Re: Hashcash for IM2000
The Famous Brett Watson <[email protected]>
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Organization | The Association for the Advancement of Alternative Concepts and Epistemological Awareness |
| Message-ID | <[email protected]> |
Wes, On Fri, 5 Sep 2003 23:20, you wrote: > I was reading an article on K5 about TMDA, and one of the commenters posted > a link to Hashcash (http://www.hashcash.org). This system looks really > promising. I recommend reading the FAQ at the site, but in a nutshell it Of the several problems with HashCash, I will mention one, selected on the basis that it's a relatively new objection. Rule zero of spam is that spam is theft. Spammers are theives, and they are showing their true colours more clearly all the time. Many of the current crop of viruses are suspected to download and install spam-related software so that spammers can spam from third party computers, rather than their own, thus making them harder to shut down. Likewise for web services, as in this description of the "Migmaf" malware. http://www.lurhq.com/migmaf.html Thus, one of the reasons that HashCash would be ineffective (relative to the effort of implementation) in the current environment is that spammers are generally willing and able to steal third party computing resources in large quantities. The more organised ones tend to maintain their own illicit distributed computing networks already. If they can use compromised third party computers to send mail, they can get those computers to compute HashCash checksums as needs be also. Conversely, legitimate operators of subscription-based mailing lists are fighting an increasing battle with recipients who implement spam-filtering measures. HashCash would be another thorn in their side, since it relies on the diligence of the end user to maintain a list of addresses not to challenge. Challenge/response is a generally useful area: I mentioned the idea of Turing Tests a while back on this list, and the idea has already gone from novel to commonplace as a spam filtering technique. You need to be extremely cautious about the implications of the challenge and response, though. Perhaps it is best to keep protocol details at this broader level: "a general mechanism for challenges and responses". HashCash could be one such challenge/response system, though I personally don't consider it useful. Regards, TFBW