RE: CAPTCHA over smtp (yet another spam solution to discuss)

"Seth Goodman" <[email protected]> Wed, 29 Nov 2006 15:54:11 -0600
Newsgroups gmane.mail.im2000
Message-ID <[email protected]>
Joachim wrote on  20 Nov 2006:

> Seth Goodman wrote:
>=20
> > > > [Lists] can charge money for posting today with no special
> > > > infrastructure.  Why are there not many lists operating this
> > > > way?=20
> > >=20
> > > How would they charge money?  (Again, bonds are different from
> > > charging money, of course.)  Would they collect my credit card
> > > number?
> >=20
> > I think you can do this today without disclosing much private
> > information.  Perhaps make a PayPal (or similar) deposit into an
> > escrow account controlled by the list owner.
>=20
> Assuming that most postings would be legitimate, how would PayPal ever
> make any money?

They collect a fee for every transfer, including transfers into escrow =
accounts.  If you don't like this, then you need a nearly-free =
micro-payment system.  This is precisely why hash-cash and all similar =
schemes are still-born.  There is no existing reliable way to transfer =
small amounts of money without taking a large percentage as a transfer =
fee.


> > To do what you suggest on a larger scale, you'd need a micropayment
> > system that also does not permit charge backs.  I have no idea if
> > that is even legal in most places (you can't keep stolen property,
> > even if someone gave it to you to pay a valid debt).
>=20
> Are you suggesting spammers would adapt by going on a credit card
> number (or whatever) theft spree?

That is how they generally purchase ISP accounts today.  By the time the =
credit card number is reported stolen, the spammer has finished their =
business and they expect the account to be closed.


> If you get spammed, seize the bond posted by the spammer, and law
> enforcement finds that this money was stolen, you are out of luck.
> Unless, of course, you are insured against that kind of thing.  (But
> who would get insured to file this once-in-a-lifetime claim for maybe
> 50=C2=A2?)

That is the whole point.  Until you can reliably transfer small amounts =
of money at very low cost, this kind of scheme is only of theoretical =
interest.


> > versus requiring literacy but no specific knowledge (captcha).
>=20
> I don't think a captcha is an accurate means of measuring literacy.

It's not supposed to.  A captcha a supposed to distinguish human from =
machine.  Recognizing a familiar pattern in a noisy image, where the =
pattern happens to be a sequence of alphanumeric characters, is the =
challenge.  It is an accident that it requires literacy.


> > I don't care if my browser negotiates a SSL connection every time it
> > views a web site.  However, I would tire quickly of processing a
> > captcha for every email address to which I directly send a message.
>=20
> What are you getting at?  What are you even arguing for (or against)?
> That there are C/R protocols that are "better" than captchas?  Then
> stop arguing, because we agree.  Email recipients should be able to
> configure what kind of C/R protocol they desire be used.

I am arguing against captcha's in particular, and C/R for email in =
general.  The reason that C/R is not widely adopted, despite a lot of =
noise originally made about the idea, is that end users most often =
choose "none" as the "kind of C/R protocol they desire be used".

>=20
> > I actually meant what I first said.  C/R email systems require my
> > direct participation.
>=20
> Why?  Your MUA would fill in the reponse for you.  Arguably not for a
> captcha, though. :-)

My MUA can't know what challenges I'd like to accept.  If I tell it to =
accept all, I have just defeated the C/R system and will not benefit in =
any way.  If I try to create a set of rules for which challenges to =
accept, I create a whole new spam vector.  This is a lose/lose scenario. =
 It increases the transaction costs for both legitimate senders and =
recipients with no long-term gain.


> > > [Repudiability of authorship is a good thing.]
> > For most everything else besides an argument in front of a Court,
> > people's perceptions are more important than proofs.
>=20
> Precisely.  Imagine your casual email making headline news.  If I
> forward a non-signed email to a newspaper, they will yawn.

Newspaper reporters are neither technologists, lawyers nor =
mathematicians.  What you can say is that _should_ yawn, or that you =
wish they _would_ yawn.  Regardless, they look at content first.  A =
leaked memo is nothing but a printed document with no signature and is =
easily forged, but likely to be believed despite that.


> > OTOH, I would have a harder time denying that this email was sent to
> > the list server from my computer.  I don't control the list server
> > (I can't even locate a human associated with it) and the headers are
> > maintained automatically.  The list maintainer's assertion is
> > probably more believable than mine.
>=20
> Those headers and everything can be spoofed.

Who cares?  Most email and memos that are leaked and become problems for =
the original authors are secured neither with cryptography nor written =
signatures.  In many cases, the only _proof_ of authorship is someone =
else's assertion that they saw the memo and they believed it came from =
the apparent author.  You are confusing provability and theory in a =
perfect world with what people actually believe and the very limited =
information on which they must base decisions every day.

--=20
Seth Goodman