Re: Monetary bonds in email
Joachim Kupke <[email protected]> Tue, 5 Dec 2006 16:03:29 -0800
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Message-ID | <[email protected]> |
Brett Watson wrote: >Where a blackhat has access to illicit credit card details, spam was >probably involved in the process of obtaining those details in the >first place. Which does however nothing to alter the fact that recipients' attention should come at a price. And yes, credit card numbers are ridiculously insecure. >There are several obvious ways that one can obtain CC details. > >1. Phishing. [...] >2. A shop. [...] I don't see much of a difference between these. If your payment method of choice is to forward your credit card number, a payee can trivially impersonate you. But even an advanced payment system would not prevent people from spending money on things they do not want. Or, for that matter, to give their money to strangers for nothing in return. >3. Keystroke logging. [... malware, actually ...] That's actually quite an obstacle for the adoption of cryptography. If machines are owned, cryptographic signatures (and what have you) cannot be trusted. >4. Hack a payment processor or online shop [...] s/H/Cr/ >Of these options, only #4 does not involve spamming as a part of the >process. If the cost of spamming goes up, then the expected return on >investment goes down, but so long as it remains a grossly profitable >exercise, there is incentive to continue. Crime is a high risk, high >margin business. Some numbers, maybe? You seem to suggest that the cost of spamming, while it may increase, would remain at the same order of magnitude? >Just as Internet banking account access credentials are bought and sold >on the black market now, new specialists will arise who sell >compromised email accounts. An account with $X worth of "stamp credit" >in it will probably cash out on the black market for a small percentage >of that amount. The dealer on the black market might have an easier time abusing the compromised account by sending him-/herself what s/he later alleges is spam. >In short, I don't think that the "bonded sender" style of anti-spam can >work, even in principle, because spam has changed. Whereas before we >were hit primarily by junk from "legitimate" businesses who saw spam as >a very cheap means of advertising, the larger source is now the >hard-core scammers and criminals who see it as a safe way to conduct >extremely profitable crimes. It's not clear that we can defeat this >crowd with economic pressure, because they don't play by the rules. If >something is too expensive for them, they steal it instead of buying >it. The economics of crime and the economics of commerce are different >things. Your last statement may be up for philosophical (or criminological, maybe) debate. In any event, you are basically saying, let's uphold the barter system! Money is easier to steal, especially in large quantities, than the goods it could buy you. While that's true, most modern societies have found it to be more efficient than trading cows against tools. >Making email a more expensive thing simply makes it a more attractive >target of theft. Cybercrooks have little incentive to hack your email >account when they can set up new free accounts easily, or just generate >spam directly. Make your email account valuable, however, and they may >decide that it's easier to steal yours than start a new one. By making paper with some numbers on it worth something (or, say, by minting coins with no gold in them), societies have long created value that is, technically, relatively easy to counterfeit. But yes, I do agree that it is scary how easy it is to steal information. The answer should be to better protect that information rather than making it worthless. --Joachim