Re: e-postage stamps, was Welcome to the new(ish) ASRG list

Barry Shein <[email protected]> Mon, 18 Mar 2013 16:01:45 -0400
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On March 17, 2013 at 22:25 [email protected] (John Levine) wrote:
 > 
 > >Verification of a stamp wouldn't have to be much different from a DNS
 > >query. "Is the following n-tuple (perhaps source plus stamp) valid?",
 > >or likely valid would be far better than what we have now.
 > 
 > Oh, OK.  So you give me one stamp, and I use it on 100,000,000 million
 > pieces of mail, each of which verifies.  Seems reasonable.
 > 
 > If that's not what you mean, the double spending problem is what makes
 > the giant transaction system intractable.

Counterfeiting has been a problem with physical money and postage
since they were both invented (for postage think: metered stamping of
bulk postal mail.)

So although it's a worthwhile issue to raise it's not clear that it's
a show-stopper.

The first consideration is the cost of successful counterfeiting.

Some spam gets through.

But that happens now.

So that cost is zero, plus or minus any added processing.

The second is detection and the likelihood of getting caught. Like
other counterfeiting one presumes the penalties would be significant.

Seems like it would be improved with a cryptographic stamp since right
now we have nothing like this.

And prevention.

That would be improved by use of an n-tuple. If instead of just
verifying the stamp's validity you also consider the sending source
(were they issued that range of stamps? a very cheap question to ask a
distributed db) prevention and detection would be improved.

Much like they probably do with metered postage. I'd imagine the first
check when something suspicious shows up is checking whether meter
number NNNNNNN (it's in the stamp image) is located in the city where
the questionable mail (or more likely 10,000 pieces) just showed up
for delivery, originating PO, the source? It's not a sure positive but
it's a very good start, a smell test.

 > On the other hand, if you're only talking about rate limiting mail
 > sent from an individual ISP by its customers, that is a solved
 > technical problem that doesn't need stamps.

THE RECIPIENT CAN CHECK IT ALSO and customize their own
decision-making or deploy more recent or more strenuous or even just
different policies such as we don't want any of that cheap RX email
even if they do pay for their stamps but it sure is handy to know
their meter prefix and put it in the no thank you list.

Much like throwing out anything which isn't 1st class mail at home, up
to the recipient.

-- 
        -Barry Shein

The World              | [email protected]           | http://www.TheWorld.com
Purveyors to the Trade | Voice: 800-THE-WRLD        | Dial-Up: US, PR, Canada
Software Tool & Die    | Public Access Internet     | SINCE 1989     *oo*