RE: CAPTCHA over smtp (yet another spam solution to discuss)
"Seth Goodman" <[email protected]> Wed, 29 Nov 2006 15:54:11 -0600
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Message-ID | <[email protected]> |
Joachim wrote on 20 Nov 2006: > Seth Goodman wrote: >=20 > > > > [Lists] can charge money for posting today with no special > > > > infrastructure. Why are there not many lists operating this > > > > way?=20 > > >=20 > > > How would they charge money? (Again, bonds are different from > > > charging money, of course.) Would they collect my credit card > > > number? > >=20 > > I think you can do this today without disclosing much private > > information. Perhaps make a PayPal (or similar) deposit into an > > escrow account controlled by the list owner. >=20 > Assuming that most postings would be legitimate, how would PayPal ever > make any money? They collect a fee for every transfer, including transfers into escrow = accounts. If you don't like this, then you need a nearly-free = micro-payment system. This is precisely why hash-cash and all similar = schemes are still-born. There is no existing reliable way to transfer = small amounts of money without taking a large percentage as a transfer = fee. > > To do what you suggest on a larger scale, you'd need a micropayment > > system that also does not permit charge backs. I have no idea if > > that is even legal in most places (you can't keep stolen property, > > even if someone gave it to you to pay a valid debt). >=20 > Are you suggesting spammers would adapt by going on a credit card > number (or whatever) theft spree? That is how they generally purchase ISP accounts today. By the time the = credit card number is reported stolen, the spammer has finished their = business and they expect the account to be closed. > If you get spammed, seize the bond posted by the spammer, and law > enforcement finds that this money was stolen, you are out of luck. > Unless, of course, you are insured against that kind of thing. (But > who would get insured to file this once-in-a-lifetime claim for maybe > 50=C2=A2?) That is the whole point. Until you can reliably transfer small amounts = of money at very low cost, this kind of scheme is only of theoretical = interest. > > versus requiring literacy but no specific knowledge (captcha). >=20 > I don't think a captcha is an accurate means of measuring literacy. It's not supposed to. A captcha a supposed to distinguish human from = machine. Recognizing a familiar pattern in a noisy image, where the = pattern happens to be a sequence of alphanumeric characters, is the = challenge. It is an accident that it requires literacy. > > I don't care if my browser negotiates a SSL connection every time it > > views a web site. However, I would tire quickly of processing a > > captcha for every email address to which I directly send a message. >=20 > What are you getting at? What are you even arguing for (or against)? > That there are C/R protocols that are "better" than captchas? Then > stop arguing, because we agree. Email recipients should be able to > configure what kind of C/R protocol they desire be used. I am arguing against captcha's in particular, and C/R for email in = general. The reason that C/R is not widely adopted, despite a lot of = noise originally made about the idea, is that end users most often = choose "none" as the "kind of C/R protocol they desire be used". >=20 > > I actually meant what I first said. C/R email systems require my > > direct participation. >=20 > Why? Your MUA would fill in the reponse for you. Arguably not for a > captcha, though. :-) My MUA can't know what challenges I'd like to accept. If I tell it to = accept all, I have just defeated the C/R system and will not benefit in = any way. If I try to create a set of rules for which challenges to = accept, I create a whole new spam vector. This is a lose/lose scenario. = It increases the transaction costs for both legitimate senders and = recipients with no long-term gain. > > > [Repudiability of authorship is a good thing.] > > For most everything else besides an argument in front of a Court, > > people's perceptions are more important than proofs. >=20 > Precisely. Imagine your casual email making headline news. If I > forward a non-signed email to a newspaper, they will yawn. Newspaper reporters are neither technologists, lawyers nor = mathematicians. What you can say is that _should_ yawn, or that you = wish they _would_ yawn. Regardless, they look at content first. A = leaked memo is nothing but a printed document with no signature and is = easily forged, but likely to be believed despite that. > > OTOH, I would have a harder time denying that this email was sent to > > the list server from my computer. I don't control the list server > > (I can't even locate a human associated with it) and the headers are > > maintained automatically. The list maintainer's assertion is > > probably more believable than mine. >=20 > Those headers and everything can be spoofed. Who cares? Most email and memos that are leaked and become problems for = the original authors are secured neither with cryptography nor written = signatures. In many cases, the only _proof_ of authorship is someone = else's assertion that they saw the memo and they believed it came from = the apparent author. You are confusing provability and theory in a = perfect world with what people actually believe and the very limited = information on which they must base decisions every day. --=20 Seth Goodman