RE: CAPTCHA over smtp (yet another spam solution to discuss)
"Seth Goodman" <[email protected]> Sat, 18 Nov 2006 01:50:55 -0600
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Message-ID | <[email protected]> |
Joachim <> wrote on -0500: > > I'm not proposing this solution. They can charge money for posting > > today with no special infrastructure. Why are there not many lists > > operating this way? > > How would they charge money? (Again, bonds are different from > charging money, of course.) Would they collect my credit card number? I think you can do this today without disclosing much private information. Perhaps make a PayPal (or similar) deposit into an escrow account controlled by the list owner. You disclose your email address but not your Bank Account or Credit Card number. I'm not claiming it's actually good. PayPal is expensive for small transactions. If someone pays with a stolen credit card number that is not reported for a while, the deposit can be reversed later. To do what you suggest on a larger scale, you'd need a micropayment system that also does not permit charge backs. I have no idea if that is even legal in most places (you can't keep stolen property, even if someone gave it to you to pay a valid debt). > > If the assertion requires zero knowledge by the sender, then anyone > > can make it. > > Please familiarize yourself with zero-knowledge proofs. > http://en.wikipedia.org/wiki/Zero-knowledge_proof has the cave story. > > > Perhaps the only thing you can assert without requiring knowledge > ^^^^^^^^^ > The point is to not disclose it. I do see the distinction: disclosing zero knowledge during the identity assertion (TLS session) versus requiring literacy but no specific knowledge (captcha). I don't care if my browser negotiates a SSL connection every time it views a web site. However, I would tire quickly of processing a captcha for every email address to which I directly send a message. > > I have already refused to deal with C/R systems when it annoys me > > enough, so I don't think it wise to inflict this on others. > > I guess you really meant to say you refused to deal with captchas that > annoyed you. I actually meant what I first said. C/R email systems require my direct participation. Protocols involving cryptographic challenges require only my computer resources and not my time. I don't mind captchas for web forms, since I don't use them very often. If I had to use captchas for sending common emails, I would personally find that annoying and would try to avoid it. > [Repudiability of authorship is a good thing.] > > That's news to me. If you don't want someone to trot out something > > you wrote down, then don't write it down. When I send someone mail > > of any kind, I have to assume that it could surface at some later > > time. It matters little whether they can prove mathematically that > > I am the author. > > Maybe not mathematically, but legally. For most everything else besides an argument in front of a Court, people's perceptions are more important than proofs. Most employees in the U.S. can be fired from their jobs if their boss decides to, whether or not they did anything improper. OTOH, you can steal from your company's pension fund and if your boss decides it's excusable, you keep your job. > > All that matters is whether others believe I wrote it. If I am not > > comfortable with the possibility that I will be faced with a written > > record of my own words, I use the telephone. > > While a phone call is usually less formal in style, it would be easier > to (at least circumstantially) prove that you spoke on that pape than > that you authored the message I am replying to. At least in the U.S., you are not permitted to record a phone conversation without the consent of all parties. Without a recording, private parties have trouble asserting a conversation even took place. I can claim we spoke on the phone about this topic and you can claim we didn't. Generally, neither of us would claim anything because of the difficulty of establishing any facts. OTOH, I would have a harder time denying that this email was sent to the list server from my computer. I don't control the list server (I can't even locate a human associated with it) and the headers are maintained automatically. The list maintainer's assertion is probably more believable than mine. In the hierarchy of communications methods, private verbal communication appears to be informal, rapid and remains largely deniable, the latter thanks to the well-known unreliability of human memory. Talking is an excellent way to encourage rapid sharing of new ideas that may be discarded later, i.e. problem-solving and brainstorming. It is inefficient and unreliable, compared to IM or email, if you want a searchable history of a conversation. -- Seth Goodman