Re: Inexpensive anti-spamware/anti-verminware tactic
Jonathan de Boyne Pollard <[email protected]>
| Newsgroups | gmane.mail.im2000 |
|---|---|
| Organization | Wack's Wicks Works |
| Message-ID | <[email protected]> |
JR> It seems to me that IM2000 would be at best have no effect JR> on the problem of UBE, and at worst it would benefit spammers. Then either you have only been following one side of the discussions or you haven't understood how IM2000 changes the rules of the game. JR> Firstly, "cost to sender". And here's that one side. JR> UBE only exists because the cost to sender is low. This is a fallacy. Unsolicited bulk mail exists in systems where the cost to the sender is high, such as the physical mail system. There's just _less_ of it. Once again: <URL:http://homepages.tesco.net./~J.deBoynePollard/Proposals/IM2000/anti-ubm.html> JR> Clearly if the cost of sending an email were somehow increased JR> sufficiently, [...] You haven't been following the discussion. Once again: JdeBP> Imposing artifical costs on senders that the system JdeBP> inherently doesn't actually require - be they JdeBP> responding to challenges, electronic postage stamps, JdeBP> or authentication - isn't the answer. Sending is JdeBP> cheap. But the answer is not to make it artifically JdeBP> expensive. JR> IM2000 does not seem to help here at all, in fact it may make JR> things worse. Wrong. It makes things better. Like James, you aren't measuring the right thing. I'll say it again: Sending is cheap. It's the benefit that Internet has. We want it to remain cheap. So we create a mail system that _takes advantage_ of that, to replace the one that it confounded by it. James is stuck on the erroneous idea, that you repeat, that penalising senders is the goal. But it is not. JR> Furthermore, since the spammer will clearly be operating their JR> own message store, they receive the great benefit of knowing JR> who has decided to read their messages. They have that information right now, with web bugs, messages with external content, and "click here to secretly tell us you read this even though you might think that you are doing something else" hyperlinks. If they cared about that information, because they wanted to target only those people who were likely to buy their services/products, they'd be doing so _already_. However, they aren't. They still send mail to everyone that they possibly can. Therefore the assertion that IM2000 gives them some benefit is baseless. Tracking mail delivery, without having to rely upon a chain of intermediaries and upon the remote end, and without having to inject further messages into the system that aren't necessarily going to be delivered reliably themselves, gives a benefit to non-UBM senders. Remember them ? In all of these discussions claiming that it's so terrible that the costs to senders aren't drastically increased, they appear to have been completely forgotten. JR> Bear in mind that it is highly unlikely the spammer would be JR> running "proper" message store software. The whole trust model of IM2000 is that recipients know that message stores work for the senders, and so expect some message stores to be in collusion with malicious senders. The design accounts for this in a lot of places (Read the section on notification processing policy and the case study of reading mail, for starters.) and people are already familiar with the ways of dealing with this problem. After all, the same is true of web servers. Malicious web site authors can and do run content HTTP server softwares that do underhanded things (like present one page to Google and another page to everyone else). People who don't like the web pages simply ostracise those web servers. JR> I think storage space is a complete red herring here. Storage space is one of the several costs that IM2000 addresses, and it is far from being a red herring. I suggest that you listen to mail administrators complaining about how much disc space they have to devote to their mail queues, for a while. And if you still don't understand, I suggest that you ask a mailbox-hosting ISP why it places quotas on its customers' mailboxes. And if you _still_ don't understand, don't delete any messages from your "jon+usenet" mailbox and remove all quotas from it. There are other costs, even _aside_ from the cost of reading mail, too. JR> It seems me that IM2000 increases the cost to the recipient. The JR> recipient has less information about the message to make their JR> decision as to whether or not the message is something they want to read. False. If it is required, the recipient has the same information to work with as can be obtained via "TOP 0" in POP3. Read the case studies and the design principles. The advantage of IM2000 is that refusal of unwanted mail can _also_ occur, under the direct control of individual recipients, _without even that much_ information having been transferred. JR> If they decide they should read a message, there is then a JR> (potentially indefinite) delay while it is fetched from its JR> remote message store. Just like the cases with POP3, IMAP, "web mail" systems, and mailboxes hosted on Microsoft Exchange. (Ironically, I experienced a delay of several hours fetching mail from a POP3 server just yesterday.) If you want red herrings, _that_ is a red herring. JR> In fact UBE messages are likely to frequently have delays at JR> this point because the spammer's message store has been detected JR> and taken off-line. False. The "connection refused" or "unable to find a server to connect to" response would be immediate, just as it is when one tries to point a web browser at <URL:http://unequivocal.co.uk./>. JR> So the process of extracting your good messages from the UBE in JR> your mailbox is more complicated and takes longer than under the JR> current mail system. Being based upon an incorrect analysis, this conclusion is false. JR> Finally, sender authentication. This is the problem that things JR> like SPF try to address. And it's another red herring. Anonymity is an unavoidable fact of life, and it isn't the problem. Addressing anonymity is addressing the wrong problem. JR> I think that sender authentication is the area that is most promising JR> and should receive the most investigation. Then you are addressing the wrong problem. JR> In summary, I think IM2000 makes it easier for spammers to send their JR> spam messages, makes it more difficult for recipients to sort out the JR> spam from their real correspondence, and diverts attention away from JR> more promising approaches to the problem. * True, but artificially increasing the cost of the Internet mail system is not the goal. * False, and based upon not reading the details. * False, and based upon another erroneous idea of what the goal is. JR> please try to avoid [...] vague references to "the web site". This is yet more evidence that JR> I've been following this discussion is untrue. If you had, you would have seen the eight URLs that I've given in this discussion already (which has now risen to nine).