Re: limitations of reputation, was Spam sent from compromised

Barry Shein <[email protected]> Sat, 23 Mar 2013 13:51:12 -0400
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On March 23, 2013 at 13:38 [email protected] (Barry Shein) wrote:
 > 
 > 1. When you see an id you haven't seen before then at least you know
 > "hmm, this is an id I have seen before!"

I hope the typo is obvious, "I HAVEN'T seen before".

But it raises another research issue:

How good is good enough?

Is there any way to suggest a threshold a spam-fighting technique
should reach before we as a group (?) would issue a seal of approval?

That threshold has multiple dimensions:

1. Types of spam etc it might stop
2. How much it might stop
3. Reliability
4. Integrity (e.g., can viruses overcome it?)
5. Likelihood of adoption by target audience (ISPs, end-users)
6. Cost-benefit
7. Approx time to adoption, reasons for resistance.

Obviously one can't (easily) put absolute numbers on such criteria but
we might be able to at least roughly partial-order them, this
technique is likely more effective on #N than that technique.

How would we order current popular techniques such as SPF, DKIM,
Spamassassin, C/R, whitelisting, etc on these criteria?

Is a composite number useful?


-- 
        -Barry Shein

The World              | [email protected]           | http://www.TheWorld.com
Purveyors to the Trade | Voice: 800-THE-WRLD        | Dial-Up: US, PR, Canada
Software Tool & Die    | Public Access Internet     | SINCE 1989     *oo*
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org