Re: [Ietf-dkim] replay is a bogus concept

2023-08-15 Thread Evan Burke
On Tue, Aug 15, 2023 at 9:29 AM Emanuel Schorsch wrote: > Still, knowing that he's a bad actor, you could skip signing. Are there >> so >> many new spammers every day? Or, rather, there is a bunch of >> professional >> spammers who know how to hide? >> > > Just to answer the second question:

Re: [Ietf-dkim] Replay attack definition discussion

2023-08-15 Thread Laura Atkins
> On 15 Aug 2023, at 17:39, Dave Crocker wrote: > > On 8/15/2023 9:32 AM, Jim Fenton wrote: >> That isn’t quite fair. We thought about replay quite a bit, and didn’t see a >> viable way of addressing it. Your comment makes it sound like we didn’t care. > > To be a bit more thorough, my

Re: [Ietf-dkim] Replay attack definition discussion

2023-08-15 Thread Dave Crocker
On 8/15/2023 9:32 AM, Jim Fenton wrote: That isn’t quite fair. We thought about replay quite a bit, and didn’t see a viable way of addressing it. Your comment makes it sound like we didn’t care. To be a bit more thorough, my recollection is that we also did not expect it to be a serious

Re: [Ietf-dkim] Replay attack definition discussion

2023-08-15 Thread Laura Atkins
> On 15 Aug 2023, at 17:32, Jim Fenton wrote: > > On 15 Aug 2023, at 5:59, Laura Atkins wrote: > >> But the reality is: bad-actors are going to get through every process. If we >> could ID spammers up front and stop them from spamming we’d very likely have >> done it already. In this case,

Re: [Ietf-dkim] Replay attack definition discussion

2023-08-15 Thread Jim Fenton
On 15 Aug 2023, at 5:59, Laura Atkins wrote: > But the reality is: bad-actors are going to get through every process. If we > could ID spammers up front and stop them from spamming we’d very likely have > done it already. In this case, they’re using DKIM in a way that was forseen > by the

Re: [Ietf-dkim] Replay attack definition discussion

2023-08-15 Thread Laura Atkins
> On 15 Aug 2023, at 12:36, Alessandro Vesely wrote: > > On Tue 15/Aug/2023 08:10:23 +0200 Bron Gondwana wrote: >> "Problem solved." >> As someone who has, as a person running a service with a large number of >> customers who can send email, ... >> If you can provide me an accurate

Re: [Ietf-dkim] replay is a bogus concept

2023-08-15 Thread Alessandro Vesely
On Tue 15/Aug/2023 08:10:23 +0200 Bron Gondwana wrote: On Thu, Aug 3, 2023, at 15:50, Michael Thomas wrote: Barry Leiba Tue, 01 August 2023 18:40 UTC I do think the background is important to publish separately for this work, however easy the problem is to describe. It's because "replay"

Re: [Ietf-dkim] replay is a bogus concept

2023-08-15 Thread Bron Gondwana
On Thu, Aug 3, 2023, at 15:50, Michael Thomas wrote: > Barry Leiba Tue, 01 August 2023 18:40 UTC > > As someone who has, as an AD, questioned the publication of such > background documents, even in working groups I chartered, I can give a > related opinion about this one: > > I do think the