mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Matti Aarnio <matti.aarnio@zmailer.org>
To: Simon Oosthoek <simon.oosthoek@ti-wmc.nl>
Cc: Matti Aarnio <matti.aarnio@zmailer.org>, linux-kernel@vger.kernel.org
Subject: Re: VGER does gradual SPF activation  (FAQ matter)
Date: Tue, 13 Jun 2006 20:41:40 +0300	[thread overview]
Message-ID: <20060613174140.GC27502@mea-ext.zmailer.org> (raw)
In-Reply-To: <448D8B2F.8060405@ti-wmc.nl>

On Mon, Jun 12, 2006 at 05:41:35PM +0200, Simon Oosthoek wrote:
> Hi Matti

Hello Simon,  for a change somebody who gets my name correctly :-)
(Just today I did teach a Londoner to pronounce that double-t properly,
it did sound weird...)

> Matti Aarnio wrote:
> >
> >For a very long time (like 20 years or so) I used to think like that.
> >
> >Doing email services in big ISP environments for about 10 years did
> >cure me of that thinking.  Ordinary Janes and Joes (and grannies
> >and granpas) must not be allowed to send email in similar ways that
> >we used to do in happy 1980es when the internet was engineer playground.
> 
> This is so against the spirit and meaning of the Internet, you're not 
> talking about the network we call Internet. You're talking about two 
> tiered internet, which is bad too.

Yes, I agree.  Surprisingly by calling it "security enhanced" or something,
ISPs can  _charge_more_,  and users are happy to buy it!  (I have seen this
happening in Finland.)

I have also seen compartementalisation(sp?) failures resulting from
"these customer networks can send email via those SMTP servers" - and
then a user changes access provider, but not email provider (or does
not know how to change OE configurations to match..)
There a widely adopted SMTP SUBMISSION protocol (SMTP on TCP port 587
and _requiring_ at least sender authentication before _any_ sort of
sending is allowed - preferrably under TLS) would make that subset
of users isp-change problems moot.
Also the server configuration is simple: "user did authenticate ok,
let it send that email" - no network ACLs to keep up at all.

With authentication done, ISP can even verify source address validity
on the submission, or perhaps choose not to verify..  It might again
be a positive sales argument.

Travellers would have _easy_ access to their "home postoffice" over
the network, and be able to send email authenticated no matter where
they are, and in whose network _without_need_to_find_ that local SMTP
server that lets them send their email...

Of course ISPs would need to  a)  enable the service (and do it
correctly),  b)  educate their users to use it.


And this, by the way, is something that I do think that people SHOULD
use, no matter if SPF (or its likes) ever makes it mandatory.

It will block tons of email viruses from sending themselves around,
until they learn to pick user's submission authentication data.
.. and when they do, service provider can block that USER whose
account is misused.


> >The Internet needs to be segregated into two kinds of users - those that
> >must not be allowed to do much of anything ( = common man to whom the
> >internet equals anyway to IE web-browser ) and to first-class citizens
> >with their own email servers...
> 
> Why don't you go fork the Internet then? Go see if that will work?
> 
> This whole discussion is kind of ridiculous for an open source project 
> like the linux kernel. If you're so keen on fixing e-mail, you should 
> work closely with the IETF working groups to create a new standard that 
> works.

Do read RFC 2821/2822 credits section.

I have been on this business quite a while :-)

> Finally, if you consider doing this, why not consider closing the 
> mailinglist to a subscription only list, that will work so much better 
> than this "free lunch" (to quote someone else)
> 
> Cheers
> Simon

Cheers from London,
  Matti Aarnio

  parent reply	other threads:[~2006-06-13 17:41 UTC|newest]

