[Sipping] comments on draft-wing-sipping-spam-score-00

Jonathan Rosenberg <jdrosen@cisco.com> Tue, 04 December 2007 14:41 UTC

Return-path: <sipping-bounces@ietf.org>
Received: from [127.0.0.1] (helo=stiedprmman1.va.neustar.com) by megatron.ietf.org with esmtp (Exim 4.43) id 1IzYy7-0001Wc-1f; Tue, 04 Dec 2007 09:41:51 -0500
Received: from sipping by megatron.ietf.org with local (Exim 4.43) id 1IzYy4-0001WQ-H2 for sipping-confirm+ok@megatron.ietf.org; Tue, 04 Dec 2007 09:41:48 -0500
Received: from [10.91.34.44] (helo=ietf-mx.ietf.org) by megatron.ietf.org with esmtp (Exim 4.43) id 1IzYy4-0001WI-7U for sipping@ietf.org; Tue, 04 Dec 2007 09:41:48 -0500
Received: from sj-iport-3-in.cisco.com ([171.71.176.72] helo=sj-iport-3.cisco.com) by ietf-mx.ietf.org with esmtp (Exim 4.43) id 1IzYy3-0003zr-OL for sipping@ietf.org; Tue, 04 Dec 2007 09:41:48 -0500
Received: from sj-dkim-2.cisco.com ([171.71.179.186]) by sj-iport-3.cisco.com with ESMTP; 04 Dec 2007 06:41:56 -0800
Received: from sj-core-3.cisco.com (sj-core-3.cisco.com [171.68.223.137]) by sj-dkim-2.cisco.com (8.12.11/8.12.11) with ESMTP id lB4Efelv007735 for <sipping@ietf.org>; Tue, 4 Dec 2007 06:41:41 -0800
Received: from xbh-sjc-231.amer.cisco.com (xbh-sjc-231.cisco.com [128.107.191.100]) by sj-core-3.cisco.com (8.12.10/8.12.6) with ESMTP id lB4EVOge024966 for <sipping@ietf.org>; Tue, 4 Dec 2007 14:41:40 GMT
Received: from xfe-sjc-212.amer.cisco.com ([171.70.151.187]) by xbh-sjc-231.amer.cisco.com with Microsoft SMTPSVC(6.0.3790.1830); Tue, 4 Dec 2007 06:41:34 -0800
Received: from [10.21.145.52] ([10.21.145.52]) by xfe-sjc-212.amer.cisco.com with Microsoft SMTPSVC(6.0.3790.1830); Tue, 4 Dec 2007 06:41:33 -0800
Message-ID: <47556743.5050604@cisco.com>
Date: Tue, 04 Dec 2007 09:42:11 -0500
From: Jonathan Rosenberg <jdrosen@cisco.com>
User-Agent: Thunderbird 2.0.0.9 (Windows/20071031)
MIME-Version: 1.0
To: IETF Sipping List <sipping@ietf.org>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
X-OriginalArrivalTime: 04 Dec 2007 14:41:33.0768 (UTC) FILETIME=[C40A3C80:01C83683]
DKIM-Signature: v=0.5; a=rsa-sha256; q=dns/txt; l=1062; t=1196779302; x=1197643302; c=relaxed/simple; s=sjdkim2002; h=Content-Type:From:Subject:Content-Transfer-Encoding:MIME-Version; d=cisco.com; i=jdrosen@cisco.com; z=From:=20Jonathan=20Rosenberg=20<jdrosen@cisco.com> |Subject:=20comments=20on=20draft-wing-sipping-spam-score-00 |Sender:=20; bh=Yz5x7bD9zWRnZQMLf8D2H9mlb8lvNYV50y5Ib8Dzz8w=; b=GBo3gA4yQNKxGwtZxcKeyDKZAjO+Y5g9uO/ziv04Xj3yof+VGGMmqQjGq/jryrCdlQNcf/4W V3vmFst3KNQXi7B5kv7ufvuCEd4ka+Ia7a7/5abqsaD1fnNlE02wHgqW;
Authentication-Results: sj-dkim-2; header.From=jdrosen@cisco.com; dkim=pass ( sig from cisco.com/sjdkim2002 verified; );
X-Spam-Score: -4.0 (----)
X-Scan-Signature: 7655788c23eb79e336f5f8ba8bce7906
Subject: [Sipping] comments on draft-wing-sipping-spam-score-00
X-BeenThere: sipping@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: "SIPPING Working Group \(applications of SIP\)" <sipping.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/sipping>, <mailto:sipping-request@ietf.org?subject=unsubscribe>
List-Post: <mailto:sipping@ietf.org>
List-Help: <mailto:sipping-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/sipping>, <mailto:sipping-request@ietf.org?subject=subscribe>
Errors-To: sipping-bounces@ietf.org

I think a key part of this is that you need to have a trust relationship 
with the sender of the score, otherwise its useless. As with any trust 
relationship, it requires authentication to make sure the guy you are 
talking to is the one you trust. This typically implies mutual TLS 
authentication between domains. It also means that you can't have more 
than one spam score at a time - just the one from the previous hop 
domain. So how would you authenticate and authorize the sources farther 
away, as this draft proposes?

It seems that, unless there is a standardized range and meaning of 
values it will be hard to take any action based on this value.

It would be good to give some examples of how an originating domain 
might compute the score.

-Jonathan R.
-- 
Jonathan D. Rosenberg, Ph.D.                   499 Thornall St.
Cisco Fellow                                   Edison, NJ 08837
Cisco, Voice Technology Group
jdrosen@cisco.com
http://www.jdrosen.net                         PHONE: (408) 902-3084
http://www.cisco.com


_______________________________________________
Sipping mailing list  https://www1.ietf.org/mailman/listinfo/sipping
This list is for NEW development of the application of SIP
Use sip-implementors@cs.columbia.edu for questions on current sip
Use sip@ietf.org for new developments of core SIP