Re: CAPTCHA over smtp (yet another spam solution to discuss)

"David Sanchez" <[email protected]> Wed, 15 Nov 2006 02:33:55 +0100
Newsgroups gmane.mail.im2000
Message-ID <[email protected]>
> [i18n of challenges in C/R-enabled email protocol]
> >Maybe I just speak english (not likely :-P ) and that smtp server only
> >chinese (but the intended recipient speaks 5 languages, for instance)
> >this will be a mess.
> >
> >How do you'll deal with that?
>
> I may be repeating myself here, but:  Let the recipient configure how
> their receiving MTA states challenges.
>
> I do acknowledge there may be corner cases where i18n makes things
> messier.  But it's not a showstopper.

At least is something to take account.

 > [Output queues as an essential feature of email]
> >I'm pretty sure i'm not the only one that things this way.
>
> People who do think like you will get their own output queue.  But most
> users are indeed confused by what it does.  And, as has been pointed out
> before, many MUAs implement their own output queue already because mail
> hubs (mail injection servers) may be down.


Reliability is something I love in e-mail.

I'm very happy with how it is working now.

On the other hand, queues is not the trickiest part of the whole
e-mail system for a user.

BTW, the common user tend to be realy ashtonished in how easy is to
forge e-mail adresses.


> >> >Yeah, i'll send you a blackmail (which is spam, by definition)
> >>
> >>Would like to see that definition.  Blackmailing people is most likely
> >>to be criminal, though.
> >
> >Well, bad example, but you can understand it, i think.
> >
> >I won't blackmail you
>
> I believe that one. :-)
> Let's see your definition of spam.  There is no use hypothesizing what
> email might look like unless we can argue, say, mathematically, that
> either of us may be right.

Your definition of spam is as valid as mine, just because is by
definition a subjetive matter.

What is unsolicited and what is bulk (3 unsolicited mails in spanish
law is bulk and BTW and a crime).

> Oh, your definition (from mw) involves "bulk."  You said your example
> was spam by definition.  Notwithstanding whether it's criminal or not,
> how is it "bulk"?

3 :-P

> >>Your definition of spam might go something along the lines of,
> >>anything that doesn't make you happy.  Other people might want, for
> >>good reason, to read messages that don't make them happy.
> >
> >You already know that blur is the frontier from ad-mail and spam.
>
> What are you getting at?  BTW, advertisers often times issue coupons.
> That have cash value.  You, as a recipient, might have configured your
> email such that a sender would need to post a $5 bond to get through to
> you.  They may be an advertiser and they may be sending you $10's worth
> of a coupon.  If you aren't interested, they pay $5 for your attention.
> If you are and use their service, you get a $10 discount.

I haven't receive a single coupon on spam mail :-P

But I understand your point

> That's an instance of avoided spam.  Had your attention been worth more,
> you would have required senders to post more valuable bonds.

Conceptually posible.

> >> >If you want whole internet availability you must deal with spam.
> >> >Simple as that.
> >> >
> >> >Moreover the idea of paying for sending is against current Internet
> >> >philosophy.
> >>
> >>You may want to give evidence for these claims.
> >
> >How can you probe the obvious?
> >
> >Is hard :-)
>
> Ask any mathematician.  Yes, obvious claims are often the hardest to
> prove, and some of them are even false.

But this wasn't.

This is an obvious claim.

How many times you are required to pay to see a webpage, send a e-mail
or send an IM to a pal?

Statistically, is marginal the times you are required to pay.

This is what i meant with "current Internet philosophy"


> >Send me $2 and i'll give you an explanation :-P
>
> Sure thing.  Do you accept checks?  To what kind of address?  (See the
> lack of a protocol?)

Yep, send it to

John Doe
123, Fake Street
31337 Caiman Islands

:-)

> >> >I will just quit using, developing or maintaining a service in that
> >> >paying is a MUST. Simple as that.
> >>
> >>Never sent old-style mail, using postage?  (To regurgitate,
> >>reimbursing recipients for their attention span is NOT postage.)
> >
> >Well, i won't blackmail you (nor anyone), i promise :-D
> >
> >I am just making my point clear
>
> Which is, you are not going to pay for anything.  Well, chances are you
> could still use email, but you could not send to anyone whose time is
> worth, to them, more money than $0.  You could send to people who prefer
> to configure their MTA such that it prompts you to solve puzzles.  If
> you do that too often, though, they might feel inclined to reconfigure
> their MTAs.  :-P

Nope, i'll pay a reasonable amount for what i consider is worth it.

I love the good things of current e-mail, I just don't want to lose
the good things.

> >Pretty fine definition, i've another one
> >
> >Spam = Unsolicited Bulk Mail
>
> Define "unsolicited."  Quantify "bulk."

Unsolicited is, more or less, unwanted.
Bulk is 3.

This is what the law says in spain :-D

>
> >>Again, we are not talking about postage.
> >
> >Why not?
>
> Postage == payment to postal service to have your mail delivered.
> Posted bonds == potentially seizable money to recipient for their
> attention.
>
> >e-mail was designed pretty much like snail-mail
>
> And that's a shortcoming.  With snail mail, you need letterboxes, and a
> mailperson must come, either to you or to the letterbox, and they must
> pick stuff up, etc.

This is what an MTA do :-)

> On the Internet, unless we're talking yesteryear's UUCP connections, you
> can approach anyone instantly.

This is, from my point of view, not necesarily true.

E-Mail must be extremely reliable, not necesarily instantaneous.

BTW, instantaneous is IM (XMPP is about presence and IM and is a well
defined protocol, not necessarily centralized)

> Bounces are a good example:  With snail mail, if you misspelt the
> recipient's address, it was a good idea for you to receive your letter
> back.  After all, it might have contained something valuable to you.
> With email, it's ridiculous.

I want to receive notification of an e-mail bounce. Not the whole e-mail.

> >> >> >The solution of a lot of mail problems should pass adopting the
> >> >> >IM2000 proposal of being the sender who stores the mail.
> >> >>
> >> >>I think this reasoning has already been found to be flawed.  Hell,
> >> >>greylisting would be superior to IM2000 if it weren't for the need for
> >> >>senders' busy-waiting.
> >> >
> >> >Maybe it's true, but spam and other mail problems will be disminished.
> >>
> >>Another claim you may want to give evidence for.
> >
> >IMHO, zombie windows sending spam and such kind of things will be
> >drastically reduced.
>
> Greylisting already achieves that.

Nope, if the "spam worm" is intelligent enought to resend the mail
(just like an MTA do) (hey, they can implement a queue :-P ).

> >I said spam is unavoidable, if you want free (as in freedom) and whole
> >internet available mail. Just that.
>
> Without a definition of spam that we are both comfortable with, any
> statement as to the avoidability of spam is useless.
>

Hell!, we didn't even agree in what e-mail is, :-P

Change "Spam is unavoidable" with "Unsolicited bulk mail, with current
email infraestructure and behaviour is unavoidable"

I understand your position, and seems a good one to me, but assumes
changes in current email behaviour that is unaceptable to me (paying,
optional reliability...)