Re: The introduction problem, was Thinking outside the box

Paul Smith <[email protected]> Mon, 18 Mar 2013 09:33:20 +0000
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On 18/03/2013 01:06, John R. Levine wrote:
>> How about simple end-to-end authentication?
>
> We already have PGP and S/MIME, both fairly widely implemented.
Do people use those as antispam methods?

Do Facebook/etc sign their emails using PGP or S/MIME?

Can I give Facebook/etc my PGP or S/MIME public key so they can encrypt 
their messages to me?

>
> This replaces the spam problem with the introduction problem, when you 
> get mail from someone who's not on your whitelist or blacklist, how do 
> you decide whether to accept it?


What I would suggest is that you still do your current filtering. But, 
you can be a bit more aggressive. You're basically giving people you 
know & lists/feeds you approve of a 'key' to get themselves through your 
spamfilter.

The main advantage over anything now would be able to give the 'key' to 
mailing lists/news feeds. Currently, a lot of spam filters can recognise 
people you've sent mail to, and thus learn to 'trust' their replies, so 
with individuals you won't get much benefit

But, a lot of news feeds use unique sender addresses which the recipient 
can't test against, or use well known sender addresses which are easily 
forged, so I can tell, for instance, Facebook, that 'my email address is 
[email protected]' AND my "email key" is 'facebookjunk'. Then, when I get a 
message from <[email protected]>', if it doesn't have the right 
'email key' in, I can distrust it, but if it does, then I can keep it.

This would be a lot easier for me to do than giving my PGP public key to 
Facebook, and it would be a lot less load on their servers than 
encrypting their messages to me.


You could get a similar effect by doing what some people already do, and 
having 'unique' email addresses for the different lists they sign up to 
(eg '[email protected]' could be almost equivalent to having an 
'email password' of 'asrg'), but it would work with situations where 
people can't easily create new email addresses, and the 'password' part 
wouldn't be visible to other people in the list.




-

Paul Smith Computer Services
Tel: 01484 855800
Vat No: GB 685 6987 53