Re: CAPTCHA over smtp (yet another spam solution to discuss)

Joachim Kupke <[email protected]> Wed, 29 Nov 2006 17:28:16 -0800
Newsgroups gmane.mail.im2000
Message-ID <[email protected]>
Seth Goodman wrote:

[If financial bonds are the answer, why does nobody use PayPal to 
implement them?]
>> Assuming that most postings would be legitimate, how would PayPal 
>> ever make any money?
>
>They collect a fee for every transfer, including transfers into escrow 
>accounts.

I said:  Requiring that bonds be posted to prevent spam is compatible 
with mailing lists.  The objection was:  Why does nobody use PayPal to 
this effect, then?  You just answered:  They're too expensive.

>If you don't like this, then you need a nearly-free micro-payment 
>system.  This is precisely why hash-cash and all similar schemes are 
>still-born.  There is no existing reliable way to transfer small 
>amounts of money without taking a large percentage as a transfer fee.

I agree:  Messages flow more easily than money.
Which does nothing to alter the fact that PayPal may be just too expensive.
Nor to alter the fact that hash-cash, e.g., doesn't model a spammer's 
(or legitimate email sender's) economical reality nearly as well as 
money.

[By subverting the security of electronic payments, spammers could 
happily continue their business.]
>> Are you suggesting spammers would adapt by going on a credit card 
>> number (or whatever) theft spree?
>
>That is how they generally purchase ISP accounts today.  By the time 
>the credit card number is reported stolen, the spammer has finished 
>their business and they expect the account to be closed.

The difference being, the spammer's victims aren't compensated (today).
Which has to do with the fact that credit cards are inherently insecure, 
which results in high transaction costs.

>That is the whole point.  Until you can reliably transfer small amounts 
>of money at very low cost, this kind of scheme is only of theoretical 
>interest.

Yep, it only works with negligible transaction costs.  Until everyone 
figures out what kind of transaction is the least expensive, the 
Internet's email protocol should come with a customizable C/R mechanism.

>> > I would tire quickly of processing a captcha for every email 
>> > address to which I directly send a message.
>>
>> What are you getting at?  What are you even arguing for (or against)?  
>> That there are C/R protocols that are "better" than captchas?  Then 
>> stop arguing, because we agree.  Email recipients should be able to 
>> configure what kind of C/R protocol they desire be used.
>
>I am arguing against captcha's in particular, and C/R for email in 
>general.  The reason that C/R is not widely adopted, despite a lot of 
>noise originally made about the idea, is that end users most often 
>choose "none" as the "kind of C/R protocol they desire be used".

The last time I checked SMTP didn't have any C/R "built in"; so, how do 
you know?  You seem to be referring to the procedure of spamming people 
whose address appears in some FROM: line in received messages with some 
challenge.

>> > C/R email systems require my direct participation.
>>
>> Why?  Your MUA would fill in the reponse for you.  Arguably not for a 
>> captcha, though. :-)
>
>My MUA can't know what challenges I'd like to accept.

Configure:  "Automatically agree to post bond for amounts <= $ XXX."

>If I tell it to accept all, I have just defeated the C/R system and 
>will not benefit in any way.

Right.  Unless you count making the likely experience of filing for 
bankruptcy as a benefit.

>If I try to create a set of rules for which challenges to accept, I 
>create a whole new spam vector.

Why?  Arguably, agreeing to automatically post small-enough bonds would 
be sufficient for most people.  But even if you create a "set of rules," 
how does that create a "spam vector"?  You would only be "spammed" with 
challenges from people you are trying to send messages to in the first 
place, and only at the very time you do.

>> > > [Repudiability of authorship is a good thing.]
>> > For most everything else besides an argument in front of a Court, 
>> > people's perceptions are more important than proofs.
>> 
>> Precisely.  Imagine your casual email making headline news.  If I 
>> forward a non-signed email to a newspaper, they will yawn.
>
>Newspaper reporters are neither technologists, lawyers nor 
>mathematicians.  What you can say is that _should_ yawn, or that you 
>wish they _would_ yawn.  Regardless, they look at content first.  A 
>leaked memo is nothing but a printed document with no signature and is 
>easily forged, but likely to be believed despite that.

We'll have to agree that we disagree.  You are basically saying that 
there is no use in electronic signatures as the number of people 
competent enough to verify them is negligibly small.  I take exception, 
but do go ahead and prove me wrong.  Forward a forged email to your 
local newspaper, with, say, $CELEBRITY confessing to $FELONY.

[If a mailing list maintainer asserts Seth Goodman sent a message, 
that's at least as good as an electronic signature.  If not better.]
>> Those headers and everything can be spoofed.
>
>Who cares?  Most email and memos that are leaked and become problems 
>for the original authors are secured neither with cryptography nor 
>written signatures.  In many cases, the only _proof_ of authorship is 
>someone else's assertion that they saw the memo and they believed it 
>came from the apparent author.  You are confusing provability and 
>theory in a perfect world with what people actually believe and the 
>very limited information on which they must base decisions every day.

I do agree that markets, e.g., react to rumors.  But rumors != facts.

At any rate, if you don't see an advantage in electronic signatures, so 
be it.  How about something more elaborate, like an encrypted ballot 
(the validity of which the sender/voter would assert using a 
zero-knowledge proof)?


--Joachim