spf-discuss
[Top] [All Lists]

Re: Email Forwarder's Protocol ( EFP )

2005-02-22 17:24:34
On Tue, Feb 22, 2005 at 04:11:13PM -0700, David MacQuigg wrote:

The way I see it, we have a fundamental requirement that we be able to 
trace the path of an email through a forwarder. That is a new requirement, 
brought about by the onslaught of spam.  Many forwarders don't comply with 
the new requirement.  That doesn't mean they are "broken", just that they 
haven't caught up with the new requirement.

Trace headers have a long history...  Are you sure this is "new" ?

The new requirement is trust, not trace.  We already have trace.
The problem is you cannot trust the trace headers unless you trust
the entity you _know_ to have added such trace headers.

This implies accountability.  Accountability implies authorization.
Authorization (NOT AUTHENTICATION) is what SPF accomplishes.

In this perspective, old style forwarders are as broken as open
relays are.  There is no accountability therefore there may be
abuse.

These systems didn't suddenly break.  These kind of systems have
been broken from the start but is was never an issue.  It became
an issue when they got abused on a large scale.

"Broken" seems to be an emotional word we should avoid.  It 
only pushes the discussion further away from a consensus,

Broken is not an emotional word.  It describes the current state
of (in this case) forwarders.

"It pushes" is an opinion.  You are welcome to have an opinion
but please don't state it as being fact.

"It only pushes the ... " is an emotional response.  If you feel
better avoiding the word broken, wire your brain to parse it as
"imperfect".  Don't assume the author is using it in an
emotional way; any emotion comes from your interpretation.

and that lack of consensus is costing ...

The abuse by a small part of the world's population, not
the lack of consensus.  Apart from this: There will never
be consensus, as this would mean the abusers would have to
stop themselves.  If we can get them to do that, we don't
need ses,srs,spf,domain keys or any other technical measure.

$2 billion per month.

Australian dollars?  New-zealand dollars? Surinam Dollars?
Which small part of the world do you mean?

$2 billion go where?  Providers? Telecom operators? Government
taxes? Luxury yachts->taxes->governments->people->you?
What is "cost" ?

-- Dave

dash-dash-space-new_line-Dave please