Re: Feedback on Hypertext Mail Protocol (a.k.a. Stub Email)

James Craig Burley <[email protected]> 22 Feb 2006 18:42:08 -0000
Newsgroups gmane.mail.im2000
Message-ID <[email protected]>
>IM2000 shifts the burden of message storage to the
>sender, but the sender can quite easily delegate this further to other
>unsuspecting victims.

Indeed.

Note that IM2000 (potentially) also shifts the *responsibility* of
message *delivery* to the sender.  I believe that's even more
important than the message-content issue, because a recipient can't
really decide whether to accept responsibility for a message without
having access to the message *content* anyway.

(I say "(potentially)" because I'm not sure whether IM2000 actually
allows a recipient agent to acknowledge receipt of a message
notification without also accepting responsibility for the message
itself -- that is, without "guaranteeing", a la SMTP, that it will
pass that notification along to the recipient.)

Assuming responsibility for message delivery remains with an IM2000
sender until the recipient accepts delivery ("unpinning" the message,
I believe is the term coined for this), regardless of whether the
recipient has retrieved the message contents, IM2000 gives ISPs (not
just end-user recipients) more flexibility with regard to how to
handle message notifications from "suspect" (non-whitelisted,
non-approved) sources, compared to traditional SMTP.

Spammers really don't care about shifting responsibility for message
delivery to anybody else, because they don't have a strong desire (nor
the resources) to assure that each recipient of their message actually
sees it, or to use other means of communication if email fails to
confirm delivery.  That distinguishes them from most senders of
legitimate messages.

(But spammers *do* care about transmitting message *content* to as
many recipients as possible.  Hence, you're right that, in IM2000 as
in SMTP, they'll exploit zombies, if they have to, to serve as
short-term message stores.)

Therefore, any approach that shifts the burden of *responsibility*
from recipients to senders, making it "cheaper" (resource-wise) to be
a typical recipient vs. a typical sender when compared to the present
SMTP-based system, will:

  - Be more likely to be acceptable to legitimate senders, since they
    also tend to be legitimate recipients, so the shift in burden
    won't be a problem for them *overall*

  - Be less likely to be bothered with by spammers, since they don't
    really have much interest in message-delivery responsibility in
    the first place, don't really care to receive legitimate email,
    and depend on sending bazillions of emails frequently

It seems likely, therefore, that shifting the *responsibility* of
message delivery from recipient to sender will tend to expose many
spammers simply because they *won't* demonstrate, to recipients, that
they "care" about messages they send:

  - In SMTP, they won't respond to temporary delivery failures by
    retrying delivery later as maybe > 99% of legitimate email senders
    do.  (Greylisting, which crudely "plays" with responsibility,
    depends on this fact, by temporarily rejecting delivery at least
    once.)

  - In IM2000, they won't repeatedly send message notifications, or
    provide message contents (especially repeatedly for a given
    recipient), over more than a fairly short period of time.  (E.g.
    if they're exploiting zombies as message stores, when shut down, a
    zombie won't be sending any more notifications or serving any more
    content.)

In both cases, spammers simply have too many potential recipients, and
too little interest in delivering their payloads to *all* of them, to
care enough to repeatedly notify and deliver content.  They favor
hit-and-run tactics, which traditional SMTP was *designed* to favor
from the outset (because of the nature of the Internet back in those
days).

And, in both cases, recipient agents can, when their (human)
recipients aren't constantly online and accepting messages immediately
upon receipt of notifications, detect these responsibility-avoiding
behaviors and prioritize/ignore messages accordingly.

Further, with IM2000 and other systems that shift responsibility to
the sender, spamtraps are particularly effective, because:

  - They need never accept responsibility for any message (they are
    therefore just like legitimate users who never log in to read mail
    anymore, and there are probably hundreds of thousands, if not
    millions, of those).

  - They need never reject any message (so they do not advertise their
    existence or nonexistence as spamtraps or real users).

  - Their "recipient agents" can detect responsibility-avoidance
    behavior and "blacklist" corresponding senders in ways that can be
    referenced by the agents for other "real" recipients.  (So they
    can "feed into" blacklists.)

In particular, by using spamtraps, the issue becomes not so much of
whether a *particular* message's sender doesn't seem to demonstrate
much interest in it, but whether that sender (e.g. the IP address)
doesn't demonstrate much interest in any of the *hundreds* or
*thousands* of messages it sends (via IM2000 notifications or SMTP
deliveries) to a variety of addresses, including spamtraps, at a given
domain, over a relatively short time.

Note that none of the above depends on *any* central system, such as
IP blacklists, RBLs, SPF, beyond traditional, simple DNS (for message
*delivery* lookup, and for message retrieval if IM2000 is used).

Instead, local-LAN-based versions of such systems, which recipient
agents on the same LAN can use and/or notify regarding spammers, would
likely be employed, thus distributing the burden of identifying
spammers more evenly throughout the Internet (giving spammers fewer
"fat targets" to dDOS), which has positive implications for
reliability (fewer points of failure), security, etc.

-- 
James Craig Burley
Software Craftsperson
<http://www.jcb-sc.com>