Re: How is it a solution to spam?
Steve Dodd <[email protected]> Sun, 30 May 2004 23:35:13 +0100
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Message-ID | <[email protected]> |
On Mon, May 31, 2004 at 12:31:02AM +0300, Stelian wrote: > Each domain is used for a few hours for sending, making RBL very hard to do. > After the notification hit the users inbox, you can't do much. The one big selling point of IM2000 is that the sending machine has to be traceable. For the recipients to be able fetch the mail from it, it has to have a static IP or at least an MX record (or equivalent) The system I'd always envisaged was a democratic blacklist.. if you open a message and it's spam, you click a button which notifies your blacklisting service. Once a critical mass of users have blacklisted the same server, the subscribers' software automatically refuses to fetch from there. You could make it hierarchical, so if the density of spammers in a particular domain or netblock exceeds a certain threshold, the whole thing gets blocked. The damage done by false positives is mitigated, because they'll remain on the sending server and can be resent when the server is removed from the blacklist. Finally, it gives the big webmail providers a much easier way of stopping spam runs while they're still in progress. If they get a dozen complaints about mail from a particular user, they can delete that user's outgoing messages, potentially preventing millions of spams getting out.. The spammers can keep making new accounts, of course, but the sophisticated techniques that now exist for preventing automated account creation should slow them down significantly. The system doesn't have to be 100% perfect, it just has to make life sufficiently difficult for the scum for them to find something else to do with their time.. > At the same time, the bandwidth abuse of the servers remains constant, > because it is limited only by the capacity of the spammers to send > spam, and that remains the same. Rate limit notifications from servers? If you're running a webmail company or corporate mail server, it should be easy to spot anomalous big wodges of notifications. You have to be careful about mailing lists, but you can monitor which servers your users regularly poll, and whitelist them. It requires some degree of software sophistication, but it doesn't seem any more complex than existing anti-spam solutions; I think it could be effective. > Although I like the design of the system, I think it makes sending mass > emails more efficient, because it scales so good. Instead of repeating the > message to each user, not knowing if they read it or not, you keep a single > copy on your machine, and those who are interested come and download it. So then maybe the spammers only spam the users that like spam? Seems like poetic justice to me :) > Goodbye webbugs ! I imagine many client implementations will prefetch messages they have received notifications for, before the user opens their mailbox. So while the fact that a message has been retrieves indicates it's been delivered ok, it doesn't prove it's been read. I can even imagine a system layered over IM2000 by which users can specify that mail notifications for them are forwarded through a 3rd party anonymizing service, so their IP address etc. are not revealed. -- Home+FOAF: http://www.loth.org.uk/ * PGP: 201A57B6 * Original portions © 2004 Steve Dodd * "I'm not falling apart, I'm coming together." * Appreciated this message? - http://www.loth.org.uk/tipjar/ * TINC * "You may be sure, dear Crito, that inaccurate language is not only in itself a mistake: it implants evil in men's souls." -- Plato