
Received: from manet.hmdnsgroup.com (manet.hmdnsgroup.com [63.247.133.3]) by sb7.songbird.com (8.12.11/8.12.11) with ESMTP id j3TMgmhs023918 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for <abuse-feedback-report@mipassoc.org>; Fri, 29 Apr 2005 15:42:49 -0700
Received: from pool-68-161-170-4.ny325.east.verizon.net ([68.161.170.4] helo=[192.168.0.7]) by manet.hmdnsgroup.com with esmtpsa (TLSv1:AES256-SHA:256) (Exim 4.50) id 1DReBI-0006im-3u; Fri, 29 Apr 2005 18:41:56 -0400
Message-ID: <4272B82C.8070500@solidmatrix.com>
Date: Fri, 29 Apr 2005 18:41:48 -0400
From: Yakov Shafranovich <YakovS@solidmatrix.com>
Organization: SolidMatrix Technologies, Inc.
User-Agent: Mozilla Thunderbird 1.0 (X11/20041206)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: Matthew Elvey <matthew@elvey.com>, abuse-feedback-report@mipassoc.org
Subject: Re: [feedback-report] misc comments (on	draft-shafranovich-feedback-report-00(pre I-D))
References: <427134DC.8010208@elvey.com> <4272ADF5.7020506@elvey.com>
In-Reply-To: <4272ADF5.7020506@elvey.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-HMDNSGroup-MailScanner-Information: Please contact the ISP for more information
X-HMDNSGroup-MailScanner: Found to be clean
X-MailScanner-From: yakovs@solidmatrix.com
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - manet.hmdnsgroup.com
X-AntiAbuse: Original Domain - mipassoc.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - solidmatrix.com
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-SongbirdInformation: support@songbird.com for more information
X-Songbird: Found to be clean
X-Songbird-From: yakovs@solidmatrix.com
Cc: 
X-BeenThere: abuse-feedback-report@mipassoc.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Public forum for discussion on the feedback-report draft <abuse-feedback-report.mipassoc.org>
List-Unsubscribe: <http://mipassoc.org/mailman/listinfo/abuse-feedback-report>,  <mailto:abuse-feedback-report-request@mipassoc.org?subject=unsubscribe>
List-Archive: <http://mipassoc.org/pipermail/abuse-feedback-report>
List-Post: <mailto:abuse-feedback-report@mipassoc.org>
List-Help: <mailto:abuse-feedback-report-request@mipassoc.org?subject=help>
List-Subscribe: <http://mipassoc.org/mailman/listinfo/abuse-feedback-report>,  <mailto:abuse-feedback-report-request@mipassoc.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Apr 2005 22:42:53 -0000

Matthew Elvey wrote:
> Is this intended to obsolete RFCs 1982 or 3462?
> 

Nope. I guess I should clarify the intent better in the next draft but 
this format intended as a child of 3462 just like DSNs and return 
receipts are. The intent of this specific format is a format for 
providing feedback between network operators and organizations regarding 
abuse issues primarly and related matters like opt-outs, "virus 
detected" messages, etc.

> Should we add to 2 Intent:
>   d To inform reputation service providers about email abuse by 
> entities* they vouch for.
> Also, what about ISPs providing hosting or dns for spamvertized email or 
> website addresses?
> *(by this I mean IPs or (HELO or 282[1|2].FrOM or Sender: or even PRA) 
> domains or perhaps something else)
> 

I intended to cover all of these and will clarify so in the next draft.

> =-=-=
> Change 3 b and 4 g  to be more explicit about whether the headers and 
> body must always be included (folks reading 3 b might (wrongly) assume 
> that headers are not part of the message).  Why not say that they MUST 
> be included?

Will do.

> =-=-=
> Re. 4 f:  s/x.x.x.x/[IP]/  and s/YYYY.ZZZZ/example.com/?   IPs could be 
> IPv6 IPs, and example.com is clearer, IMO.

K.

> =-=-=
> Big picture issues:
> One issue I see with this draft is that it's impossible to send such 
> reports without specialized tools; normal MUAs can't send this mime type.
> Is that a feature or a bug?  Another issue is that it implies that a 
> reporter must craft a separate email for each reportee.
> 

Both are features:
1st issue - its intended for ISP to ISP communications primarly (i.e. 
their abuse systems and things like AOL's scomp).
2nd issue - this format is intended to cover the use case of one 
report/message. Summaries and aggregate formats will follow as a 
separate standard. ISP feedback affected both of these points.

Regarding the first point once more, I would really really really like 
to write a Thunderbird/Mozilla Mail extension to generate these reports 
but don't have the time to do so.

> This thread outlines the task before us well, IMO:
> <http://groups-beta.google.com/group/news.admin.net-abuse.email/browse_frm/thread/fbb5ea0269b1fada/fdd399a8b869aa77#fdd399a8b869aa77> 
> 

I don't have the time to read through it right now but I will do so 
either Sunday night or early next week. However, a quick look through it 
seems to talk about parsing issues. I will get back on this as soon as I 
read the whole thing in detail.

