spf-discuss
[Top] [All Lists]

RE: Sender-ID in Gmail advertising

2004-12-23 07:11:48
Only problem with challenge response is that spammers can work around them.... 
automated tools to response to the challenge, even placing the challange image 
on other sites (Usualy adult sites) to get someone else to complete the 
challange has been know to work...

E.g.

1. Spammer sends e-mail that is SPF valid
2. Receive sends challenge to spammer
3. Spammer puts the challenge up on some adult site their own
4. Visitor to the adult site is presented with the same challenge to gain 
access.
5. Spammer captures the response and sends to the e-mail receiver
6. Spammer is then fully verified!

Not 100% successful as you can imagine!

I am working on something vagauley similar but that hopefully does offer 100% 
success rate.... currently working on integrating a sender verification systme.

Dan Field
ClearMyMail.com

-----Original Message-----
From: owner-spf-discuss(_at_)v2(_dot_)listbox(_dot_)com
[mailto:owner-spf-discuss(_at_)v2(_dot_)listbox(_dot_)com]On Behalf Of 
jpinkerton
Sent: 23 December 2004 14:04
To: spf-discuss(_at_)v2(_dot_)listbox(_dot_)com
Subject: Re: [spf-discuss] Sender-ID in Gmail advertising



----- Original Message -----
From: "jpinkerton" <johnp(_at_)idimo(_dot_)com>
To: <spf-discuss(_at_)v2(_dot_)listbox(_dot_)com>
Sent: Thursday, December 23, 2004 3:00 PM
Subject: Re: [spf-discuss] Sender-ID in Gmail advertising



----- Original Message -----
From: "jpinkerton" <johnp(_at_)idimo(_dot_)com>
To: <spf-discuss(_at_)v2(_dot_)listbox(_dot_)com>
Sent: Thursday, December 23, 2004 2:53 PM
Subject: Re: [spf-discuss] Sender-ID in Gmail advertising



----- Original Message -----
From: "Rene Barbier" <Rene(_dot_)Barbier(_at_)irislink(_dot_)com>
To: <spf-discuss(_at_)v2(_dot_)listbox(_dot_)com>
Sent: Thursday, December 23, 2004 2:38 PM
Subject: Re: [spf-discuss] Sender-ID in Gmail advertising


jpinkerton wrote:
Now being advertised on Gmail :-(



Use Sender ID to End Spam
Maintenance Free Network Appliance Stop 100% of spam email
www.sendio.com


Their web site mentions a Challenge/Response mechanism combined (how?)
with SPF, but not Sender ID

Dunno -
it also mentions
"
a.. Eliminates 100% of machine generated Spam
a.. Patented Sender Authentication technology
a.. Processes five millions messages per day
a.. High-availability Cluster of 2 Pentium....................
"

Patented????

It's a bit strange to see spf being sold as hardware ;-)

Quote--

" How Sendio ICE Box Eliminates SPAM
Sendio ICE Box holds email from all unverified senders until the sender is
authenticated. Senders are sent a one-time authentication request, to
verify
their identity. Upon verification, Sendio ICE Box releases the email to
your
corporate mail server and the message is delivered.

Fact: Spammers operate behind a veil of anonymity created by the gap in
the
SMTP protocol. Spammers can not compromise this veil of protection by
responding to an ICE Box authentication request. "

--endQuote

"unverified senders" appears to be a reference to failures from a
sender-ID
check, and then a c/r method is used.  It's like the new IBM system.

I suppose I'll link it in the website just for the sake of
completeness........


Sorry - forgot the url of the quote - -
http://www.sendio.com/tools/free_form_content/view.html?phase=show&id=107206
4753&tool_id=38&cat_id=2.4


Kind regards,

John Pinkerton.
johnp(_at_)idimo(_dot_)com
ICQ 313355492


-------
Sender Policy Framework: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Read the whitepaper!  http://spf.pobox.com/whitepaper.pdf
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname=spf-discuss(_at_)v2(_dot_)listbox(_dot_)com

-------
Sender Policy Framework: http://spf.pobox.com/
Archives at http://archives.listbox.com/spf-discuss/current/
Read the whitepaper!  http://spf.pobox.com/whitepaper.pdf
To unsubscribe, change your address, or temporarily deactivate your 
subscription, 
please go to 
http://v2.listbox.com/member/?listname=spf-discuss(_at_)v2(_dot_)listbox(_dot_)com