Re: The introduction problem, was Thinking outside the box
Paul Smith <[email protected]> Wed, 20 Mar 2013 12:08:14 +0000
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On 20/03/2013 10:53, Ian Eiloart wrote: > I'm a 48 year old human, I want random people that I've known in the past to be able to email me to catch up. And I want people with connections to my friends and family to be able to make contact with me out of the blue. Do these people just email 'ian.eiloart@<every domain that exists>' hoping to contact you? I doubt it. They have seen or been told your email address. These are not what I would call 'random people'. A 'random person' is someone in Mongolia who has just picked a random set of characters which happen to make my email address and sent me an email asking about the weather in Chile (or offering a method to enlarge bits of my anatomy). All your above examples have been "introduced to you" already, by the fact that they have been provided with your email address by you (or a delegate of you). If they have been provided with your email address they could easily have been given extra information as well. > If I want someone to be able to email me, I currently have to tell them my email address. In my 'brand new email way', I just have to tell them my 'key' as well. I can think up a new notation as well: 'my email address is [email protected]/mailme'. There, that's the key distribution problem sorted :-). > > Er, but you just gave your key to the spammers. You might just as well say your email address is [email protected]. But, I can change the key, I can set different keys for different people, I can provide a regularly changing key on a website and then when I get a contact I 'want' I can send them a more permanent key (in an automated way, so human effort is minimal) (I can't use my email address as the 'secret', because then if you send a message Cc'd to all your contacts wishing them 'Happy Christmas' (as some users are wont to do), you've just given my 'secret' to loads of other people, who could potentially be baddies) A person could easily parse: "my email address is [email protected], the email key to use is '82515621'", but a spammer's website scraper will have a lot more effort to understand this than to simply identify an email address (which has a nice unusual character right there, to make it easy to find). I can change the key on websites regularly if I wish. In my experience spammers harvest addresses from websites very infrequently (there are lots of web pages to look at on the Internet). If I change the key monthly, and accept the last 3 months' keys, spammers will have to put a lot more effort in to harvest the address details much more regularly than they currently do. I could give a different key on business cards, which may last forever, because it is highly unlikely that I'll give a spammer a business card. etc. Also, a huge amount of spam which hits our servers is for non-existent addresses (which have NEVER existed). OK, these bounce, but it shows that spammers often just guess email addresses, they don't bother harvesting them from websites, they just try all the common names and append your domain name to them, hoping that some will get through. Even if I put the 'key' on my website in big, harvester friendly, letters, all this 'random' spam would be stopped dead. Yes, they could do a password attack on the 'key', but will they really try hundreds of thousands of times to get through to each recipient? (and my MTA could protect against that type of attack). If I do want to receive email from people who guess my email address (postmaster@ is an example), then I could just set the key for that recipient to be blank. - Paul Smith Computer Services Tel: 01484 855800 Vat No: GB 685 6987 53