> 
> =-=-=
> 
> Oh, and Yakov, you may post anything from our private email on this 
> topic. (Please post what you will or may I?) Thrilled to hear that J is 
> on board.
> 

Please go ahead.

Yakov

P.S. I am currently working on the -01 draft, I will post a list of 
planned changes over the weekend or early next week for feedback.


Received: from out1.smtp.messagingengine.com (out1.smtp.messagingengine.com [66.111.4.25]) by sb7.songbird.com (8.12.11/8.12.11) with ESMTP id j3TLx9tY020503 for <abuse-feedback-report@mipassoc.org>; Fri, 29 Apr 2005 14:59:10 -0700
Received: from frontend3.messagingengine.com (frontend3.internal [10.202.2.152]) by frontend1.messagingengine.com (Postfix) with ESMTP id 9EF4BC87319 for <abuse-feedback-report@mipassoc.org>; Fri, 29 Apr 2005 17:58:17 -0400 (EDT)
X-Sasl-enc: 3X/5TuXiEFEHGdvg4HPsIJ7ZANjrw8AT1EsW3O8plBoN 1114811897
Received: from [192.168.1.250] (pix.nextbus.com [64.142.39.201]) by frontend3.messagingengine.com (Postfix) with ESMTP id 8496A66; Fri, 29 Apr 2005 17:58:16 -0400 (EDT)
Message-ID: <4272ADF5.7020506@elvey.com>
Date: Fri, 29 Apr 2005 14:58:13 -0700
From: Matthew Elvey <matthew@elvey.com>
User-Agent: Mozilla Thunderbird 1.0 (Windows/20041206)
X-Accept-Language: en-us, en
MIME-Version: 1.0
To: abuse-feedback-report@mipassoc.org
References: <427134DC.8010208@elvey.com>
In-Reply-To: <427134DC.8010208@elvey.com>
X-Habeas-SWE-1: winter into spring
X-Habeas-SWE-2: brightly anticipated
X-Habeas-SWE-3: like Habeas SWE (tm)
X-Habeas-SWE-4: Copyright 2002 Habeas (tm)
X-Habeas-SWE-5: Sender Warranted Email (SWE) (tm). The sender of this
X-Habeas-SWE-6: email in exchange for a license for this Habeas
X-Habeas-SWE-7: warrant mark warrants that this is a Habeas Compliant
X-Habeas-SWE-8: Message (HCM) and not spam. Please report use of this
X-Habeas-SWE-9: mark in spam to <http://www.habeas.com/report/>.
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-SongbirdInformation: support@songbird.com for more information
X-Songbird: Found to be clean
X-Songbird-From: matthew@elvey.com
Subject: [feedback-report] misc comments (on draft-shafranovich-feedback-report-00(pre I-D))
X-BeenThere: abuse-feedback-report@mipassoc.org
X-Mailman-Version: 2.1.5
Precedence: list
List-Id: Public forum for discussion on the feedback-report draft <abuse-feedback-report.mipassoc.org>
List-Unsubscribe: <http://mipassoc.org/mailman/listinfo/abuse-feedback-report>,  <mailto:abuse-feedback-report-request@mipassoc.org?subject=unsubscribe>
List-Archive: <http://mipassoc.org/pipermail/abuse-feedback-report>
List-Post: <mailto:abuse-feedback-report@mipassoc.org>
List-Help: <mailto:abuse-feedback-report-request@mipassoc.org?subject=help>
List-Subscribe: <http://mipassoc.org/mailman/listinfo/abuse-feedback-report>,  <mailto:abuse-feedback-report-request@mipassoc.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Apr 2005 21:59:22 -0000

Is this intended to obsolete RFCs 1982 or 3462?

Should we add to 2 Intent:
   d To inform reputation service providers about email abuse by 
entities* they vouch for.
Also, what about ISPs providing hosting or dns for spamvertized email or 
website addresses?
*(by this I mean IPs or (HELO or 282[1|2].FrOM or Sender: or even PRA) 
domains or perhaps something else)

=-=-=
Change 3 b and 4 g  to be more explicit about whether the headers and 
body must always be included (folks reading 3 b might (wrongly) assume 
that headers are not part of the message).  Why not say that they MUST 
be included?
=-=-=
Re. 4 f:  s/x.x.x.x/[IP]/  and s/YYYY.ZZZZ/example.com/?   IPs could be 
IPv6 IPs, and example.com is clearer, IMO.
=-=-=
Big picture issues:
One issue I see with this draft is that it's impossible to send such 
reports without specialized tools; normal MUAs can't send this mime type.
Is that a feature or a bug?  Another issue is that it implies that a 
reporter must craft a separate email for each reportee.

This thread outlines the task before us well, IMO:
<http://groups-beta.google.com/group/news.admin.net-abuse.email/browse_frm/thread/fbb5ea0269b1fada/fdd399a8b869aa77#fdd399a8b869aa77> 


=-=-=

Oh, and Yakov, you may post anything from our private email on this 
topic. (Please post what you will or may I?) Thrilled to hear that J is 
on board.




