Re: skilled crooks, Water tight opt-in (yet another FUSSP)
Alessandro Vesely <[email protected]> Mon, 13 Jan 2014 16:06:27 +0100
| Newsgroups | gmane.ietf.asrg |
|---|---|
| Message-ID | <[email protected]> |
On Sun 12/Jan/2014 03:47:20 +0100 Chris Lewis wrote: > On 01/11/2014 09:05 PM, John Levine wrote: > >> I recall Laura reporting on a bunch of forged subscriptions done >> so well that the only reason she was sure it was dirty is that >> one of the subscription addresses they forged was hers. > > The reality is that it's trivially forgeable. So are signatures, credit > cards and driver's licenses. > > But we muddle along anyway. Yes, that is necessary. /Requiring/ unforgeable proofs of consent would hamper well-established practices. That doesn't mean unforgeable proofs should be rejected. > In other words, it doesn't have to be/shouldn't be the only evidence > you're relying on. On a case-by-case basis, there will usually be other > information that will help you prove that a batch of subscriptions are > good or bad. > > I caught Richter touting subscription addresses of 192.168.0.0/16. > Others touting IP addresses in the wrong continent. Others touting COI > registrations from 15 years after the domain went defunct. Or just the > one time where the person involved said "no I didn't". > > Throw doubt on a handful and they all become suspect. Not sure. As long as unscrupulous marketers are able to append an email address to a web visit (possibly deploying some questionable software), they can simulate a plausible subscription. They can use complaint rates to keep beneath the radar. It seems OptGuard would certify such registrations without turning a hair. I agree credit cards are similarly flawed. However, client-side banks do register history so that users can check the details of recent transactions. Because people are picky about their money. Signatures (both digital and hand made) and digital driver's licenses work better. > Large scale spammers will garner a lot of complaints. Some of them will > almost certainly destroy the credibility of supposed registration data > for the rest. > > I'm with Neil, I don't think forged subscriptions scale very well. Right. The point is just that that design is one-sided. A better method can be introduced gradually, alongside of the existing one. Ale - This is the asrg mailing list. To change your subscription settings, see http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org