Re: SPF (was: Re: Bug#257644: ITP: libspf2 -- Sender Policy Framework library, written in C)
Isaac To <iketo2@netscape.net> wrote in message news:<2kYrZ-u1-3@gated-at.bofh.it>...
> >>>>> "Erik" == Erik Aronesty <erik@zoneedit.com> writes:
> 
>     Erik> Spammers can use this loophole to get around SPF.  Thus SPF
>     Erik> is ...  well ... broken.
> 
> This complain to SRS is something new to me, and such knowledge will
> enhance our understanding on naysayers of SPF.  Care to take a look at
> 
> http://www.libsrs2.org/srs/srs.pdf
That pdf didn't work for me.  I read this instead. 
http://spf.pobox.com/srspng.html
I was thinking that a spammer could creates an envelope address with
"SRS0+hash=timestamp=aol.com=bob@throwawaydomain.com" and a From:
bob@aol.com with valid SPF info in throwawaydomain.com.
They, obviously, could do this.  Someone who sees that spam will,
likely, blame aol.com and not "throwawaydomain.com".  Just like
spammers use throwawar IP's to send mail, they will use throwaway
domains to masquerate as forwarding agents - just like they use
throwaway IP's now.
Does this tool justify the complexity and effort of implementing SPF?
Or should we be moving towards something like IM2000?
Reply to: