Wed, 6 Sep 2017 08:44:22 +0200
Remko Tronçon <[email protected]> wrote:

> I was sort of hoping that you would come up with a magic trick after
> getting through your reading list.

Hehe, most of the problems in that list is about how to authenticate
remote servers in SMTP (like SPF, DKIM and so on). I didn't find lots of
new information from that list, frankly, and that's why I started
investigating p2p literature.

> I don't see an easy solution. Looking at my account, my guess is
> badly setup servers are the biggest problem today. Servers probably
> need to tighten their registration (e.g. no IBR, harder proof of
> validity), server vendors might
> take steps to discourage bad setups (e.g. make it hard to enable
> IBR), but you'll always
> have to deal with the case of badly setup servers (and eventually
> malicious servers) on
> a federated network, so you'll need to have S2S checks.

The problem is, last time I checked[1], one third of ejabberd servers
were running ancient versions, like 5 years old or more. There are also
lots of jabberd servers, not sure they have any registration protection
at all. Seems like we need to punish a lot of servers in order to
tighten things up.

[1]
https://chatlogs.jabber.ru/[email protected]/2017/03/02.html#15:42:12.564438
_______________________________________________
Standards mailing list
Info: https://mail.jabber.org/mailman/listinfo/standards
Unsubscribe: [email protected]
_______________________________________________

Reply via email to