Re: How is it a solution to spam?

Jonathan de Boyne Pollard <[email protected]> Thu, 03 Jun 2004 00:58:54 +0100
Newsgroups gmane.mail.im2000
Organization Wack's Wicks Works
Message-ID <[email protected]>
S> the spammers now send 200.000.000 notifications  500 bytes each,

... which (by design) don't contain any of the information that 
the UBM senders actually want to convey.

<URL:http://homepages.tesco.net./~J.deBoynePollard/Proposals/IM2000/design.html#NoTrivialCovertChannels>

S> Each domain is used for a few hours for sending, 
S> making RBL very hard to do.

In order for the messages to be "sent" to the intended recipients, 
the message stores have to be locatable, by the recipients using the
particular domain name used in the notification, and contactable, at 
a time determined by the recipients.  The notion that the message 
stores will appear and disappear at several domain names in rotation
is thus a fantasy.   It simply wouldn't work as an effective UBM 
sending scheme, since recipients wouldn't be able to fetch and thus 
read the UBM messages.  Message stores have pretty much the same 
stability and reliability requirements as content HTTP servers.

And, of course, the "RBL" equivalent is applied to notifications.

<URL:http://homepages.tesco.net./~J.deBoynePollard/Proposals/IM2000/Architecture/recipient-notification-agent.html#NotificationProcessing>

S> After the notification hit the users inbox, you can't do much.

You are falsely conflating notifications and messages.  You are 
also confused about where the "Inbox" actually *is* in an IM2000 
system.

<URL:http://homepages.tesco.net./~J.deBoynePollard/Proposals/IM2000/differences-from-smtp.html#SenderStoresInbox>

S> So, we have just amplified our spam problem 20 times [...]

Wrong.  Your argument does not support this conclusion at all.

S> after the notification is received by the client, the damage is done. 

Wrong.  As I said, you are falsely conflating notifications and 
messages.

S> I think it makes sending mass emails more efficient, [...]

... which is, of course, a good thing.  "bulk", by itself, is not a
sufficient criterion, remember.

<URL:http://homepages.tesco.net./~J.deBoynePollard/Proposals/IM2000/design.html#SendingIsCheap>

S> you keep a single copy on your machine, those who are interested 
S> come and download it.

... which is, of course, also a good thing.  The (obvious) converse 
is that those who are _not_ interested do _not_ come and download the
message, remember.

S> Now you can [...] see what type of subject lines make them open 
S> the message. 

No, one cannot.  Notifications do not contain subject information.

S> Is your victim a man or a woman, a child or a grown-up? 
S> Spammers heaven !  This is all a little to scary.

No.  It's actually little more than the classic fear, uncertainty,
and doubt, as a matter of fact, which could be dispelled with a little
thought.  None of that information is in fact directly obtainable.  
The fact that <[email protected]> responded to a notification by choosing 
to retrieve a message from one's message store, tells one nothing 
about the age or sex of the owner of that recipient mailbox name.