Great Circle Associates List-Managers
(April 2001)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: we aren't the enemy, but it's hard to prove it
From: Chuq Von Rospach <chuqui @ plaidworks . com>
Date: Mon, 30 Apr 2001 11:07:04 -0700
To: James M Galvin <galvin @ acm . org>, Tom Neff <tneff @ panix . com>
Cc: <List-Managers @ greatcircle . com>
In-reply-to: <Pine.BSF.4.21.0104301101320.10986-100000@two.elistx.com>
User-agent: Microsoft-Entourage/9.0.1.3108

On 4/30/01 8:42 AM, "James M Galvin" <galvin@acm.org> wrote:

> My model was down one more level.  I was imagining sites "subscribing"
> to the service.  Thus the service could be used at the SMTP level but
> could also be used later.

Something like ORBs, but as a whitelist?

>   What we really need (or perhaps already have and I just don't know
>   where to find it) is an authenticating mechanism between mail
>   gateways - something that gets you safely across "untrusted hops"
>   and into someone's trusted domain.

Actually, I don't agree.

The *real* solution here is a way to authenticate an e-mail address. As long
as I can create e-mail from any address I want, and a receiving site can't
verify that it actually came from that site, the rest is plugging thumbs in
the dike. And that means some kind of public key authentication.

You want to fix all this, make an email address verifiable, and start
rejecting everything that won't verify. Until you do, it's always patches
and hacks that the spammers will find ways to work around.

And, of course, turning this around -- until there's a reliable public key
infrastructure that's easy to use and hard to hack  AND someone convinces
AOL to buy into it and write it into their software so AOL users *can* use
it, it'll never happen. And given how quickly AOL adopts standards in their
software....





References:
Indexed By Date Previous: Re: we aren't the enemy, but it's hard to prove it
From: "John R Levine" <johnl@iecc.com>
Next: Re: we aren't the enemy, but it's hard to prove it
From: "David W. Tamkin" <dattier@ripco.com>
Indexed By Thread Previous: Re: we aren't the enemy, but it's hard to prove it
From: James M Galvin <galvin@acm.org>
Next: Re: we aren't the enemy, but it's hard to prove it
From: Chuq Von Rospach <chuqui@plaidworks.com>

Google
 
Search Internet Search www.greatcircle.com