Re: Inexpensive anti-spamware/anti-verminware tactic
Jonathan de Boyne Pollard <[email protected]>
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Organization | Wack's Wicks Works |
| Message-ID | <[email protected]> |
JdeBP> The two have a very fundamental architectural difference,
JdeBP> which happens to be the nub of the problem. No amount of
JdeBP> "improvement" to the SMTP-based system will change that
JdeBP> fundamental difference.
JCB> Sampling the spam my system gets, I notice some that are
JCB> nothing but one of the following:
JCB> - URLs to web sites with text advertising a product
JCB> - URLs to web sites with only graphics (e.g. JPEGs)
JCB> advertising a product
JCB> - MIME-encoded graphics (JPEGs) advertising a product
JCB> How does the fundamental architectural difference between
JCB> IM2000 and SMTP address UCE of those sorts?
By having the sender store the messages concerned, and the recipients
only download them when they choose to read them, of course.
Hint: This argument has come up before. Whilst it is fair to say that
sending a message comprising solely a URL, with the expectation that the
recipient will automatically view the web page at that URL, is the nearest
that the SMTP-based Internet mail system can come to IM2000, there are also
two very important points that most people miss:
1. Whilst it's the closest that the SMTP-based Internet mail system can
come to IM2000, it's _not_ IM2000. It's just a simulacrum. In particular,
note that the SMTP-based mail message contains a lot more than an IM2000
notification would, and provides senders with trivial covert channels.
<URL:http://homepages.tesco.net./~J.deBoynePollard/Proposals/IM2000/design.html#NoTrivialCovertChannels>
2. Senders _use_ these covert channels in the SMTP-based Internet mail
system. People claim that they receive unsolicited bulk mail that
comprises only a URL. But they often unconsciously edit out what it is
that they actually _are_ receiving, which _isn't_ as they describe. My
unsolicited bulk mail load comprises messages with URLs, but these URLs
are invariably accompanied either by enticing text in the body encouraging
one to view the web page with the advertisement on it ("click _here_ to
remove yourself from our mailing list") or enticing text _in the headers_
("Re: The web page I was telling you about").
Really there are two separate issues here:
1. If unsolicited bulk messages in SMTP-based Internet mail _did_ devolve
into merely URL-and-nothing-else-at-all, then people wouldn't be complaining
about a problem in the first place. They'd look at who the sender is and
what web site the URL indicates, and simply wouldn't look at anything whose
origin appeared to be unpalatable. Indeed, the faint of heart would even
link their MUAs to "Net Nanny" web page rating services and have URLs in
messages rated automatically, so that they could have others do the work
for them of deciding what web pages to avoid reading. In essence, we'd
already have IM2000. But the existence of the trivial covert channels
means that this isn't the case. Therefore any argument based upon the
notion that "The situation is already pretty much as it would be were
IM2000 to be adopted." is wrong.
2. It's an error to conflate transport and content. The two are separate,
and their problems are only very loosely related. IM2000 addresses
transport. People want it to address content as well. But that's a
mistake. The problems with transport and the problems with content can,
and should, be addressed separately. The "graphics advertising a product"
notion is a red herring, therefore. Your first two cases are identical
as far as transport is concerned.
JCB> [IM2000] will also make *delivery* of such UCE much less expensive,
JCB> correct?
It depends from what one is comparing. Are you comparing sending the
_same_ message (containing the URL pointing to the web page) through
both systems ? If so, the answer is that senders' costs actually
increase slightly, as they have to send three things (a notification,
a message, and the web page) in place of two (a message and the web
page). Are you comparing sending a URL pointing to a web page via
SMTP-based Internet mail with sending the actual web page content _as_
the message in IM2000 ? If so, the delivery costs should be slightly
(but not "much") less. However: (a) That SMTP-based case doesn't occur
in the real world (because the UBM senders exploit the covert channels to
send more than solly a notification message). (b) So what if sending
is cheap ? That's the _whole point_. Internet is good at this and we
are trying to take advatage of it. You should be concentrating upon
the costs to the recipients, rather than concentrating upon the senders'
costs as you have been doing here.