Re: [saag] Ubiquitous Encryption: spam filtering

Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com> Tue, 23 June 2015 15:22 UTC

Return-Path: <kathleen.moriarty.ietf@gmail.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 51E771B2D28 for <saag@ietfa.amsl.com>; Tue, 23 Jun 2015 08:22:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id g5YEjQcxFOrx for <saag@ietfa.amsl.com>; Tue, 23 Jun 2015 08:22:44 -0700 (PDT)
Received: from mail-wg0-x230.google.com (mail-wg0-x230.google.com [IPv6:2a00:1450:400c:c00::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6B2171B2CD8 for <saag@ietf.org>; Tue, 23 Jun 2015 08:22:44 -0700 (PDT)
Received: by wgbhy7 with SMTP id hy7so12729601wgb.2 for <saag@ietf.org>; Tue, 23 Jun 2015 08:22:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=kWtcimb4iXou45xCOTcle+VTxaYxDeRtlEvMfxF4e9k=; b=ppcKp1/KiC8fDxw1DKTOwhQbByZYjNedpt0mgQQAVTyHPlT5szw3Ihte/+Lbjl7fz1 fgA8dbTt2dTyaGZenSOZ8sAc/jfoLv9qFSmb/NS/V88PNVDkyz8DoLvTrT8rzKXOLtnv qRehnmGXjBRggN3wQEkY81Th08lXy3sKhiR+g4DS1q5/umJiHEiEpinL9WiltiV/+Cj1 aXVlqKpbsTGfFvIfmuhbbksP1Q5DmO21mxWm0ql5OFomMb3IuaQ8TR99UFdtrwDvrBGC iIQYW9f9TIXvoca7sU1H2MWJxGPEF8E2kPorByt3UNJT2FGzqTVW3VOmxyyfXoMNh58d NgHg==
MIME-Version: 1.0
X-Received: by 10.194.75.132 with SMTP id c4mr8527806wjw.80.1435072963067; Tue, 23 Jun 2015 08:22:43 -0700 (PDT)
Received: by 10.28.188.134 with HTTP; Tue, 23 Jun 2015 08:22:42 -0700 (PDT)
In-Reply-To: <20150623151902.89304.qmail@ary.lan>
References: <20150623151902.89304.qmail@ary.lan>
Date: Tue, 23 Jun 2015 11:22:42 -0400
Message-ID: <CAHbuEH61zVR=EmjPS7ViGUFBRzf9YqJGhR-n90L9xt4+Qd6NHg@mail.gmail.com>
From: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
To: John Levine <johnl@taugh.com>
Content-Type: multipart/alternative; boundary="047d7bb04b7c30c2c4051930f66e"
Archived-At: <http://mailarchive.ietf.org/arch/msg/saag/PKU1SPQjMOVjNdN7ERLbnEClGqE>
Cc: "saag@ietf.org" <saag@ietf.org>
Subject: Re: [saag] Ubiquitous Encryption: spam filtering
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 23 Jun 2015 15:22:47 -0000

Hi John,

There is some text in the draft. If we missed anything or didn't go into
enough detail yet, contributions are welcome, especially if you are active
in this area.

Thank you!

On Tue, Jun 23, 2015 at 11:19 AM, John Levine <johnl@taugh.com> wrote:

> I can't find in the archives whether the ubiquitous encryption
> discussion has looked at the knotty issues of spam filtering.
>
> It's a really hard problem -- filtering is essential to keep mail
> usable, both due to the sheer volume of the spam and the need to keep
> phishing and malware away from recipients.  You can do some filtering
> on the envelope, but there's no substitute for looking at the contents
> of the message.
>
> All of the middlebox issues apply, it's much easier to do the
> filtering on a large shared server than at endpoints.  Partly that's
> because the endpoints often have limited bandwidth and compute power
> (think phones) and partly it's because effective filtering needs to
> consult shared frequently updated lists of malware signatures and
> malicious urls.
>
> R's,
> John
>
> _______________________________________________
> saag mailing list
> saag@ietf.org
> https://www.ietf.org/mailman/listinfo/saag
>



-- 

Best regards,
Kathleen