Re: Water tight opt-in (yet another FUSSP)

Alessandro Vesely <[email protected]> Fri, 03 Jan 2014 12:28:35 +0100
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
Hi,

On Wed 01/Jan/2014 21:28:11 +0100 Martijn Grooten wrote:
> On Wed, Jan 01, 2014 at 12:19:12PM +0100, Alessandro Vesely wrote:
>> I'm not sure how to call it, "legitimate spam"?  I mean bulk mail, sent
>> using true names, possibly authenticated, sometimes wanted.
> 
> Do you have any reason to assume that there is a strong correlation
> between 'wanted' and 'having given verifiable permission'?
> 
> For this supposed FUSSP assumes that there is. I doubt that this is
> the case.

The FUSSP does not assume all messages are wanted.  Check out
TrashMail.net:  They usually set short-lasting permissions, both as
the number of incoming messages allowed as well as the physical time
allotted.

Let me clarify that the TrashMail add-on is _very_ convenient and
hardly beatable.  Its only shortcoming is that legitimate spammers may
perceive it as repressive, since it returns a surrogate address and
precludes any cooperation.  That said, I don't think spammers will
rush for the required web-form upgrades, if cooperation is opened up.
 Yet, opening that possibility will further weaken excuses like "we
cannot do COI because users are advised to never click on links
received by email".

> I agree that making the right decision on these kinds of emails is
> perhaps the biggest challenge for spam filters (though not
> necessarily the most important one). But I am not convinced that this
> proposal would do a better job at this than what spam filters do now,
> which is make an educated guess based on the reputation of the
> sender, the content of the email and, sometimes, the preferences and
> behaviour of the recipient.

Bayesian guessing is mumbo jumbo compared to algorithms that know what
they do, or maybe that's me.

> Apart from this there are also, as has been mentioned, practical
> issues. As well as issues to do with privacy and data protection.

Yes.  Suggestions and workarounds are welcome :-)  In particular, on
how to integrate the add-on's JavaScript with a webfinger-like thing.

For privacy, however, the issue cuts both ways.  A sender who agrees
to cooperatively accept obscure, tagged addresses is waiving its
ability to enhance customer profiling by exchanging data with other
operators, which is based on email addresses comparison.  OTOH, the
changes implied by letting your mailbox provider manage your
subscriptions are rather formal than actual, if you consider ISPs can
sniff COI messages anyway.

> And, perhaps most importantly, the fact that giving certain senders
> direct access to many people's inboxes introduces a dangerous single
> point of failure that those with malicious intentions will be all to
> eager to try to exploit.

I don't think I got that.  D'you mean "direct access" as an
alternative to letting some social network notify for them?

Ale
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org