Re: The introduction problem, was Thinking outside the box
Paul Smith <[email protected]> Mon, 18 Mar 2013 09:33:20 +0000
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On 18/03/2013 01:06, John R. Levine wrote: >> How about simple end-to-end authentication? > > We already have PGP and S/MIME, both fairly widely implemented. Do people use those as antispam methods? Do Facebook/etc sign their emails using PGP or S/MIME? Can I give Facebook/etc my PGP or S/MIME public key so they can encrypt their messages to me? > > This replaces the spam problem with the introduction problem, when you > get mail from someone who's not on your whitelist or blacklist, how do > you decide whether to accept it? What I would suggest is that you still do your current filtering. But, you can be a bit more aggressive. You're basically giving people you know & lists/feeds you approve of a 'key' to get themselves through your spamfilter. The main advantage over anything now would be able to give the 'key' to mailing lists/news feeds. Currently, a lot of spam filters can recognise people you've sent mail to, and thus learn to 'trust' their replies, so with individuals you won't get much benefit But, a lot of news feeds use unique sender addresses which the recipient can't test against, or use well known sender addresses which are easily forged, so I can tell, for instance, Facebook, that 'my email address is [email protected]' AND my "email key" is 'facebookjunk'. Then, when I get a message from <[email protected]>', if it doesn't have the right 'email key' in, I can distrust it, but if it does, then I can keep it. This would be a lot easier for me to do than giving my PGP public key to Facebook, and it would be a lot less load on their servers than encrypting their messages to me. You could get a similar effect by doing what some people already do, and having 'unique' email addresses for the different lists they sign up to (eg '[email protected]' could be almost equivalent to having an 'email password' of 'asrg'), but it would work with situations where people can't easily create new email addresses, and the 'password' part wouldn't be visible to other people in the list. - Paul Smith Computer Services Tel: 01484 855800 Vat No: GB 685 6987 53