ietf-asrg
[Top] [All Lists]

Re: [Asrg] Re: "worm spam" and SPF

2004-12-03 18:20:04

FUSSP: http://www.rhyolite.com/anti-spam/you-might-be.html

On Dec 03 2004, gep2(_at_)terabites(_dot_)com wrote:

THE DEFAULT, for unknown/unspecified senders, would be to allow
through the mesh filter only mails smaller than a specified size
(say 25K or 50K bytes maybe) which contain no HTML and no
attachments... thus simple, text E-mails not exceeding the specified
maximum size.

So note that the proposal DOES NOT eliminate HTML-burdened mail,
nor does it impact ANY legitimate E-mail technology.  It DOES mean
that UNSOLICITED mail from UNKNOWN senders would need to be sent (as
it SHOULD be anyhow, since the format is designed for universal
readability) as small E-mails using only plain ASCII text.

This is problematic at best. Many mail reading programs don't follow
standards properly, and even try to improve on perceived shortcomings
in the name of robustness. There is never any guarantee that an ASCII
message, sent as ASCII, will actually be displayed as ASCII rather
than some other format which the reading program thinks it can somehow
deduce.

Any filter of the type you propose must still second guess how all the
major current mail reading programs will interpret ASCII, under all
their available options, settings and overrides. This is an arms race
exactly like the current one.

Furthermore, typical spam messages are 2-3K in length, well below your
proposed limit. This allows higher throughput at the spammer's end.

If the first step in your solution, namely blocking emails containing
nasty side effects, is ineffective, then you are simply proposing a
highly configurable whitelisting system, with all the associated
scalability issues.


-- 
Laird Breyer.

_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg