Re: Feedback on Hypertext Mail Protocol (a.k.a. Stub Email)

Nathan Cheng <[email protected]> Wed, 22 Feb 2006 08:14:47 -0800
Newsgroups gmane.mail.im2000
Message-ID <[email protected]>
So then perhaps the only benefit of IM2000 schemes over today's 
situation is that you get to see the Subject/Sender/To of the email 
before retrieving the entire email? If adoption is painless and user 
experience remains pretty much the same, then that's still a 
worthwhile benefit, isn't it? I know that's how I delete from my inbox 
spam that the filter missed--I just look at the To/Subect, check the 
boxes and hit "Delete". With IM2000 at least I won't have retrieved 
the entire contents of those emails.

Also, my proposal for "HTMP with obfuscation" (outlined in comments 
below my article) would dramatically increase bandwith costs for the 
sender, which would really only effect spammers. Is that a worthwhile 
benefit?

Aren't these two benefits alone enough to justify the effort?

Nathan

Brian Candler wrote:

> On Tue, Feb 21, 2006 at 04:11:44PM -0800, Nathan Cheng wrote:
> 
>>There are over 1600 messages on this list over a period of about 5 
>>years, so I was wondering if someone could write about 3 sentences to 
>>fill me in on the current state of IM2000 affairs, as well as what 
>>primary objections to my idea--or ideas such as mine--may have already 
>>been aired on this list.
> 
> 
> The current state is that it's dead :-) Yours is one of a handful of
> messages here over the last several months.
> 
> The name of your project is quite interesting, because arguing the need for
> a new E-mail system tends to end up as "squaring the circle". That is,
> people seem to think that having a verified electronic identity for the
> sender of a mail will result in a reduction in spam; but since new
> electronic identities can be created at whim [1], this can never solve the
> spam problem.
> 
> Spammers will just use whatever new protocol or mechanism is put in place.
> At best you can solve the 'joe job' problem of receiving spurious bounces to
> messages you never sent, but there are far simpler mechanisms for doing this
> which work with SMTP mail today [2]
> 
> That is, unless you want every E-mail sender identity to be certified by an
> agency like Verisign or cacert.org or your national government; or that you
> will always have a prior arrangement with every person with whom you want to
> exchange E-mail, learning their electronic identity out-of-band [3]. When
> pushed down this route, it turns out that people generally don't want to
> lose the ability to receive E-mails from people they've not been formally
> "introduced" to by some other mechanism, nor to have to jump through
> identity verification hoops just to get an E-mail address.
> 
> I wrote an assessment of IM2000 a while back:
> http://pobox.com/~b.candler/doc/misc/im2000.html
> 
> The essence is that while I think "pull" E-mail systems do have benefits
> (which I expect are shared by your own proposal), by themselves they are
> unlikely to reduce spam in the way that has been claimed for IM2000.
> 
> Regards,
> 
> Brian.
> 
> [1] Taking electronic identity as E-mail address (user@domain), then you can
> easily create new ones by:
> 
> - registering a new domain (cheap, easy, and with thousands of registrars
>   to choose from there will always be ones with lax security checks)
> - using a dynamic DNS provider
> - using a freemail service like hotmail.com, netscape.com
> - using a free/pay-as-you-go ISP dialup service, which gives you one or
>   more E-mail accounts
> - taking over someone else's account, e.g. by hacking into the machine where
>   their credentials are stored. By some estimates, around 50% of all
>   Windows machines currently connected to the Internet are infested with
>   viruses or malware.
> 
> Unless you can plug *all* those holes, spammers will have an infinite supply
> of valid E-mail addresses to draw upon.
> 
> If the electronic identity is a public/private key pair, then new key pairs
> can be generated on demand within seconds.
> 
> [2] Examples include BATV and SES. These can be deployed incrementally and
> give immediate benefit to the person performing the deployment; there is no
> need to wait for the rest of the Internet to upgrade themselves as well.
> 
> [3] Such as printing your E-mail address or RSA key fingerprint on a
> business card, and handing it out to everyone you need to E-mail. The other
> party will need to import this into their E-mail client before they can
> receive mail from you. This is essentially "whitelisting" in today's world;
> "pull" E-mail systems can give a stronger check on the claimed identity of a
> received mail, but it's already quite hard for a spammer to guess which
> people are in your whitelist when sending you spam.
>