Re: Email Web of Trust - Problem Statement
Jeff Silverman <[email protected]> Mon, 08 Mar 2004 21:50:48 -0800
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
Alan DeKok wrote: >Mark Baugher <[email protected]> wrote: > > >>> Taken over multiple intermediary hops, these numbers give you some >>>probability that any one message is a priori going to be spam. It's >>>not perfect, but it's a start. >>> >>> >>Yes, but it begs the question of what is spam. >> >> > > Nope. Spam is whatever a domain decides is spam. > > Yakov, This is why I felt that each individual ought to maintain his or her own blacklist/whitelist. I recognize that it is more work. Suppose a person has a legitimate business relationship with a business. That business sends out 4 marketing E-mails a month and 1 statement a month. Then 80% of the mail traffic from this business is spam. Now, you and I might disagree on whether 20% non-spam content is sufficient that we should get mail from this business, and that would be a reasonable disagreement. If you and I each have our lists, then we need not come to a consensus, and I believe that the implementation would not be much more complicated. > > >> One needs a very clear definition of what is spam in order to trust >>that some domain does or does not originate spam. And there could >>be more than one metric such as originating UBE promotions versus >>nefarious scams to bilk people out of their savings. >> >> > > More metrics make it more complicated. The simple question is: > > - If the message was passed from person to person, rather than being > delivered directly, what are the odds it would be marked along the > way to be spam? > > It's not quite trust, but it's a start. > > > Alan, I have what I think is a very clear definition of SPAM. In my mind, SPAM is what spamassassin thinks is spam. And therein lies a problem: the SPAMmer can easily get a copy of spamassassin (it is, after all, open source), and keep crafting and crafting and crafting the message until spamassassin no longer thinks it is SPAM. Actually, I have what might be a better definition of SPAM. SPAM is any message with a successful response rate less than a certain percentage rate, say 1% or 0.1%, unless the message was explicitly agreed to by an opt-in mechanism. One of the reasons why I like this definition is because it forces the SPAMmer to receive messages. You and I are human beings (or else you are a very, very good implementation of the Turing test!) and whenever I send you an E-mail message, you always send one back to me. That's common courtesy, and you are polite. It is also a 100% response rate. But even if you skipped a message or two or three, that would reduce the response rate to 25%. By way of contrast, nobody responds to SPAMmers, they have a response rate of less than .1%. E-mail is so cheap, they can continue in business at that low rate. The problem with my better definition of SPAM is that I don't know how to measure it without trusting the SPAMmer, and that seems impossible unless there is a trust third party. I think we're in agreement that trusted third parties are undesirable solutions, yes? Unfortunately, my comment isn't helpful other than to help describe the problem. Sorry. >>More generally, the trust could be based on a particular policy or set of >>policies: A particular domain, for example, might be trusted to adhere to >>certain antispam policies regarding UBE, authenticating senders, responding >>to complaints, etc. >> >> > > OK. And how do you measure this? How do you enforce it? It's very >problematic. > > Alan DeKok. > > Sincerely yours, Jeff Silverman