Re: CAPTCHA over smtp (yet another spam solution to discuss)

Joachim Kupke <[email protected]> Fri, 17 Nov 2006 18:14:46 -0800
Newsgroups gmane.mail.im2000
Message-ID <[email protected]>
Seth Goodman wrote:

>> My point again:  Make all restrictions configurable, for the 
>> recipient. Where in this case, the recipient is the mailing list.
>
>Then the folks who today want no restrictions will prevent such a 
>system from being used.  They block that currently, and they don't 
>appear to be losing any ground.

To each their own.  You mentioned NNTP.  Some newsgroups are moderated, 
others aren't.  Depending on the circumstances, I might prefer to 
subscribe to one or the other.

>> Why impose a one-size-fits-all pseudo-solution?
>
>I'm not proposing this solution.  They can charge money for posting 
>today with no special infrastructure.  Why are there not many lists 
>operating this way?

How would they charge money?  (Again, bonds are different from charging 
money, of course.)  Would they collect my credit card number?

[Non-repudiability of cryptographic signatures]
>> For an offline system, that's not a strength, it's a core feature.
>
>That's right.  It was a requirement for a digital signature system.

You make it sound as if it were a somewhat important point.  It is the 
whole and only point of offline signatures.

>> In an online system, the sender issues a zero-knowledge proof of 
>> their knowledge of a valid signature.  The recipient does not have 
>> the ability to prove anything to anyone, although they have the 
>> entire transcript of the communication.
>
>If the assertion requires zero knowledge by the sender, then anyone can 
>make it.

Please familiarize yourself with zero-knowledge proofs.  
http://en.wikipedia.org/wiki/Zero-knowledge_proof has the cave story.

>Perhaps the only thing you can assert without requiring knowledge
                                                ^^^^^^^^^
The point is to not disclose it.

[...]
>I have already refused to deal with C/R systems when it annoys me 
>enough, so I don't think it wise to inflict this on others.

I guess you really meant to say you refused to deal with captchas that 
annoyed you.

[Repudiability of authorship is a good thing.]
>That's news to me.  If you don't want someone to trot out something you 
>wrote down, then don't write it down.  When I send someone mail of any 
>kind, I have to assume that it could surface at some later time.  It 
>matters little whether they can prove mathematically that I am the 
>author.

Maybe not mathematically, but legally.

>All that matters is whether others believe I wrote it. If I am not 
>comfortable with the possibility that I will be faced with a written 
>record of my own words, I use the telephone.

While a phone call is usually less formal in style, it would be easier 
to (at least circumstantially) prove that you spoke on that pape than 
that you authored the message I am replying to.


--Joachim