ietf-asrg
[Top] [All Lists]

Re: forged bounces, was [Asrg] A CAPTCHA that automatically detects and neutralizes attacks.

2005-06-02 20:26:33
What I've been referring to as bounces may more appropriately be
called challenges.  Anyway, what I have been saying is that the
challenge (which currently looks like an ordinary email) be
standardized so that they can be universally recognized as a
challenge.  I am proposing a filter that could recognize this
challenge email. ...

Do we really have to figure out yet again why an automated C/R system
is inferior in every way to a signature system like Domainkeys?

DK in effect sends the answer to the challenge along with the original
message.  The recipient does the "challenge" by validating the message
checksum and and checking the singature against the sender's published
key.  It doesn't triple the mail traffic like C/R does, it doesn't
require that senders remember all the mail they've sent to know which
challenges are to real mail and which to forged, and as a free added
bonus, it works today with several hundred million DK signed messages
being sent and delivered every day.

Regards,
John Levine, johnl(_at_)taugh(_dot_)com, Taughannock Networks, Trumansburg NY
http://www.taugh.com


_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg



<Prev in Thread] Current Thread [Next in Thread>