spf-discuss
[Top] [All Lists]

Re: Response to DDoS using SPF

2005-03-24 07:14:09

> Simply removing SPF may not be an option.  More likely there would be a
> worldwide switch to SenderID [... ,] which avoids all these problems.

SenderID uses the same record syntax and DNS look-up system as SPF. It is, I
suspect, therefore vulnerable to the same kind of DDOS attack, with the same
potential for amplification.

Here is the original quote, in context:

As for "quick fixes", I can not come up with any that are less work than
disabling SPF all together.  Say the quick fix is to change your SPF
record, most likely close to the absolute minimum amount of work there
could possibly be.  This is exactly the same amount of work as removing
your SPF record or commenting out a line in your MTA's configuration.
In which case, if someone has negative information concerning SPF,
they'll just remove it.

Simply removing SPF may not be an option. More likely there would be a worldwide switch to SenderID or another authentication protocol like DomainKeys, which avoids all these problems.

The subordinate clause refers to DomainKeys, not SenderID. SenderID would have the same problems.

My statement was not intended to spark a debate over the merits of these different protocols, but simply to say that a successful attack on SPF could result in a worldwide switch to another protocol, even one that might have worse problems.

I have a suggestion for these discussions. Assume that someone is coming into the discussion without having read all the prior posts. Quote everything in the prior posts that is relevant. Storage is not an issue, and it is very easy if you are following the discussion closely to just skip past the quotes.

Also, I think it is a good idea to delete the automatically inserted who-said-what lines. The discussion will go more quickly if nobody feels they are being personally attacked, and have to defend some prior statement.

-- Dave

*************************************************************     *
* David MacQuigg, PhD          * email: dmquigg-spf(_at_)yahoo(_dot_)com     *  
*
* IC Design Engineer           * phone:  USA 520-721-4583      *  *  *
* Analog Design Methodologies                                  *  *  *
*                                  * 9320 East Mikelyn Lane     * * *
* VRS Consulting, P.C.             * Tucson, Arizona 85710        *
************************************************************* *


<Prev in Thread] Current Thread [Next in Thread>