Re: limitations of reputation, was Spam sent from compromised

Barry Shein <[email protected]> Sun, 24 Mar 2013 14:00:39 -0400
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On March 23, 2013 at 20:23 [email protected] (Martijn Grooten) wrote:
 > > For example, if you send too many (I have no idea what "too many" is
 > > exactly) msgs or statuses on Facebook they pop-up a captcha to
 > > continue. It's happened to me, doesn't take much to set that off and
 > > it's not overly burdensome.
 > 
 > This may well work for ISPs and webmail providers. (I'm looking at you,
 > Yahoo!)

Which accounts for what percentage of spam sources? In particular,
botnet population?

My guess is: almost all of it.

Based on not much.

But if I'm right...

 > For this to be used Internet-wide, you get something like hashcash, the
 > Wikipedia page on which is pretty good:

...that probably isn't very important, tho nothing wrong with it.

But I thought the problem always was that with millions of botted PCs
why would spammers care a lot about a work scheme like hashcash?

 > http://en.wikipedia.org/wiki/Hashcash
 > 
 > It also links to a rather good research paper which goes some way
 > towards showing why it might not work:
 > 
 > http://www.hashcash.org/papers/proof-work.pdf
 > 
 > I think that paper it's a good example of doing research on something
 > that would require a significant change to the email infrastructure. You
 > could use similar methods to prove that your idea would work.

The paper mentions what I did about botnets, and several other
interesting points.

-- 
        -Barry Shein

The World              | [email protected]           | http://www.TheWorld.com
Purveyors to the Trade | Voice: 800-THE-WRLD        | Dial-Up: US, PR, Canada
Software Tool & Die    | Public Access Internet     | SINCE 1989     *oo*
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org