Re: Water tight opt-in (yet another FUSSP)

Alessandro Vesely <[email protected]> Sat, 11 Jan 2014 19:03:41 +0100
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On Sat 11/Jan/2014 15:23:54 +0100 Neil Schwartzman wrote:
> 
> From what I can parse this proposal involves receivers changing
> infrastructure to fix a problem for which we already have a solution,

Well, that's not really an infrastructural change, it is just a minor
software modification.  I mean, for senders who can accept a non-PII
email address --just an anonymous private channel between them and
their customer, kept under their customer's control rather than theirs.

Whatever is the solution we have, it must leave something to be
desired, given that many people use tagged addresses by hand.

> AND it makes receivers the de facto curators of permission, which may
> have associated legal liabilities. So, more cost, and potential
> exposure with no benefits to our customers? Proposing this would be
> career suicide.
> 
> Allow me to have a long belly laugh.

Far from me the idea to stop you laughing, I believe it's healthy :-)

However, from a user's POV, the tradeoff is to have a single curator
of choice instead of a bunch of senders, some of which are newcomers
and some of which are untrustworthy.  Would users migrate if your
competitors offered this extra feature?

> The sender of email has, as part of their normal operating
> responsibilities and costs, the need to collect and retain permission
> data, mostly for legal purposes (permission doesn’t figure into SMTP
> nor reputational decisions for message disposition).

Permission data collected by a sender on its own can be easily forged.
 I'm always surprised to I hear it bears some legal value.  A
confirmation signed by a recipient-side curator would allow a sender
to accomplish that need in a well-defined way.

> Under Canada’s Anti-spam Legislation, there is a follow-the-money
> régime. Were a receiver to be the holder of permission data, and
> somewhere along the line screwed it up, implementation of this
> scheme may leave them exposed to investigations and administrative
> monetary penalties.

Yes.  The holder of permission data has to be the operator of the MX
pointed to by the tagged address, for this scheme to work.  Part of
that role could be outsourced.

I'm unable to think of any computer-aided tagged-address scheme where
the data is maintained on recipient's storage.  I suspect that those
who use tagged addresses consistently --whom I envy-- use just their
brains.

> I see zero motivating factors to help Senders deal with any problems
> at their end, and many potential negatives. 

It takes two to SMTP.

Ale
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org