Re: Hashcash for IM2000

The Famous Brett Watson <[email protected]>
Newsgroups gmane.mail.im2000
Organization The Association for the Advancement of Alternative Concepts and Epistemological Awareness
Message-ID <[email protected]>
Wes,

On Fri, 5 Sep 2003 23:20, you wrote:
> I was reading an article on K5 about TMDA, and one of the commenters posted
> a link to Hashcash (http://www.hashcash.org). This system looks really
> promising. I recommend reading the FAQ at the site, but in a nutshell it

Of the several problems with HashCash, I will mention one, selected on the 
basis that it's a relatively new objection.

Rule zero of spam is that spam is theft. Spammers are theives, and they are 
showing their true colours more clearly all the time. Many of the current 
crop of viruses are suspected to download and install spam-related software 
so that spammers can spam from third party computers, rather than their own, 
thus making them harder to shut down. Likewise for web services, as in this 
description of the "Migmaf" malware.

  http://www.lurhq.com/migmaf.html

Thus, one of the reasons that HashCash would be ineffective (relative to the 
effort of implementation) in the current environment is that spammers are 
generally willing and able to steal third party computing resources in large 
quantities. The more organised ones tend to maintain their own illicit 
distributed computing networks already. If they can use compromised third 
party computers to send mail, they can get those computers to compute 
HashCash checksums as needs be also.

Conversely, legitimate operators of subscription-based mailing lists are 
fighting an increasing battle with recipients who implement spam-filtering 
measures. HashCash would be another thorn in their side, since it relies on 
the diligence of the end user to maintain a list of addresses not to 
challenge.

Challenge/response is a generally useful area: I mentioned the idea of Turing 
Tests a while back on this list, and the idea has already gone from novel to 
commonplace as a spam filtering technique. You need to be extremely cautious 
about the implications of the challenge and response, though. Perhaps it is 
best to keep protocol details at this broader level: "a general mechanism for 
challenges and responses". HashCash could be one such challenge/response 
system, though I personally don't consider it useful.

Regards,
TFBW
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.