Re: limitations of reputation, was Spam sent from compromised

Barry Shein <[email protected]> Sat, 23 Mar 2013 13:38:20 -0400
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On March 23, 2013 at 04:52 [email protected] (John Levine) wrote:
 > 
 > 1.  The introduction problem: what do you do when you see an identity
 > you haven't seen before?
 > 
 > 2.  Identity theft: when a botnet sends spam from Grandma's computer,
 > it sends it with Grandma's identity.

I don't wholly accept this idea that because something isn't perfect
that therefore it's completely useless.

I think we've already determined we can't come up with any perfect
solution to spam, or haven't yet.

So at best we can measure various approaches, try to analyze the
cost-benefit, and try to decide whether something is a worthwhile
weapon in the arsenal.

Specifically:

1. When you see an id you haven't seen before then at least you know
"hmm, this is an id I have seen before!"

That's useful. What you do with that information is your business to a
great extent.

But one could also do that by just having software which can remember
which addresses I think are ok maybe because I hit some key while
reading an email, "remember this sender as ok".

It doesn't have to rise to the level of whitelisting, but even just
showing them in different colors on a summary index of email could be
useful, or sorting on them.

But it would help if I had some confidence in that identity whether
I've seen it before or not. Right now I get email from myself all day
much of which is spam. How's that for a degenerate case?

2. All bets are off with botnets, particularly if one's only recipient
defense is confirming the identity of the sender.

That problem needs to be mitigated at its root cause.

But one could imagine approaches which mitigate even that, such as if
I had to enter some passphrase to send email at all, or more than some
amount, particularly if I hadn't entered the passphrase in some amount
of time. Maybe that's not acceptable to some but that doesn't
necessarily invalidate the idea. Obviously it couldn't be a simple,
static passphrase that a virus could just grab and use.

Or just reporting to users what email they've sent since the last time
their screen saver suspended or similar.

I'd imagine a pop-up which says "you've sent 3,065 email msgs while
the screen saver was running -- does that seem right to you?" could be
helpful, particularly if it offered some useful course of action to
clicking "no, that does not seem right".

Of course a bot virus could attack that reporting also, as I said, all
bets are off if you're pwned.

For example, if you send too many (I have no idea what "too many" is
exactly) msgs or statuses on Facebook they pop-up a captcha to
continue. It's happened to me, doesn't take much to set that off and
it's not overly burdensome.

-- 
        -Barry Shein

The World              | [email protected]           | http://www.TheWorld.com
Purveyors to the Trade | Voice: 800-THE-WRLD        | Dial-Up: US, PR, Canada
Software Tool & Die    | Public Access Internet     | SINCE 1989     *oo*
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org