Re: Thinking outside the box

Paul Smith <[email protected]> Tue, 19 Mar 2013 17:41:13 +0000
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On 19/03/2013 17:20, Martijn Grooten wrote:
> aving just seen your next post, with further explanations of the 
> scheme, I understand that, essentially, your scheme redefines an email 
> address to be a 2-tuple {email-address,password}. 
Possibly, or possibly three things - recipient email address, sender 
email address, password.

So, I can have a general password which anyone can use, or a personal 
password which only one sender can use to email me, for instance.

Also I can change my password(s), without changing my email address. At 
the moment it's not unknown for people to change their email address 
when it receives too much spam. With the scheme I suggest, you wouldn't 
need to do that, just change the password. (Whether that would be any 
easier than changing your email address may be debatable, but at least 
it's prettier :-) )

> I think that almost all problems we have now with email-addresses 
> receiving spam apply to your 2-tuples receiving spam. 
For someone to send spam to me, they'd have to get a suitable password.

They could do this via compromised accounts, hacking a server with my 
details on or by tricking me into telling them my password. But, I can 
change the appropriate password then, to cut them off. At the moment 
once they have my email address, they have it forever. The only option 
is to put up with it, have more aggressive filtering, or change my email 
address. This would change with a password system.

Most of the spam I receive currently is to harvested addresses (I still 
receive lots of spam to an obscure address I last used on Usenet about 
15 years ago, and from 'invisible' email addresses I've planted on 
websites), or to made up addresses. These would all be stopped by a 
'password' scheme.

> second password. (I've ignored implementation details. The exercise 
> was to "think outside the box" and to rebuild email and/or anti-spam 
> from scratch. In that context, I think it's fine not to worry about 
> these.)
Thank you that someone has remembered that...

(I'm aware that this wouldn't work easily or well as a bolt-on to the 
current system, but if everyone expected to have to get two bits of info 
to send a message to someone, then I'm not convinced it's that unworkable).

-

Paul Smith Computer Services
Tel: 01484 855800
Vat No: GB 685 6987 53