Re: CAPTCHA over smtp (yet another spam solution to discuss)

Joachim Kupke <[email protected]> Wed, 15 Nov 2006 15:58:57 -0800
Newsgroups gmane.mail.im2000
Message-ID <[email protected]>
Brian Candler wrote:

>> Repudiable signatures.  Another application of C/R email.
>
>I'm not sure, but I think you mean "non-repudiable signatures".

No; "repudiable" is correct.  The verifier sends a challenge, and 
computing a valid reponse requires the private key.  But the prover can 
repudiate ever having "signed" (in the offline sense) because it is 
trivial to manufacture, given any response, a corresponding challenge.

[Solving captchas in the large is a waste of humankind's time.]
>Absolutely. But spammers are not particularly known for their high 
>levels of ethics, nor their consideration for efficient use of 
>resources.

This has nothing to do with spammers.  Legitimate senders waste their 
time.  Illegitimate senders might spend time to make messages "go 
through," but recipients never get compensated.

>Indeed, the current situation is probably better; people can have their 
>spam filters reasonably well self-tailored and updated over time (using 
>Bayesian learning for example), whilst the effort required to set up 
>your own custom captchas and keep upgrading them is quite significant.

That's how money is superior:  The only maintenance effort required 
would be to adjust for inflation. :-P


--Joachim