Re: Email Web of Trust - Problem Statement
Mark Baugher <[email protected]> Mon, 08 Mar 2004 15:38:48 -0800
| Newsgroups | gmane.ietf.asrg.smtpverify |
|---|---|
| Message-ID | <[email protected]> |
At 02:18 PM 3/8/2004, Alan DeKok wrote: >Mark Baugher <[email protected]> wrote: > > > Taken over multiple intermediary hops, these numbers give you some > > >probability that any one message is a priori going to be spam. It's > > >not perfect, but it's a start. > > > > Yes, but it begs the question of what is spam. > > Nope. Spam is whatever a domain decides is spam. I could be missing something here, but "web of trust" to me means that a collection of principals have decided to trust each other to some degree for some specific access or authorization to some resource. So I don't understand your response. One principal that speaks for a particular domain might have its own definition, but where does the web come into play? > > One needs a very clear definition of what is spam in order to trust > > that some domain does or does not originate spam. And there could > > be more than one metric such as originating UBE promotions versus > > nefarious scams to bilk people out of their savings. > > More metrics make it more complicated. The simple question is: > > - If the message was passed from person to person, rather than being > delivered directly, what are the odds it would be marked along the > way to be spam? I think I'm missing something. Is the "web" the chain of persons (relays?), specifically, or is it more general, such as a web of mail operators that trust each others authorization decisions? Mark > It's not quite trust, but it's a start. > > > More generally, the trust could be based on a particular policy or set of > > policies: A particular domain, for example, might be trusted to adhere to > > certain antispam policies regarding UBE, authenticating senders, > responding > > to complaints, etc. > > OK. And how do you measure this? How do you enforce it? It's very >problematic. > > Alan DeKok.