spf-discuss
[Top] [All Lists]

RE: Re[2]: Agenda item: SenderID Position Statement

2004-12-07 05:51:13
Hi,
to be honest we are using SPF and following it up allready quite a while
and we never had even one false positve. In fact per definition false
positives are not possible in SPF. If domain A specifies that legit
mails from domain A originate only from Host B then domain A disallows
mails being sent on behalf of A from other hosts B. Full Stop.
If my MTA then receives a mail of A from Host C its forged as defined.
Where are here the thousands of false positives?
Maybe if owner of domain A missconfigured his SPF. Ok. But thats not
the fault of SPF.
Anyway - these are just my 10cts. I think this discussion of forwarders
doesnt bring anything. Let the market decide. Noboy is forced to
publish SPF or to check SPF.
Stefan


-----Original Message-----
From: owner-spf-discuss(_at_)v2(_dot_)listbox(_dot_)com 
[mailto:owner-spf-discuss(_at_)v2(_dot_)listbox(_dot_)com] On Behalf Of Chris 
Drake
Sent: Tuesday, December 07, 2004 1:42 PM
To: spf-discuss(_at_)v2(_dot_)listbox(_dot_)com
Subject: Re[2]: [spf-discuss] Agenda item: SenderID Position Statement

equally, and it's *really* important to *not* point out 
their faults.
Oh yeah? - like - forget the fact that SPF et al all suffer 
from 100 to 1000 *times* more false positives than the 
current leading anti spam and anti-forgery techniques - lets 
just be *dishonest* instead?
Good idea.  Really trustworthy & ethical.  Where do I 
download your code to run on my server again? :-)

You hurt yourself when you admit the shortcomings in your own 
products (or when you deliberately choose not to collect 
false-positive statistics that make you look bad)

You hurt hundreds of thousands of innocent victims (loosing 
their legit emails) when you cover up your problems.  Yeah - 
sure - it's not your fault that people using your SPF weapon 
don't know how to aim it
properly: but you can at least let them know there's other 
weapons out there that work 1000 times better.

Kind Regards,
Chris Drake

-------
Sender Policy Framework: http://spf.pobox.com/ Archives at 
http://archives.listbox.com/spf-discuss/current/
Read the whitepaper!  http://spf.pobox.com/whitepaper.pdf
To unsubscribe, change your address, or temporarily 
deactivate your subscription, please go to 
http://v2.listbox.com/member/?listname=spf-discuss(_at_)v2(_dot_)listbox(_dot_)com



  
This mail was checked for viruses by GFI MailSecurity. 
GFI also develops anti-spam software (GFI MailEssentials), a fax server (GFI 
FAXmaker), and network security and management software (GFI LANguard) - 
www.gfi.com 


<Prev in Thread] Current Thread [Next in Thread>