Re: Water tight opt-in (yet another FUSSP)

Alessandro Vesely <[email protected]> Sat, 04 Jan 2014 13:18:46 +0100
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
Hi Neil,

On Fri 03/Jan/2014 15:42:33 +0100 Neil Schwartzman wrote:
> On Jan 1, 2014, at 6:19 AM, Alessandro Vesely <[email protected]> wrote:
>> On Tue 31/Dec/2013 19:34:35 +0100 Neil Schwartzman wrote:
>>> 
>>> I’d like to ask you a fundamental question - what problem are you trying
>>> to solve?
>> 
>> I'm not sure how to call it, "legitimate spam"?  I mean bulk mail, sent
>> using true names, possibly authenticated, sometimes wanted.  For
>> example, most web sites require some kind of subscription in order to
>> post any content (because of web-spam) they may use OpenID, COI, or
>> whatever, and collect posters' addresses.  Those addresses are treated
>> with varying degrees of conscientiousness by different operators.  
> 
> their systems, their rules. having a verifiable permission token
> will not make a jot of difference to any of the big receivers, and
> I doubt any of the smaller ones either.

Yes.  No, receivers don't use verifiable permission tokens, they issue
them.  Receivers get list identifiers in return.  Recipients say how
much a list is "wanted" at subscription time.  A list identifier
paired with email authentication can help setting a message score.

At that point, users have three options with unwanted list mail
destined to a disposable address:

1.  They can unsubscribe or adjust their preferences at the list's
    site.

2.  They can signal list messages as spam.  This may result in a spam
    report that the list manager can use to tune the list's volume.

3.  They can alter the list's "wantedness".  This includes disposing
    of the address for good.

> I can have confirmed opt-in and still spam a recipient. those ‘gift
> cards do it all the time. 'Click here to obtain a $25 Best Buy
> Card’ is usually followed by ‘confirm your email address and mobile
> phone number, so we can provide offers from our partners’. which is
> usually followed with a metric ton of spam (and I use that word
> advisedly).

That illustrates the problem well.  And COI is relatively uncommon
among those bands.

> I can have confirmed opt-in and diverge from the stated intent of
> my list, say, cars, now carrying content about every type of car
> accessory, because I thought recipients might find that
> interesting. I can have confirmed opt-in, and never mention the
> frequency with which mailings will take place, then begin sending,
> on the hour. That’s spam, too.

It is common practice to segment a list into various sublists.  It may
be acceptable if all of the sublists are declared at subscription
time.  Otherwise it is poor list management, which forces users to go
for option 3 above.

>> The problem is to allow people to keep control of their mailboxes
>> without limiting their ability to subscribe at will.
>> 
>> Does that answer your question?
> 
> not really, no. what is the problem with subscribing at will? I do
> it all the time.
> 
> Functional unsubscribe is a provision of numerous laws.  I may have
> confirmed opt-in, but when a recipient says ‘stop’ I am legally
> bound to do so; COI doesn’t trump ‘unsubscribe’
> 
> So, unless I’m missing something here, I don’t see the problem, let
> alone clearly understand the solution.

I think Dave depicted the problem well.  For the solution, perhaps I
could put it this way:  Now that address harvesting is somewhat
démodé, we may consider instructing users to never type their true
email address into a web form.  (If average users were able to paste,
there wouldn't be so many web forms asking to type the address twice.)

Legitimate spammers tend to consider disposable addresses as a kind of
fraud.  Let me quote this:

   TowerData has done extensive research and data collection on spam
   traps, frequent complainers, honeypots, bots, and disposable
   emails to help you maintain a worry free and clean email list.
      http://www.towerdata.com/email-validation/email-list-cleaning/

The rough idea is to offer some functionality (verifiable permission
tokens, spam reports, and the like) such that honest spammers can
accept, or even prefer to cooperate with mailbox providers, rather
than oppose to them.  Of course, if a mailbox provider offers too
much, its clients will quickly migrate elsewhere; but if it offers too
little, spammers won't take it.  So the question is what the right
balance is, and how it can be implemented in a tunable, yet simple way.

Thank you for your patience
Ale
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org