Re: The introduction problem, was Thinking outside the box

Martijn Grooten <[email protected]> Wed, 20 Mar 2013 13:55:27 +0000
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
> These are not what I would call 'random people'.

No. But as Ian patiently explained, it is very hard to distinguish between random people, who only want to email you to send spam, and those non-random people that you've never heard of yet you still want to receive email from. If you can't come up with a solution for that, you haven't solved the introduction problem.

> But, I can change the key

or change your email address

> , I can set different keys for different people

or use different email addresses for different people

>, I can provide a regularly changing key on a website and then when I get a contact I
> 'want' I can send them a more permanent key (in an automated way, so
> human effort is minimal)

or use a regularly-changing email address for public use and only give out your private email address (in an automated way) if you get a contact you 'want'.

> A person could easily parse:  "my email address is [email protected], the
> email key to use is '82515621'", but a spammer's website scraper will have a
> lot more effort to understand this than to simply identify an email address
> (which has a nice unusual character right there, to make it easy to find).

Many people publish their email addresses on websites in ways that effectively can't be scraped. (Usually because the way they do it is unique enough.) Other people don't publish their address at all, but simply use a contact form. Many people don't ever publish their email address on a website, ever.

Guess what: they still get spam. Probably because someone who had this email address in their mailbox/contacts was logged in to a machine infected with malware that searched for such addresses. If everyone used address/key combinations, malware would be written to scrape for such combinations.

So your proposal doesn't solve anything.

> I can change the key on websites regularly if I wish. In my experience
> spammers harvest addresses from websites very infrequently (there are lots
> of web pages to look at on the Internet). If I change the key monthly, and
> accept the last 3 months' keys, spammers will have to put a lot more effort in
> to harvest the address details much more regularly than they currently do.

There are limited cases where temporary email addresses may be very useful. But most people wouldn't want to ignore email addresses they gave out in the past.

(If I wanted to contact Ian about his council work, or John to give him some work, I may look at their websites for their address. I may just as likely get their email address from a friend who had sent them something last year.)

> I could give a different key on business cards, which may last forever,
> because it is highly unlikely that I'll give a spammer a business card. etc.

No, but the person who may have entered your address to their address book, may find their machine infected with malware, after which...

> Also, a huge amount of spam which hits our servers is for non-existent
> addresses (which have NEVER existed). OK, these bounce, but it shows that
> spammers often just guess email addresses

Given the weird local-part/domain combinations I've seen, I think it unlikely that it's merely guessing. I suspect a lot of people selling lists of email addresses simply increase the size of these lists by combining one address's local-part with another address's domain.

> , they don't bother harvesting
> them from websites, they just try all the common names and append your
> domain name to them, hoping that some will get through. Even if I put the
> 'key' on my website in big, harvester friendly, letters, all this 'random' spam
> would be stopped dead.

Given that your proposal would require significant changes to the email infrastructure, I think it's fair to say that spammers would adapt too. So "they're not doing it now" is not a good reason to assume they won't change their behaviour.

Btw, these "dictionary attacks", as I think they're commonly called, aren't exactly hard to block, are they?

Martijn.


________________________________

Virus Bulletin Ltd, The Pentagon, Abingdon, OX14 3YP, England.
Company Reg No: 2388295. VAT Reg No: GB 532 5598 33.
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org