RE: CAPTCHA over smtp (yet another spam solution to discuss)

"Seth Goodman" <[email protected]> Sat, 18 Nov 2006 01:50:55 -0600
Newsgroups gmane.mail.im2000
Message-ID <[email protected]>
Joachim <> wrote on  -0500:

> > I'm not proposing this solution.  They can charge money for posting
> > today with no special infrastructure.  Why are there not many lists
> > operating this way?
>
> How would they charge money?  (Again, bonds are different from
> charging money, of course.)  Would they collect my credit card number?

I think you can do this today without disclosing much private
information.  Perhaps make a PayPal (or similar) deposit into an escrow
account controlled by the list owner.  You disclose your email address
but not your Bank Account or Credit Card number.  I'm not claiming it's
actually good.  PayPal is expensive for small transactions.  If someone
pays with a stolen credit card number that is not reported for a while,
the deposit can be reversed later.

To do what you suggest on a larger scale, you'd need a micropayment
system that also does not permit charge backs.  I have no idea if that
is even legal in most places (you can't keep stolen property, even if
someone gave it to you to pay a valid debt).


> > If the assertion requires zero knowledge by the sender, then anyone
> > can make it.
>
> Please familiarize yourself with zero-knowledge proofs.
> http://en.wikipedia.org/wiki/Zero-knowledge_proof has the cave story.
>
> > Perhaps the only thing you can assert without requiring knowledge
>                                                 ^^^^^^^^^
> The point is to not disclose it.

I do see the distinction:  disclosing zero knowledge during the identity
assertion (TLS session) versus requiring literacy but no specific
knowledge (captcha).  I don't care if my browser negotiates a SSL
connection every time it views a web site.  However, I would tire
quickly of processing a captcha for every email address to which I
directly send a message.


> > I have already refused to deal with C/R systems when it annoys me
> > enough, so I don't think it wise to inflict this on others.
>
> I guess you really meant to say you refused to deal with captchas that
> annoyed you.

I actually meant what I first said.  C/R email systems require my direct
participation.  Protocols involving cryptographic challenges require
only my computer resources and not my time.  I don't mind captchas for
web forms, since I don't use them very often.  If I had to use captchas
for sending common emails, I would personally find that annoying and
would try to avoid it.


> [Repudiability of authorship is a good thing.]
> > That's news to me.  If you don't want someone to trot out something
> > you wrote down, then don't write it down.  When I send someone mail
> > of any kind, I have to assume that it could surface at some later
> > time.  It matters little whether they can prove mathematically that
> > I am the author.
>
> Maybe not mathematically, but legally.

For most everything else besides an argument in front of a Court,
people's perceptions are more important than proofs.  Most employees in
the U.S. can be fired from their jobs if their boss decides to, whether
or not they did anything improper.  OTOH, you can steal from your
company's pension fund and if your boss decides it's excusable, you keep
your job.


> > All that matters is whether others believe I wrote it. If I am not
> > comfortable with the possibility that I will be faced with a written
> > record of my own words, I use the telephone.
>
> While a phone call is usually less formal in style, it would be easier
> to (at least circumstantially) prove that you spoke on that pape than
> that you authored the message I am replying to.

At least in the U.S., you are not permitted to record a phone
conversation without the consent of all parties.  Without a recording,
private parties have trouble asserting a conversation even took place.
I can claim we spoke on the phone about this topic and you can claim we
didn't.  Generally, neither of us would claim anything because of the
difficulty of establishing any facts.

OTOH, I would have a harder time denying that this email was sent to the
list server from my computer.  I don't control the list server (I can't
even locate a human associated with it) and the headers are maintained
automatically.  The list maintainer's assertion is probably more
believable than mine.

In the hierarchy of communications methods, private verbal communication
appears to be informal, rapid and remains largely deniable, the latter
thanks to the well-known unreliability of human memory.  Talking is an
excellent way to encourage rapid sharing of new ideas that may be
discarded later, i.e. problem-solving and brainstorming.  It is
inefficient and unreliable, compared to IM or email, if you want a
searchable history of a conversation.

--
Seth Goodman