Re: The introduction problem, was Thinking outside the box

Paul Smith <[email protected]> Mon, 18 Mar 2013 20:52:49 +0000
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On 18/03/2013 17:28, John Levine wrote:
>>> We already have PGP and S/MIME, both fairly widely implemented.
>> Do people use those as antispam methods?
> No, because there is no reason to assume anything about mail with a
> crypto signature unless you have a priori knowledge about the signing
> agent.
Which was my point. If you send me a message signed with your private 
key, then all that tells me is that you signed the message with your 
private key. If I know you, then that's good, but if I don't, then it 
tells me virtually nothing.

But, if I tell you (and only you) my "public" key, and you sign/encrypt 
your message to me with MY public key, then I can be fairly sure that 
the signed messages I receive aren't spam. Which is the same sort of 
mechanism I was suggesting. i.e. the 'key' is provided by the recipient, 
not the sender. The difference was that a 'password' is easier for 
people to deal with and requires less processing power. It may not be as 
'secure', but it would still stop the vast majority of spam. I agree the 
'introduction problem' still exists, but that's always going to be a 
problem.

Theoretically we can stop email forgery (DKIM, SPF, cryptographic 
signing etc), but the only ways I can see that we can possibly stop spam 
are either to have recipients 'authorise' senders somehow, or have a 
limited number of MTAs which all know each other and which all mail 
senders eventually need to use.

(BTW, a 'key' would also be a way to prove explicit 'opt-in' to mailing 
lists - you can harvest my email address from many places, but you can't 
know my 'key' unless I tell you)



-

Paul Smith Computer Services
Tel: 01484 855800
Vat No: GB 685 6987 53