Re: The introduction problem, was Thinking outside the box
Paul Smith <[email protected]> Mon, 18 Mar 2013 20:52:49 +0000
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On 18/03/2013 17:28, John Levine wrote: >>> We already have PGP and S/MIME, both fairly widely implemented. >> Do people use those as antispam methods? > No, because there is no reason to assume anything about mail with a > crypto signature unless you have a priori knowledge about the signing > agent. Which was my point. If you send me a message signed with your private key, then all that tells me is that you signed the message with your private key. If I know you, then that's good, but if I don't, then it tells me virtually nothing. But, if I tell you (and only you) my "public" key, and you sign/encrypt your message to me with MY public key, then I can be fairly sure that the signed messages I receive aren't spam. Which is the same sort of mechanism I was suggesting. i.e. the 'key' is provided by the recipient, not the sender. The difference was that a 'password' is easier for people to deal with and requires less processing power. It may not be as 'secure', but it would still stop the vast majority of spam. I agree the 'introduction problem' still exists, but that's always going to be a problem. Theoretically we can stop email forgery (DKIM, SPF, cryptographic signing etc), but the only ways I can see that we can possibly stop spam are either to have recipients 'authorise' senders somehow, or have a limited number of MTAs which all know each other and which all mail senders eventually need to use. (BTW, a 'key' would also be a way to prove explicit 'opt-in' to mailing lists - you can harvest my email address from many places, but you can't know my 'key' unless I tell you) - Paul Smith Computer Services Tel: 01484 855800 Vat No: GB 685 6987 53