Summary

  • Scott Bradner's November 1996 argument distinguished control over sending a message from evidence about the identity and age of its eventual readers.
  • The RFC recognized limited Web screening and separate local controls, without treating them as guarantees covering every independently distributed copy.

A sender using a mail exploder in Bradner's 1996 account addressed one message to a mailing list. The receiving program redistributed it according to a subscriber list managed elsewhere. One subscriber could itself be another exploder, initiating another round of deliveries. The original sender had set the process in motion without necessarily knowing even the first list's membership, let alone its eventual readership (§3.2.1).

That handoff gave concrete form to the problem examined in Source Directed Access Control on the Internet. Published in November 1996, RFC 2057 named Scott Bradner of Harvard University as its author. It was adapted from a deposition submitted in a challenge to the US Communications Decency Act of 1996. Its status was Informational, explicitly not an Internet standard. It brought his technical argument about obligations placed on senders into the public RFC record (header and §1).

Who could decide what happened next?

Bradner's institutional account began with local operators: each controlled its own computers, networks and permitted links. Standards work involving IETF coordinated communication between systems. InterNIC's naming and address-registration functions helped keep identifiers unique; they did not constitute a registry of readers and their ages. In his 1996 description, neither standards coordination nor registration supplied authority over content on every participating machine (§2).

The distinction persisted even before redistribution. An email address identified a delivery destination, not authoritatively the person reading there. Bradner described self-reported details, aliases and remailers, alongside the delay between sending a message and its retrieval. A known account holder might share an account with somebody else. Bradner argued in 1996 that advance identification would add separate exchanges and clerical work, including credit-card checks or maintaining access-code records (§3.1).

Mailing lists added a locally managed membership decision. Automated subscriptions could change the audience, while nested lists extended it through another operator. Moderation selected which messages went forward; it did not establish every final reader's age. The sender, list administrator and moderator therefore occupied different positions, even when they participated in the same publication process.

USENET made the custody of copies especially important. Bradner described messages copied and stored across independently managed servers, whose local managers selected groups and access. A new server could join dissemination through an existing participant without asking original posters. The poster's decision to publish did not confer command over each server holding the message (§3.2.2).

IRC presented changing membership rather than a settled audience: participants joined conversations through relay servers and appeared under nicknames. Bradner's assessment of the resulting identification difficulties carried an explicit limitation. He stated that he had not personally operated an IRC server; this was not a verified deployment study (§3.2.3).

The Web exception was real, but local

For anonymous FTP and Gopher, Bradner's 1996 assessment emphasized limitations of then-available screening facilities. He acknowledged named, password-protected FTP access, while judging account administration burdensome for broad public access. Those judgments concerned the software and operating arrangements he described, not every possible future implementation (§§4.1–4.2).

The Web received different treatment. Forms could collect information from a visitor, and a Common Gateway Interface, or CGI, program could process it before the server granted or denied access to a particular page. Bradner thus recognized a genuine screening decision at some originating sites. He nevertheless judged identity checking and database maintenance to require substantial continuing work in 1996 (§4.3).

His qualification was twofold. Access to those facilities depended partly on the host: his account of restrictions on customers running CGI relied partly on second-hand information. Separately, his overseas-cache example illustrated a stored copy serving another reader without a fresh request reaching the original publisher. It described a mechanism, not an identified deployment.

Within that example, source screening did not automatically govern the independently stored copy. Nor did an account or requesting machine identify the human at a shared terminal. A server's hit count recorded file accesses, not unique readers or their ages. An access account, a terminal and a person were distinct subjects of evidence.

Decisions closer to the reader

Institutional screening, client blocking and content tagging placed decisions at different points. Bradner favored client-side controls in 1996 and supported voluntary and third-party ratings. But providing a rating did not ensure that every receiving client was configured to act on it. His preference was not a comparative product trial or evidence of comprehensive effectiveness. Likewise, a person's affirmative decision to retrieve material did not establish their age (§§5–6).

The mismatch concerned information as much as authority: the sender's first handoff did not reveal every later reader, while downstream operators retained their own decisions. The worldwide proof infrastructure envisaged in §8 remained undesigned and undemonstrated in the RFC. The document records a 1996 technical argument, not a permanent limit on engineering or a settlement of legal duties (§8).

Sources

Primary text: RFC 2057, plain text; HTML edition. Publication details: RFC Editor record; IETF Datatracker record. These are editions and records of the same document, not independent investigations.