Monetary bonds in email

"Brett Watson" <[email protected]> Tue, 5 Dec 2006 15:16:22 +1100
Newsgroups gmane.mail.im2000
Message-ID <[email protected]>
Subject was "CAPTCHA over smtp (yet another spam solution to discuss)".

On 12/5/06, Joachim Kupke <[email protected]> wrote:
> Let's assume everybody turns their filters off.
> Let's assume everybody receives 1=A2 per spam message (if claimed).
> Somebody will have to pay for it.
>
> You are saying:  Spammers could abuse credit cards to an extent
> necessary to spend this kind of money.
>
> No numbers, but if you can squeeze that much money out of stolen credit
> cards, you probably won't have to "work" (be it as a spammer) anymore.

The "one cent per spam message (if claimed)" is a "bond": a monetary
promise that certain conditions will be met, with forfeiture of the
bond as the cost of non-compliance.

Where a blackhat has access to illicit credit card details, spam was
probably involved in the process of obtaining those details in the
first place. A blackhat has two broad ways of obtaining such details:
buy them on the black market, or obtain them himself. In the former
case, he's just paying someone else to do the latter, so let's
concentrate on the latter case.

There are several obvious ways that one can obtain CC details.

1. Phishing. Send spam which claims to be from a particular bank,
claiming that the user must reactivate his Internet banking facility.
Provide a web page with forms covering the gamut from account number
to credit card number, to mother's maiden name, PINs and passwords.

2. A shop. Set up an Internet shop front selling cheap pharmaceuticals
or imitation watches. Advertise via spam. Don't actually hold any
stock or make any deliveries -- just allow people to order, disclosing
their CC# and verification codes, then apologise that the transaction
could not be processed for some reason. (E.g.: "Our payment processing
facility is down, please try again tomorrow.")

3. Keystroke logging. Send spam which points people to a website
loaded with an exploit which installs a keylogger on their system.
Harvest every useful piece of information, such as eBay and PayPal
login details, Internet banking details, email addresses for further
spamming, and, of course, credit card details.

4. Hack a payment processor or online shop directly. Raid the database
or install a back door.

Of these options, only #4 does not involve spamming as a part of the
process. If the cost of spamming goes up, then the expected return on
investment goes down, but so long as it remains a grossly profitable
exercise, there is incentive to continue. Crime is a high risk, high
margin business.

But even this analysis overlooks the obvious. Let's make the
assumptions you cite about every email being covered by a one cent
bond which the recipient may claim if he considers the message spam.
This creates a new form of currency in the spammer world: compromised
email accounts.

Just as Internet banking account access credentials are bought and
sold on the black market now, new specialists will arise who sell
compromised email accounts. An account with $X worth of "stamp credit"
in it will probably cash out on the black market for a small
percentage of that amount. It competes against the process of setting
up a new Yahoo!/Hotmail not-quite-free-anymore email account with $X
in credit from a stolen credit card.

There's also the question of how easily a certain activity can be
"cashed out", or converted into something of value. If you have a
credit card number, then you can attempt to purchase goods and have
them shipped to you, or you can purchase intangibles like a domain
name and email credit. In the latter case, you can start using the
goods instantly, before anyone has a chance to detect the fraud. It's
much easier to "cash out" that way, and thus an attractive form of
fraud.

In short, I don't think that the "bonded sender" style of anti-spam
can work, even in principle, because spam has changed. Whereas before
we were hit primarily by junk from "legitimate" businesses who saw
spam as a very cheap means of advertising, the larger source is now
the hard-core scammers and criminals who see it as a safe way to
conduct extremely profitable crimes. It's not clear that we can defeat
this crowd with economic pressure, because they don't play by the
rules. If something is too expensive for them, they steal it instead
of buying it. The economics of crime and the economics of commerce are
different things.

Making email a more expensive thing simply makes it a more attractive
target of theft. Cybercrooks have little incentive to hack your email
account when they can set up new free accounts easily, or just
generate spam directly. Make your email account valuable, however, and
they may decide that it's easier to steal yours than start a new one.