public inbox for overseers@sourceware.org
 help / color / mirror / Atom feed
* ORBS redux, round n
@ 2000-12-30  6:08 Jim Kingdon
  2000-03-24  8:22 ` Jim Kingdon
  2000-12-30  6:08 ` Chris Faylor
  0 siblings, 2 replies; 32+ messages in thread
From: Jim Kingdon @ 2000-12-30  6:08 UTC (permalink / raw)
  To: overseers

OK, let me try to approach the ORBS thing in a calmer manner (yeah, I
know, fat chance, but I'll try :-)).

The current problem with ORBS is that there are situations in which
someone's mail is getting blocked and I don't know what to tell them.
For example, someone wrote in with 24.95.79.12 as their IP ("nslookup
12.79.95.24.relays.orbs.org" returns 127.0.0.4).  Note that this is a
static ORBS listing - not a listing because it was tested and found to
be an open relay (see discussion of 127.0.0.4 at
http://www.orbs.org/usingindex.html ).  Actual open relays will get
listed by RSS in due course, so people who have open relays are still
going to need to fix them, with or without ORBS.

So what are our options?

* Do nothing.  Comfort ourselves with the fact that the people annoyed
  by ORBS are fewer in number than the people annoyed by spam.

* Tell people "you need to allow ORBS to probe for open relays on your
  network".  Do we really want to require this as a condition for
  sending email to us?  And is it known that concern over being probed
  is the only reason people get a static ORBS listing?

* Modify our tester so that we only consider ORBS listings of
  127.0.0.2.  I guess the main downside for me is just that it would
  make our configuration more complicated at a time when we are having
  fewer and fewer resources (that I've noticed, anyway) available for
  maintain a complex configuration.

* Stop using ORBS and rely on RSS for open relay blocking.  There are
  certain problems which the above solutions don't solve (multi-level
  relays, the PR factor of whether ORBS is widely respected quite
  aside from whether those perceptions are justified, there might be
  others).  The question is how much spam RSS would let through that
  is currently being blocked by ORBS.

    [kingdon@sourceware /qmail]$ grep RSS /var/log/rbl-checks | wc -l
	112
    [kingdon@sourceware /qmail]$ grep ORBS /var/log/rbl-checks | wc -l
	396
    [kingdon@sourceware /qmail]$ 

  If memory serves, rblcheck checks RSS first, then ORBS, so the above
  numbers are pretty bad for RSS.

* Any others?

I guess I'm leaning towards "do nothing" until/unless RSS gets more
effective.

^ permalink raw reply	[flat|nested] 32+ messages in thread
* Re: ORBS redux, round n
@ 2000-12-30  6:08 Phil Edwards
  2000-03-24  9:04 ` Phil Edwards
  0 siblings, 1 reply; 32+ messages in thread
From: Phil Edwards @ 2000-12-30  6:08 UTC (permalink / raw)
  To: overseers

Chris Faylor <cgf@cygnus.com>:
> On Fri, Mar 24, 2000 at 04:54:42PM +0000, Jonathan Larmour wrote:
> >Jim Kingdon wrote:
> >> 
> >> The current list of people in the "sourceware" group (who can edit
> >> infra/bin/rbl-whitelist) are:
> >
> >Well, if I do get added to the sourceware group, my first act will be
> >editting http://sourceware.cygnus.com/sourceware/spam.html to mention this
> >file!
>
> Do we want to make it publicly known that there is a whitelist?  That might
> remove an incentive for people to actually work to fix the problem.

"If you make an exception for one, you'll have to make exceptions for
everyone..."

My experience with these kinds of exceptions is that you don't publicize
them, and that you make the requirements to get on the list very stringent,
with no exceptions.  Of course, if you're going to be stringent about
no-exceptions-on-the-exceptions-list, you should probably be stringent
about ORBS in the first place, etc, etc.


Phil

^ permalink raw reply	[flat|nested] 32+ messages in thread

end of thread, other threads:[~2000-12-30  6:08 UTC | newest]

Thread overview: 32+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2000-12-30  6:08 ORBS redux, round n Jim Kingdon
2000-03-24  8:22 ` Jim Kingdon
2000-12-30  6:08 ` Chris Faylor
2000-03-24  8:28   ` Chris Faylor
2000-12-30  6:08   ` Jonathan Larmour
2000-03-24  8:32     ` Jonathan Larmour
2000-12-30  6:08     ` Chris Faylor
2000-03-24  8:33       ` Chris Faylor
2000-12-30  6:08       ` Jim Kingdon
2000-03-24  8:41         ` Jim Kingdon
2000-12-30  6:08         ` Tom Tromey
2000-03-24  8:50           ` Tom Tromey
2000-12-30  6:08           ` Chris Faylor
2000-03-24  8:53             ` Chris Faylor
2000-12-30  6:08         ` Jonathan Larmour
2000-03-24  8:54           ` Jonathan Larmour
2000-12-30  6:08           ` Jeffrey A Law
2000-03-24  9:19             ` Jeffrey A Law
2000-12-30  6:08             ` Jonathan Larmour
2000-03-24  9:22               ` Jonathan Larmour
2000-12-30  6:08               ` Chris Faylor
2000-03-24  9:57                 ` Chris Faylor
2000-12-30  6:08           ` Chris Faylor
2000-03-24  8:58             ` Chris Faylor
2000-12-30  6:08             ` Chris Faylor
2000-03-24  9:02               ` Chris Faylor
2000-12-30  6:08               ` Jim Kingdon
2000-03-24  9:54                 ` Jim Kingdon
2000-12-30  6:08         ` Jeffrey A Law
2000-03-24  9:11           ` Jeffrey A Law
  -- strict thread matches above, loose matches on Subject: below --
2000-12-30  6:08 Phil Edwards
2000-03-24  9:04 ` Phil Edwards

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).