Re: CAPTCHA over smtp (yet another spam solution to discuss)
Joachim Kupke <[email protected]> Tue, 14 Nov 2006 16:24:39 -0800
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Message-ID | <[email protected]> |
Brian Candler wrote: [i18n of captchas] >That's a minor issue. Presumably the people you're E-mailing talk both >Chinese and English; they will therefore configure their Captcha system >to issue challenges in both Chinese and English (or to let the user >choose, like HTTP language negotiation). If you do not share a common >language then there's little point in establishing communications >anyway :-) My point exactly. >> Plus, these folks didn't whitelist you to begin with? > >The point about whitelists is more important. There is an unstated >assumption here that there is a robust whitelist system behind this, >which IMO means better authentication of messages than the claimed MAIL >FROM:<> or From: headers. Otherwise, spammers will just send mails with >the MAIL FROM:<> of your friends, which often isn't hard to guess. >(Consider that your "friends" may include PayPal, Amazon, Ebay etc) Repudiable signatures. Another application of C/R email. >Anyway, I think the bigger issue with Captchas is whether they can >scale. I think they can. A spammer could pay, say, 0.1c-1c in real cash >per Captcha solved. There are plenty of poor people in the world who >would happily do this. With a bit of practice they would be up to a >couple of thousand per hour, and so earning $2-$20 per hour cash. However, those poor people would have been served better if they earned that kind of money doing some useful work. The idea of keeping millions of people busy solving captchas doesn't bode well with the philosophy of efficiency. >Now, that's still a lot more than spammers currently pay for sending >E-mail. A bigger problem is that captchas can be broken. Then don't break them. A captcha that no longer "tells computers and humans apart," by definition, is not a captcha. --Joachim