Re: Opportunistic signatures - a proposed design
Atom 'Smasher' <[email protected]>
| Newsgroups | gmane.mail.spam.hashcash |
|---|---|
| Message-ID | <20040901123235.Y6745@willy_wonka> |
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
On Wed, 1 Sep 2004, Eric S. Johansson wrote:
> it's clear we must agree to disagree.
=========
no prob... like i said, "in the most respectful way". this is obviously
helping both of us think critically about real-world solutions for
real-world problems... that's a good thing.
> In my world, there is no opportunity to modify desktops.
=========
it would've been entertaining to have been a fly on the wall when they
folded, and accepted that email had to happen on the desktops. i can only
imagine how they kicked and screamed.
> There is opportunity to use an interception box to implement stamped
> mail enterprisewide. There are insufficient resources to stamp every
> single piece of e-mail every single time. E-mail from known recipients
> must be allowed through without subjecting them to content filters every
> time.
============
white-listing a "secret in plain sight" might be the most feasible
solution. just maintain contact with the IT dept of your suppliers,
vendors, etc and keep each other updated as to what outgoing "secret" will
be available.
> like it or not, political considerations come first, human factors come
> second, technical considerations come pretty close to dead last.
===========
i think white-listing a secret in plain sight fits that mold. you can
whitelist using the disclaimer in your supplier's email footer... or the
phone number in your customer's email footer... these things are VERY
unlikely to be in spam. it requires zero effort for end users on both
sides of the transaction... only the sysadmin has to tweak anything. and
you have the technology to implement it now (shell script, batch file,
etc).
> 100 percent stamping is a political nonstarter with serious technical
> problems. This means, that any viable stamping system will consist of
> something approximating stamping, a content filter and a forgery
> friendly white list.
===========
a non-starter is actually ok with me... i'm a geek. all hashcash does is
guide a message past my filter. currently, that makes it easier for other
geeks to not be concerned with my filter.
if it catches on big, that's cool. if not, that's cool too. i'm using it
because it seems like it's valuable for me. in a way, it could be more
valuable if it doesn't catch on....
> Yes, the white list has the same risks as signing only more so because
> you can send messages faster with a plain white list. signatures could
> protect us from simple forgery from anywhere. signatures would improve
> the ability is legal action against spammers (i.e. provable theft of
> data), improve the ability to detect zombie sources and make the machine
> owner accountable.
=============
spammers currently steal service, steal computer resources, and
break-and-enter every single day (that's hardly a full list of criminal
offenses). how often are they prosecuted? i don't think the threat of
using stolen property (a signing key) will deter them. especially when a
valid defense would be claiming that they didn't steal the key, the broke
it. the only law against breaking a key is mathematical, not legal.
spammers have attacked address books and addresses in stored email,
apparently targeting address-based whitelists (like the spam i got "From"
my wife), but they haven't (yet) tried looking for other tokens that a
whitelist can be based on. if you wanted a simple way to whitelist (or
blacklist) my email, you could use the pgp fingerprint in my header of
footer, or the URL for my key...
> so, let's just agree to disagree.
===========
let's also agree to let our adversarial ideologies (to the extent that our
ideologies are adversarial) help us both to come up with things that work,
and understand why other things won't work...
...atom
_________________________________________
PGP key - http://atom.smasher.org/pgp.txt
762A 3B98 A3C3 96C9 C6B7 582A B88D 52E4 D9F5 7808
-------------------------------------------------
"The incidence of disease has increased
in proportion to the progress of science."
-- Akbarali Jetha
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.3.6 (FreeBSD)
Comment: What is this gibberish?
Comment: http://atom.smasher.org/links/#digital_signatures
iQEcBAEBCAAGBQJBNhjpAAoJEAx/d+cTpVciICMIALLcugmsE2qeux7wR+EtRIvY
m7zDDq7a/jDsQxjShwjagSDeah+EmNf4nHKxjNTsSQTO5LftHAzlt8E3yLxdK4A1
cKOfk9WritAMKlsYcEmffotVsxLth5DDnXo9Fi2g/LAQprsUMY3C74uFWQa3wbFl
2vXifNzqNEObPFzX/YxtKs7rvv/2EkSRSu/MuJKsB/mkRvvN2ycLfVqGbEz1x3mI
GjQut9RCINnYvPCfKh5GLbrgdF79KCbv0dU1PybZlYSH+/1zZHvImSPbLS+USf+S
lLD9HMcKp04oTvpPLqXBHjPOf5Kno0IylHeXwuuodiP2vXnp2gleKSRWzdU4eqs=
=uvQV
-----END PGP SIGNATURE-----