Thread overview: 101+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-06-10 22:27 Matti Aarnio
2006-06-10 23:06 ` David Woodhouse
2006-06-11  0:16   ` Rik van Riel
2006-06-11  0:44     ` David Woodhouse
2006-06-11 13:02     ` Theodore Tso
2006-06-11 13:55       ` Rik van Riel
2006-06-11 14:03         ` Avi Kivity
2006-06-12  8:47           ` Matthias Andree
2006-06-12 10:17             ` Neil Brown
2006-06-12 10:35               ` David Woodhouse
2006-06-12 11:07               ` Matthias Andree
2006-06-11  2:24   ` marty fouts
2006-06-11  2:41     ` jdow
2006-06-11  2:58       ` David Schwartz
2006-06-11  5:17         ` jdow
2006-06-12  8:18           ` Bernd Petrovitsch
2006-06-12  8:23             ` jdow
2006-06-12  8:31               ` Bernd Petrovitsch
2006-06-12  9:47               ` Neil Brown
2006-06-12 10:30                 ` Alan Cox
2006-06-12 10:33                   ` Neil Brown
2006-06-12 17:37               ` Gerhard Mack
2006-06-12 18:14                 ` Krzysztof Halasa
2006-06-12 18:46                   ` jdow
2006-06-12 19:16                     ` Krzysztof Halasa
2006-06-12 21:51                   ` Bernd Petrovitsch
2006-06-13 21:12                 ` David Woodhouse
2006-06-12  9:53             ` Alan Cox
2006-06-12 10:01               ` Bernd Petrovitsch
2006-06-12 11:14                 ` Matthias Andree
2006-06-12 10:58               ` Neil Brown
2006-06-12 11:22                 ` Matthias Andree
2006-06-12 11:42             ` Kyle Moffett
2006-06-13 23:32               ` Scott Lockwood
2006-06-13 23:42                 ` Kyle Moffett
2006-06-14  0:02               ` Neil Brown
2006-06-14 10:20                 ` Matthias Andree
2006-06-16  3:53                   ` Kyle Moffett
2006-06-12  8:27     ` Bernd Petrovitsch
2006-06-12 20:25       ` Horst von Brand
2006-06-12 21:10         ` Nick Warne
2006-06-12 22:06           ` Jesper Juhl
2006-06-12 22:12             ` Randy.Dunlap
2006-06-12 23:03             ` jdow
2006-06-13  3:00               ` Horst von Brand
2006-06-13  5:54                 ` jdow
2006-06-13  8:36                   ` Bernd Petrovitsch
2006-06-13  9:58                   ` Marc Perkel
2006-06-13 13:28                   ` Horst von Brand
2006-06-13 14:34                     ` David Woodhouse
2006-06-13  9:05                 ` David Woodhouse
2006-06-13 10:45                   ` Matthias Andree
2006-06-13 12:24                     ` David Woodhouse
2006-06-13 12:49                       ` Matthias Andree
2006-06-13 13:10                         ` David Woodhouse
2006-06-13 15:19                         ` Marc Perkel
2006-06-13 15:57                           ` Auke Kok
2006-06-13 19:54                             ` David Woodhouse
2006-06-13 20:31                               ` Lennart Sorensen
2006-06-13 20:48                                 ` David Woodhouse
2006-06-15 17:05               ` Keith Owens
2006-06-15 23:14                 ` Wakko Warner
2006-06-13  0:11             ` Phil Oester
2006-06-13  0:26               ` David Miller
2006-06-13  4:18                 ` Willy Tarreau
2006-06-13 15:17               ` Joel Jaeggli
2006-06-12 21:43         ` Bernd Petrovitsch
2006-06-13  3:05           ` Horst von Brand
2006-06-13  8:31             ` Bernd Petrovitsch
2006-06-13 10:50               ` Matthias Andree
2006-06-13 13:15                 ` Justin Piszcz
2006-06-11  5:09   ` Neil Brown
2006-06-11  5:26     ` jdow
2006-06-11  6:12       ` Willy Tarreau
2006-06-11 16:02 ` Folkert van Heusden
2006-06-11 17:54   ` Lee Revell
2006-06-11 18:54     ` David Miller
2006-06-12  9:09       ` Matthias Andree
2006-06-12 11:32       ` Nikita Danilov
2006-06-12 14:52       ` Jeff Garzik
2006-06-12 20:00         ` David Miller
2006-06-12 22:29           ` Jesper Juhl
2006-06-12 22:48             ` David Miller
2006-06-12 22:57               ` Jesper Juhl
2006-06-13  3:54         ` VGER does gradual SPF activation (FAQ matter) - Alternative Marc Perkel
2006-06-13  4:51           ` David Miller
2006-06-13 13:41         ` VGER does gradual SPF activation (FAQ matter) Athanasius
2006-06-11 17:31 ` Marc Perkel
2006-06-11 18:50 ` Florian Weimer
     [not found] ` <20060611072223.GA16150@flint.arm.linux.org.uk>
2006-06-12  8:32   ` Matti Aarnio
2006-06-12  8:40     ` Russell King
2006-06-12  9:57       ` Neil Brown
2006-06-12 15:55         ` Russell King
2006-06-12 20:06       ` Zwane Mwaikambo
2006-06-12 11:22     ` David Woodhouse
2006-06-12 15:41     ` Simon Oosthoek
2006-06-12 22:55       ` Matthias Andree
2006-06-13 17:41       ` Matti Aarnio [this message]
2006-06-12  9:05 ` Matthias Andree
2006-06-12 17:28   ` Matthew Frost
2006-06-13  0:12   ` David Woodhouse

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20060613174140.GC27502@mea-ext.zmailer.org \
    --to=matti.aarnio@zmailer.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=simon.oosthoek@ti-wmc.nl \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®