Re: CAPTCHA over smtp (yet another spam solution to discuss)

"David Sanchez" <[email protected]> Wed, 15 Nov 2006 15:17:57 +0100
Newsgroups gmane.mail.im2000
Message-ID <[email protected]>
> [i18n of challenges in C/R-enabled email protocol]
> >At least is something to take account.
>
> Yes.  However:  How many properly-internationalized bounces of
> traditional messages have you ever received?

Yep, will make it good this time, no?

> [Output queues as an essential feature of email]
> >Reliability is something I love in e-mail.
> >
> >I'm very happy with how it is working now.
>
> You never ever had an email lost?  Or (maybe worse) people calling you
> up immediately after sending you something, and they go, "did you get my
> mail?"  And you have never had a hammy message identified as spam?

Yep, not too many times, but this happens.

Mail lost within my MTA ? Nope, not a single one in 5 years using qmail.

Mail lost in another MTA? yep, certainly, but is something you could not control

On the other hand MUA option of Read confirmation works fine.

> >On the other hand, queues is not the trickiest part of the whole e-mail
> >system for a user.
> >
> >BTW, the common user tend to be realy ashtonished in how easy is to
> >forge e-mail adresses.
>
> Which brings us back to the need for repudiable signatures.  Which
> brings us back to the need for a C/R system underneath the user-visible
> exchange of messages.  (And as an aside, it also brings us back to how
> email is different from snail mail and shouldn't be designed to work
> like it.)

I just stated e-mail was designed to behave like snail mail, i don't
think this is a good thing.

Repudiable signatures? seems interesting. But I think this is not what
the original mail talked about.


> >Your definition of spam is as valid as mine, just because is by
> >definition a subjetive matter.
>
> So, there is an objective definition that says it's subjective?  Which
> is the objective definition?

In a subjetive matter there's no objetive definition.

> >What is unsolicited and what is bulk (3 unsolicited mails in spanish
> >law is bulk and BTW and a crime).
> >
> >>Oh, your definition (from mw) involves "bulk."  You said your example
> >>was spam by definition.  Notwithstanding whether it's criminal or not,
> >>how is it "bulk"?
> >
> >3 :-P
>
> What, you can blackmail me twice, and the third message makes it bulk
> and therefore spam?
>
> >>>>>Moreover the idea of paying for sending is against current Internet
> >>>>>philosophy.
> [...]
> >This is an obvious claim.
> >
> >How many times you are required to pay to see a webpage,
>
> Often times.  Think subscriptions to academic journals.

I know this is possible, but this is not the common practice, and
that's what i said "current philosophy" doesn't mean all the Internet
services, all over the world, for anything.

However, paying services in Internet, you should agree, is marginal
compared to the amount of non-paying services in Internet.

> >send a e-mail or send an IM to a pal?
>
> The proposal does not at all go as far as that.  Pledging money is
> different from spending money.  Think of it as a security deposit.  If
> you do screw things up, you can be held accountable.  If you don't, you
> just move on.

Sorry, i get lost... a security deposit?

How do you try to implement this C/R with paying services?

Sorry, I'm losing something...

> >>>>>I will just quit using, developing or maintaining a service in that
> >>>>>paying is a MUST. Simple as that.
> [That decreases your chances of approaching new acquantainces via
> email.]
> >Nope, i'll pay a reasonable amount for what i consider is worth it.
> >
> >I love the good things of current e-mail, I just don't want to lose the
> >good things.
>
> Amongst which is the possibility for advertisers to pay an ISP to let
> them bypass their anti-spam filters.  I would much prefer to see the
> individual recipient, the victim, to cash in on spam.

Fortunately, this is likely to be illegal in this country :-)

> >Bulk is 3.
> >
> >This is what the law says in spain :-D
>
> Irrespective of what makes the law of the land particularly reasonable:
> You would never throw a party and invite more than two people?

They really want to receive my e-mails.

My parties are great.

> >> >e-mail was designed pretty much like snail-mail
> >>
> >>And that's a shortcoming.  With snail mail, you need letterboxes, and
> >>a mailperson must come, either to you or to the letterbox, and they
> >>must pick stuff up, etc.
> >
> >This is what an MTA do :-)
>
> The fact that the design was implemented doesn't make the design any
> better.

It worked for more than 25 years now with some problems.

Being pragmatic, mail works great, with some problems we are working to resolve.

It's just an opinion, everybody has one :-P

> >>On the Internet, unless we're talking yesteryear's UUCP connections, you
> >>can approach anyone instantly.
> >
> >This is, from my point of view, not necesarily true.
>
> Example?

When i send you an e-mail, you can be off-line :-)

> >E-Mail must be extremely reliable, not necesarily instantaneous.
>
> How is email reliable if everybody doesn't use advanced MTA software?
> Regarding the instantaneousity, there is a fine line.  Messages need not
> appear on the recipient's screen instantaneously.  But the recipient (or
> an agent on their behalf) should assume responsibility for delivery of
> messages fast.

The recipient?, IMHO is the sender who is responsible of its own piece of mail.

> [Bounces]
> >I want to receive notification of an e-mail bounce. Not the whole e-mail.
>
> How do you (reliably, right?) identify the original message?  Would you
> also like to receive delivery notification messages?

I look to the bounce mail and it's fairly easy to me to know from
Subject and first lines.

I don't get your question, maybe.

> [IM2000 prevents zombies from spamming]
> >>Greylisting already achieves that.
> >
> >Nope, if the "spam worm" is intelligent enought to resend the mail
> >(just like an MTA do) (hey, they can implement a queue :-P ).
>
> If the spam worm is intelligent enough, they can send both the
> notification and the actual spam message from the zombie machine.
> Conceptually, greylisting /is/ IM2000, with two disadvantages:  Senders
> wait busily, and usually, recipients (users) have little control over
> the time window during which their inboxes are opened for messages from
> new addresses.

AFAIK greylisting is just a delay in the sending of unknown pieces of mail.

http://en.wikipedia.org/wiki/Greylisting

Maybe this will be circunvented for spammers in the next few months
(not likely, because not too much servers use greylisting and spammers
are getting enough profit yet).

This has little to do with being the sender who stores the mail.

If you are trying to say that an spammer can use IM2000 like any other
mail user, that's true, but with many more costs for the spammer.

> >Change "Spam is unavoidable" with "Unsolicited bulk mail, with current
> >email infraestructure and behaviour is unavoidable"
>
> That's the point of changing the infrastructure, right?
>

Right. But this started with a little change to SMTP and ended with a
complete rework of the e-mail system.

An open question: How could you avoid "ipv6 effect" in all this stuff?

(being "ipv6 effect" the transition problem it is suffering)


> --Joachim
>