Re: Thinking outside the box
Ian Eiloart <[email protected]> Mon, 18 Mar 2013 13:51:35 +0000
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On 17 Mar 2013, at 14:59, Richi Jennings <[email protected]> wrote: > On Sun, Mar 17, 2013 at 2:43 PM, Jose-Marcio Martins > <[email protected]> wrote: >> As long as we're interested on the spam problem, there are two things to be >> clearly defined. > > IME, anti-spam researchers usually answer that pair of questions like this: > > 1. It's not about content, it's about consent. > > 2. Spam is UBE -- unsolicited bulk email. > - Unsolicited means lacking informed consent. > - Bulk means automatically-generated (and does not imply large > volumes). Compare with other definitions, notably UCE (the C being > Commercial). > - Email... I'll leave that to your imagination. Actually, I think "bulk" is irrelevant. If I receive a spam message, I don't care how many other people have received it. In fact, I can't even determine that, and nor can my anti-spam software, although my ESP's anti-spam software may be able to. If I'm the first to receive it, or if it's personalised, then even the ESP can't determine that. And, if I'm to hold someone to account for spamming me, I should not have to prove that there were other recipients. UK legislation, based on EU directives, addresses unsolicited marketing email (UME), where "marketing" is broadly defined as not just offers for sale of goods or services, but also as promotion of organisational aims. In my view, a new service would need to eliminate some of the complications, so that we can hold senders and domain owners accountable for email that seems to be sent by them: 1. It would be based on LMTP, not SMTP, in order that individual accept/reject preferences can be expressed. 2. Spoofing of sender addresses would be eliminated - eg through publication of SPF records, strict control of intradomain sender spoofing, and banning of forwarding without sender rewriting. 3. Clients would expose sender information properly by showing addresses as well as comments. But, actually they might also be more careful about identifying senders properly with digital signatures. 4. Mailing lists should not need to modify message bodies. So, clients would have to expose message headers, like list-unsubscribe and list-id headers. This would mean that s-mime, dkim and pgp/gpg might not be corrupted by mailing lists, so we'd have more robust end to end authentication. 5. Domains would need to be flagged for email use. So, for example, they'd have to publish an MX record in order to be able to send email. 6. Reputation services would be based upon domains and email addresses, not IP addresses. This would make transition to IPv6 easier. 7. Currently, UK legislation includes a weak distinction between personal and business recipients. It's legal to send UME to business recipients - presumably there are businesses that like to be on the receiving end of B2B marketing. But which of these email addresses is a business address: "[email protected]", "[email protected]", "[email protected]". I think it's uncontroversial that the first is business, the last is personal. However, the middle one is ambiguous (it's a personal local part, in a business domain). I'd like to see some infrastructure for expressing the concept. Or, a personal name in the local part makes it a personal address (but what about jobs@apple�). Or, maybe the exemption should just be removed entirely. -- Ian Eiloart Postmaster, University of Sussex +44 (0) 1273 87-3148