Re: limitations of reputation, was Spam sent from compromised
Barry Shein <[email protected]> Sat, 23 Mar 2013 13:38:20 -0400
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On March 23, 2013 at 04:52 [email protected] (John Levine) wrote: > > 1. The introduction problem: what do you do when you see an identity > you haven't seen before? > > 2. Identity theft: when a botnet sends spam from Grandma's computer, > it sends it with Grandma's identity. I don't wholly accept this idea that because something isn't perfect that therefore it's completely useless. I think we've already determined we can't come up with any perfect solution to spam, or haven't yet. So at best we can measure various approaches, try to analyze the cost-benefit, and try to decide whether something is a worthwhile weapon in the arsenal. Specifically: 1. When you see an id you haven't seen before then at least you know "hmm, this is an id I have seen before!" That's useful. What you do with that information is your business to a great extent. But one could also do that by just having software which can remember which addresses I think are ok maybe because I hit some key while reading an email, "remember this sender as ok". It doesn't have to rise to the level of whitelisting, but even just showing them in different colors on a summary index of email could be useful, or sorting on them. But it would help if I had some confidence in that identity whether I've seen it before or not. Right now I get email from myself all day much of which is spam. How's that for a degenerate case? 2. All bets are off with botnets, particularly if one's only recipient defense is confirming the identity of the sender. That problem needs to be mitigated at its root cause. But one could imagine approaches which mitigate even that, such as if I had to enter some passphrase to send email at all, or more than some amount, particularly if I hadn't entered the passphrase in some amount of time. Maybe that's not acceptable to some but that doesn't necessarily invalidate the idea. Obviously it couldn't be a simple, static passphrase that a virus could just grab and use. Or just reporting to users what email they've sent since the last time their screen saver suspended or similar. I'd imagine a pop-up which says "you've sent 3,065 email msgs while the screen saver was running -- does that seem right to you?" could be helpful, particularly if it offered some useful course of action to clicking "no, that does not seem right". Of course a bot virus could attack that reporting also, as I said, all bets are off if you're pwned. For example, if you send too many (I have no idea what "too many" is exactly) msgs or statuses on Facebook they pop-up a captcha to continue. It's happened to me, doesn't take much to set that off and it's not overly burdensome. -- -Barry Shein The World | [email protected] | http://www.TheWorld.com Purveyors to the Trade | Voice: 800-THE-WRLD | Dial-Up: US, PR, Canada Software Tool & Die | Public Access Internet | SINCE 1989 *oo* - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org