Wed, 6 Sep 2017 08:44:22 +0200 Remko Tronçon <[email protected]> wrote:
> I was sort of hoping that you would come up with a magic trick after > getting through your reading list. Hehe, most of the problems in that list is about how to authenticate remote servers in SMTP (like SPF, DKIM and so on). I didn't find lots of new information from that list, frankly, and that's why I started investigating p2p literature. > I don't see an easy solution. Looking at my account, my guess is > badly setup servers are the biggest problem today. Servers probably > need to tighten their registration (e.g. no IBR, harder proof of > validity), server vendors might > take steps to discourage bad setups (e.g. make it hard to enable > IBR), but you'll always > have to deal with the case of badly setup servers (and eventually > malicious servers) on > a federated network, so you'll need to have S2S checks. The problem is, last time I checked[1], one third of ejabberd servers were running ancient versions, like 5 years old or more. There are also lots of jabberd servers, not sure they have any registration protection at all. Seems like we need to punish a lot of servers in order to tighten things up. [1] https://chatlogs.jabber.ru/[email protected]/2017/03/02.html#15:42:12.564438 _______________________________________________ Standards mailing list Info: https://mail.jabber.org/mailman/listinfo/standards Unsubscribe: [email protected] _______________________________________________
