Re: e-postage stamps, was Welcome to the new(ish) ASRG list

Barry Shein <[email protected]> Mon, 18 Mar 2013 20:28:43 -0400
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On March 18, 2013 at 22:33 [email protected] (John Levine) wrote:
 > >>>Verification of a stamp wouldn't have to be much different from a DNS
 > >>>query. "Is the following n-tuple (perhaps source plus stamp) valid?",
 > >>>or likely valid would be far better than what we have now.
 > >>
 > >> Oh, OK.  So you give me one stamp, and I use it on 100,000,000 million
 > >> pieces of mail, each of which verifies.  Seems reasonable.
 > >
 > >It's a distributed system with less-than-perfect real-time replication.
 > >So maybe 8 or 10 of them verify before every server knows the stamp is
 > >used.
 > 
 > I don't think the scale works.  Most payment systems are designed with
 > the assumption that most transactions will succeed, with failed ones
 > relatively uncommon.  In the e-postage world where 90% of the mail is
 > spam, I'd expect 90% of the stamps to be double spent.

How about an 2-tuple of (sender,stamp)?

 > This also has the adverse selection problem, it encourages phishing,
 > fake drugs, and other high value spammers who figure that it's just
 > a cost of doing business.  Or they set up the First Very Authentic
 > E-Postage Bank of Nigeria, and debase the currency.

They could, but people would have to accept it.

They might.

But then again, in the described scheme, as a recipient there's no
reason to honor e-postage at all except as a way to avoid spam, so why
bother?

I suppose the E-Postage Bank of Nigeria could try to improve its
reputation and make itself an acceptable but cheaper alternative.

Nothing inherently wrong with that, marketplace competition.

It reminds me of certificate authorities, easier said than done.


-- 
        -Barry Shein

The World              | [email protected]           | http://www.TheWorld.com
Purveyors to the Trade | Voice: 800-THE-WRLD        | Dial-Up: US, PR, Canada
Software Tool & Die    | Public Access Internet     | SINCE 1989     *oo*