Monetary bonds in email
"Brett Watson" <[email protected]> Tue, 5 Dec 2006 15:16:22 +1100
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Message-ID | <[email protected]> |
Subject was "CAPTCHA over smtp (yet another spam solution to discuss)". On 12/5/06, Joachim Kupke <[email protected]> wrote: > Let's assume everybody turns their filters off. > Let's assume everybody receives 1=A2 per spam message (if claimed). > Somebody will have to pay for it. > > You are saying: Spammers could abuse credit cards to an extent > necessary to spend this kind of money. > > No numbers, but if you can squeeze that much money out of stolen credit > cards, you probably won't have to "work" (be it as a spammer) anymore. The "one cent per spam message (if claimed)" is a "bond": a monetary promise that certain conditions will be met, with forfeiture of the bond as the cost of non-compliance. Where a blackhat has access to illicit credit card details, spam was probably involved in the process of obtaining those details in the first place. A blackhat has two broad ways of obtaining such details: buy them on the black market, or obtain them himself. In the former case, he's just paying someone else to do the latter, so let's concentrate on the latter case. There are several obvious ways that one can obtain CC details. 1. Phishing. Send spam which claims to be from a particular bank, claiming that the user must reactivate his Internet banking facility. Provide a web page with forms covering the gamut from account number to credit card number, to mother's maiden name, PINs and passwords. 2. A shop. Set up an Internet shop front selling cheap pharmaceuticals or imitation watches. Advertise via spam. Don't actually hold any stock or make any deliveries -- just allow people to order, disclosing their CC# and verification codes, then apologise that the transaction could not be processed for some reason. (E.g.: "Our payment processing facility is down, please try again tomorrow.") 3. Keystroke logging. Send spam which points people to a website loaded with an exploit which installs a keylogger on their system. Harvest every useful piece of information, such as eBay and PayPal login details, Internet banking details, email addresses for further spamming, and, of course, credit card details. 4. Hack a payment processor or online shop directly. Raid the database or install a back door. Of these options, only #4 does not involve spamming as a part of the process. If the cost of spamming goes up, then the expected return on investment goes down, but so long as it remains a grossly profitable exercise, there is incentive to continue. Crime is a high risk, high margin business. But even this analysis overlooks the obvious. Let's make the assumptions you cite about every email being covered by a one cent bond which the recipient may claim if he considers the message spam. This creates a new form of currency in the spammer world: compromised email accounts. Just as Internet banking account access credentials are bought and sold on the black market now, new specialists will arise who sell compromised email accounts. An account with $X worth of "stamp credit" in it will probably cash out on the black market for a small percentage of that amount. It competes against the process of setting up a new Yahoo!/Hotmail not-quite-free-anymore email account with $X in credit from a stolen credit card. There's also the question of how easily a certain activity can be "cashed out", or converted into something of value. If you have a credit card number, then you can attempt to purchase goods and have them shipped to you, or you can purchase intangibles like a domain name and email credit. In the latter case, you can start using the goods instantly, before anyone has a chance to detect the fraud. It's much easier to "cash out" that way, and thus an attractive form of fraud. In short, I don't think that the "bonded sender" style of anti-spam can work, even in principle, because spam has changed. Whereas before we were hit primarily by junk from "legitimate" businesses who saw spam as a very cheap means of advertising, the larger source is now the hard-core scammers and criminals who see it as a safe way to conduct extremely profitable crimes. It's not clear that we can defeat this crowd with economic pressure, because they don't play by the rules. If something is too expensive for them, they steal it instead of buying it. The economics of crime and the economics of commerce are different things. Making email a more expensive thing simply makes it a more attractive target of theft. Cybercrooks have little incentive to hack your email account when they can set up new free accounts easily, or just generate spam directly. Make your email account valuable, however, and they may decide that it's easier to steal yours than start a new one.