[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Trouble with Sender Authentication





On Nov 9, 2006, at 9:24 PM, John Levine wrote:


Could someone kindly point me to workable CSV library so that I could provide Doug with an example of using CSV to generate highier amount of amplification than his assertions about SPF?

It'll be a challenge. CSV is a single DNS query per message, so the only things you get to use for amplification are delegation and CNAMEs.

I do agree that the DNS threat from SPF is not qualitatively worse than what we already put up with for CNAMEs.

Chaining CNAMEs does not offer the same distributed attack. CNAME chaining uses resources of the attacker. While CNAMEs can be a problem, they represent a threat than can be identified and handled by the affected party. The SPF attack can not be identified and there is no defense possible. I would call that a qualitative difference.

-Doug