problem.
> > 
> 
> Or because they don't have better tools.   Or if better tools exist, they're not widely or uniformly used by senders.
> 
> Also, why should it be a dark art to have legitimate email successfully delivered?
> 
I see this as one of the many manifestations of possibly the biggest shortcoming in the original design of the Internet's architecture, i.e. not having an "identity layer" taking care of user authentication and information sharing in a uniform way below all application protocols. Of course, this need only became fully apparent much later than when the architecture was designed, so the architects are entirely excused; also, this is not just a technical problem, and the organizational architecture is not fully ready even now.

Still, if I had a standard way to sign my email and privately, securely disclose who I am to the recipient, we would not have had the need to build alternative identity systems such as DKIM, based on unacceptably vague proxies for the sender's identity (i.e. the domain of their email provider). Identity is a precondition for any reputation system - if you attribute reputation to the wrong identity you are going to blame someone for someone else's actions, which is exactly how antispam filters mostly work today.

--

Vittorio Bertola | Head of Policy & Innovation, Open-Xchange
vittorio.bertola@open-xchange.com mailto:vittorio.bertola@open-xchange.com
Office @ Via Treviso 12, 10144 Torino, Italy