Cost/benefit comparisons --- invitation for review.

Meng Weng Wong <[email protected]> Sat, 28 Feb 2004 14:31:42 -0500
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
On Sat, Feb 28, 2004 at 10:29:16AM -0500, Alan DeKok wrote:
|   But I don't see people doing cost/benefit analysis.  I see people
| saying "Your proposal isn't perfect, so we shouldn't implement it."  I
| don't know about anyone else, but I don't have delusions that I'm
| omnipotent, perfect, or all-knowing.  I don't believe any one solution
| will be the "magic bullet" to stop spam.  I'm willing to accept
| imperfect solutions if they are better than the alternatives.

I'm sure we've all done some degree of cost/benefit analysis, even if
it's just back-of-the-envelope or off-the-top-of-our-heads; but as Dave
Crocker says best, spam is a very complex set of problems and we need to
consider how any proposed solution or solutions will interact; and we
need to ask ourselves how spammers will respond.  This is a game, like
chess, that must be played several moves ahead.

If we can establish a vocabulary and a framework for future discussion,
at least we can agree on where we disagree.  The problems that spam
causes ISPs are very different from the problems seen by other segments.

And then there is the issue of implementation and execution.  The deployment
problem is more about politics and education than it is about technology.
The nicest bell in the world won't work if the cat doesn't want to wear it.
So it is crucial that we back something that is deployable, even if it
is not the best answer technically.  But it is also crucial that the
deployable answer we come up with is technically good enough to solve
the problems it sets out ot solve.

In the spirit of getting the cost/benefit analysis out in the open, I am
working on a set of comparisons that try to cover the technical and the
deployment grounds.  In creating the questions I was guided by the
discussion and evaluation documents that were produced by ASRG.  The
answers are entirely subjective, they are a first step, and I am not
terribly attached to any of them.

The first drafts of what I am doing can be found under

  http://dumbo.pobox.com/~mengwong/tmp/comparisons/

For example,

  http://dumbo.pobox.com/~mengwong/tmp/comparisons/spf.gif
  http://dumbo.pobox.com/~mengwong/tmp/comparisons/cid.gif
  http://dumbo.pobox.com/~mengwong/tmp/comparisons/dk.gif

I am about a third of the way through; the full list of technologies I
am trying to review is at

  http://dumbo.pobox.com/~mengwong/tmp/comparisons/full-list.tiff

They were uploaded a few days ago and I have made some changes to the
source documents since then, so if you find something that's obviously
wrong I may have already corrected them.  I will upload a new version
today or tomorrow.

I am offering these documents not for attack but for correction.
Constructive criticism is welcome.

These documents ARE NOT the official position of the SPF community.
They are not appropriate for media attention.  They are working
documents subject to change.