Re: CAPTCHA over smtp (yet another spam solution to discuss)
Joachim Kupke <[email protected]> Mon, 20 Nov 2006 11:13:09 -0800
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Message-ID | <[email protected]> |
Seth Goodman wrote: >> > [Lists] can charge money for posting today with no special >> > infrastructure. Why are there not many lists operating this way? >> >> How would they charge money? (Again, bonds are different from >> charging money, of course.) Would they collect my credit card >> number? > >I think you can do this today without disclosing much private >information. Perhaps make a PayPal (or similar) deposit into an escrow >account controlled by the list owner. Assuming that most postings would be legitimate, how would PayPal ever make any money? >To do what you suggest on a larger scale, you'd need a micropayment >system that also does not permit charge backs. I have no idea if that >is even legal in most places (you can't keep stolen property, even if >someone gave it to you to pay a valid debt). Are you suggesting spammers would adapt by going on a credit card number (or whatever) theft spree? If you get spammed, seize the bond posted by the spammer, and law enforcement finds that this money was stolen, you are out of luck. Unless, of course, you are insured against that kind of thing. (But who would get insured to file this once-in-a-lifetime claim for maybe 50ยข?) [Zero-knowledge proofs] >I do see the distinction: disclosing zero knowledge during the >identity assertion (TLS session) Note, however, that zero-knowledge proofs can be used to assert more than mere identity. >versus requiring literacy but no specific knowledge (captcha). I don't think a captcha is an accurate means of measuring literacy. >I don't care if my browser negotiates a SSL connection every time it >views a web site. However, I would tire quickly of processing a >captcha for every email address to which I directly send a message. What are you getting at? What are you even arguing for (or against)? That there are C/R protocols that are "better" than captchas? Then stop arguing, because we agree. Email recipients should be able to configure what kind of C/R protocol they desire be used. >I actually meant what I first said. C/R email systems require my >direct participation. Why? Your MUA would fill in the reponse for you. Arguably not for a captcha, though. :-) >> [Repudiability of authorship is a good thing.] >For most everything else besides an argument in front of a Court, >people's perceptions are more important than proofs. Precisely. Imagine your casual email making headline news. If I forward a non-signed email to a newspaper, they will yawn. >OTOH, I would have a harder time denying that this email was sent to >the list server from my computer. I don't control the list server (I >can't even locate a human associated with it) and the headers are >maintained automatically. The list maintainer's assertion is probably >more believable than mine. Those headers and everything can be spoofed. --Joachim