Re: Email web of trust - summary?
"Peter J. Holzer" <[email protected]> Mon, 8 Mar 2004 19:43:15 +0100
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
On 2004-03-04 01:06:41 -0500, Yakov Shafranovich wrote:
> There has been some fruitful discussion on the topic. Does anyone want
> to volunteer to put together a short document (something rough, not in
> ID form) so we can refer to it, and also publish on the main ASRG list
> for review?
I don't think the discussion is quite over yet, but here are the points
that have been brought up so far:
1) There needs to be some concept of identity and a means for
establishing it. An identity could be an IP address, a domain name,
an email address, a PGP key. (with various levels of usefulness and
confidence)
2) Scaling issues: The number of identities is huge. There are millions
of domain names and mail relays and vastly more email addresses.
A web of trust is likely to be a scale-free graph, though. That is,
the number of edges of the nodes is heavily skewed and there will be
some nodes with lots of edges (hubs) and many with few edges. Efficient
algorithms to search such graphs have been developed in the last few
years.
(Incidentally, research on diseases suggests that diseases can be
fought most efficiently by vaccinating the hubs, which may also be
useful in fighting spam)
Search results can also often be cached.
3) Privacy issues:
Could be ameliorated by using domain names instead of email
addresses.
4) How can the web of trust be secured from spammers?
There will be rogue members of the network, and computers will be
hijacked. So spammers will get into the web of trust.
It is expected that such incidents will be rare (compared to the
total number of participants in the web) and therefore spammers will
not gain enough trust to spam many people. Also, the rogues or
compomised identities will rapidly lose trust themselves.
Spammers can create new identities rapidly. New identities should
therefore not be trusted.
5) What is trust?
It is not a binary value, but a continuum.
It is also not a scalar, but a vector.
E.g.,
I can trust (to a certain degree) an identity to be belong to a
specific person.
I can trust (to a certain degree) an identity not be the source of
spam mail.
I can trust (to a certain degree) an identity to be careful in
choosing their friends.
I can trust (to a certain degree) an identity to be an honest
business.
...
(not all of these dimensions are relevant to spam, of course)
Trust changes over time. A newly created identity isn't trusted by
anybody and can gain trust over time. It can also lose trust if it
behaves in an unacceptable manner. The history of trust may be
relevant.
(That summary sounds rather more optimistic than I feel myself)
hp
--
_ | Peter J. Holzer | I think we need two definitions:
|_|_) | Sysadmin WSR | 1) The problem the *users* want us to solve
| | | [email protected] | 2) The problem our solution addresses.
__/ | http://www.hjp.at/ | -- Phillip Hallam-Baker on spam
[demime 0.99d.1 removed an attachment of type application/pgp-signature]