Re: Email Web of Trust - Problem Statement

Jeff Silverman <[email protected]> Mon, 08 Mar 2004 21:50:48 -0800
Newsgroups gmane.ietf.asrg.smtpverify
Message-ID <[email protected]>
Alan DeKok wrote:

>Mark Baugher <[email protected]> wrote:
>  
>
>>>  Taken over multiple intermediary hops, these numbers give you some
>>>probability that any one message is a priori going to be spam.  It's
>>>not perfect, but it's a start.
>>>      
>>>
>>Yes, but it begs the question of what is spam.
>>    
>>
>
>  Nope.  Spam is whatever a domain decides is spam.
>  
>
Yakov,

     This is why I felt that each individual ought to maintain his or 
her own blacklist/whitelist.  I recognize that it is more work.

    Suppose a person has a legitimate business relationship with a 
business.  That business sends out 4 marketing E-mails a month and 1 
statement a month.  Then 80% of the mail traffic from this business is 
spam. Now, you and I might disagree on whether 20% non-spam content is 
sufficient that we should get mail from this business, and that would be 
a reasonable disagreement.  If you and I each have our lists, then we 
need not come to a consensus, and I believe that the implementation 
would not be much more complicated.

>  
>
>> One needs a very clear definition of what is spam in order to trust
>>that some domain does or does not originate spam.  And there could
>>be more than one metric such as originating UBE promotions versus
>>nefarious scams to bilk people out of their savings.
>>    
>>
>
>  More metrics make it more complicated.  The simple question is:
>
>  - If the message was passed from person to person, rather than being
>    delivered directly, what are the odds it would be marked along the
>    way to be spam?
>
>  It's not quite trust, but it's a start.
>
>  
>
Alan,

    I have what I think is a very clear definition of SPAM.  In my mind, 
SPAM is what spamassassin thinks is spam.  And therein lies a problem: 
the SPAMmer can easily get a copy of spamassassin (it is, after all, 
open source), and keep crafting and crafting and crafting the message 
until spamassassin no longer thinks it is SPAM.

    Actually, I have what might be a better definition of SPAM.  SPAM is 
any message with a successful response rate less than a certain 
percentage rate, say 1% or 0.1%, unless the message was explicitly 
agreed to by an opt-in mechanism.  One of the reasons why I like this 
definition is because it forces the SPAMmer to receive messages.

    You and I are human beings (or else you are a very, very good 
implementation of the Turing test!) and whenever I send you an E-mail 
message, you always send one back to me.  That's common courtesy, and 
you are polite.  It is also a 100% response rate. But even if you 
skipped a message or two or three, that would reduce the response rate 
to 25%.  By way of contrast, nobody responds to SPAMmers, they have a 
response rate of less than .1%.  E-mail is so cheap, they can continue 
in business at that low rate.

    The problem with my better definition of SPAM is that I don't know 
how to measure it without trusting the SPAMmer, and that seems 
impossible unless there is a trust third party.  I think we're in 
agreement that trusted third parties are undesirable solutions, yes?

    Unfortunately, my comment isn't helpful other than to help describe 
the problem.  Sorry.

>>More generally, the trust could be based on a particular policy or set of 
>>policies:  A particular domain, for example, might be trusted to adhere to 
>>certain antispam policies regarding UBE, authenticating senders, responding 
>>to complaints, etc.
>>    
>>
>
>  OK.  And how do you measure this?  How do you enforce it?  It's very
>problematic.
>
>  Alan DeKok.
>  
>
Sincerely yours,



Jeff Silverman