On Second Thought, Why Not Just Ditch Sender Authentication Altogether

from the just-ditch-'em-all dept

ZaneK writes "The SPF Council has requested that the IETF revoke its support for the Sender ID SMTP authentication experiment because Sender ID conflicts with SPF in ways that can cause false positives. Because of their bickering, the IETF may pull support for both proposals. This may not matter, since, so far, spammers are the biggest beneficiaries of both SPF and Sender ID." What? A standards battle over pretty much useless technology? Who could have predicted that?
Hide this

Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.

Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.

While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.

–The Techdirt Team


Reader Comments

Subscribe: RSS

View by: Time | Thread


  • identicon
    Pete Austin, 5 Sep 2005 @ 5:41am

    SPF is better than nothing

    In particular, it makes life more difficult for mass-mailing worms. Unfortunately it's *not* a perfect guarantee that email comes from the alleged sender, despite claims that is is. My understanding is that email malware can bypass SPF by spoofing both the sending domain and the sending IP address. However it then won't receive the SMTP replies from recipients, which makes mail-sending more complex and less certain.

    How SPF Works, Why Sender ID is a non-starter, Analysis of Microsoft's MARID Patent Applications.

    link to this | view in chronology ]

  • identicon
    Matthew Elvey, 13 Sep 2005 @ 1:36am

    Buy a clue?

    Duh, authentication is only useful in conjunction with a reputation service. Large ISPs run their own; smaller mail receivers use public ones like cloudmark's or senderbase's.
    CSV makes this clear; the reputation check is part of the protocol.

    link to this | view in chronology ]


Follow Techdirt
Essential Reading
Techdirt Deals
Report this ad  |  Hide Techdirt ads
Techdirt Insider Discord

The latest chatter on the Techdirt Insider Discord channel...

Loading...
Recent Stories

This site, like most other sites on the web, uses cookies. For more information, see our privacy policy. Got it
Close

Email This

This feature is only available to registered users. Register or sign in to use it.