That much trouble?
Posted Sep 7, 2004 12:19 UTC (Tue) by
arafel (subscriber, #18557)
In reply to:
That much trouble? by khim
Parent article:
Debian rejects Sender ID
>Argh. Of course receiving servers do not need to verify PGP signature - they
>do not even need to check if it's there or not. End-user mail agent will do
>it.
Then it doesn't accomplish what SPF is trying to do. A spammer I've annoyed before has used my domain as the 'source' for one of his spam floods. If SPF had been deployed, I wouldn't have received the 100,000 bounces or so that I got.
How do you propose that PGP signing of email would help with that? Because I can't see how it would make any real difference.
Bear in mind that the aim is to drop the mail before it even really enters the system, not to post process it. We can already do that.
>And as for "simple PGP signed (by unknown key) mail" being not better then
>normal mail - it's not. It's harder to create and you can not generate
>1'000'000 different PGP keys with ease. Plus if you can not find key on
>public keyserver - it's reason enough to reject mail.
So all the spammers will do is use their zombie machines to generate keys and submit them to keyservers. Congratulations, we now have another wrecked resource.
(
Log in to post comments)