ietf-asrg
[Top] [All Lists]

RE: [Asrg] 7. Best Practices - DNSBLs - Article

2003-08-12 17:03:49
At 9:48 AM -0700 2003/08/12, Jason Steiner wrote:

 I dispute this. Blocklists have reputations, even if that reputation is
 no reputation at all, and anyone who does a minimal amount of
 research can find out what that reputation is. If you don't like a
 blocklist's reputation, don't use it.

That assumes that everyone knows the full reputation of all black lists. This is not a valid assumption. Even experienced e-mail practitioners may not know the reputation of even just the majority of the existing black lists.

 Do we really need an auditing organization to tell us that SPEWS
 has no contact information and lists more than just the spammer?
 Of course not. So what is the real goal of proposals for auditing
 organizations?

To help the people find out the necessary information more easily. Hell, we were using SPEWS at ntp.org, until I found out that they cast their net too wide. But it took collateral damage for me to find that out.

I shouldn't have to suffer collateral damage or do excessive amounts of investigation in order to determine the reputation of major black lists.

 To make sure that every blocklist follows the same standards, which
 just so happen to be the preferred standards of the person making
 the proposal! But that defeats the whole purpose of having multiple
 blocklists. And it would be far easier to start a new blocklist that
 actually embodied those standards than it would be to start a
 organization intended to enforce those standards on other blocklists
 that might well disagree with them.

No one is talking about enforcement here. We're talking about an independent third party (or parties) that survey the available black lists, try to come up with some sort of list-neutral form where they can all be compared, and then present that information to the public.

 Where are you going to find a truly impartial third party, and who's
 going to make sure that they stay impartial? Where will we find these
 angels to rule us?

This is where I was hoping a community-based effort might do us some good. Any one person or group of people might be biased one way or the other, but hopefully we could structure the effort as a whole so that these biases would tend to balance out.

--
Brad Knowles, <brad(_dot_)knowles(_at_)skynet(_dot_)be>

"They that can give up essential liberty to obtain a little temporary
safety deserve neither liberty nor safety."
    -Benjamin Franklin, Historical Review of Pennsylvania.

GCS/IT d+(-) s:+(++)>: a C++(+++)$ UMBSHI++++$ P+>++ L+ !E-(---) W+++(--) N+
!w--- O- M++ V PS++(+++) PE- Y+(++) PGP>+++ t+(+++) 5++(+++) X++(+++) R+(+++)
tv+(+++) b+(++++) DI+(++++) D+(++) G+(++++) e++>++++ h--- r---(+++)* z(+++)

_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg