Re: Opportunistic signatures - a proposed design

Atom 'Smasher' <[email protected]>
Newsgroups gmane.mail.spam.hashcash
Message-ID <20040901123235.Y6745@willy_wonka>
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

On Wed, 1 Sep 2004, Eric S. Johansson wrote:

> it's clear we must agree to disagree.
=========

no prob... like i said, "in the most respectful way". this is obviously 
helping both of us think critically about real-world solutions for 
real-world problems... that's a good thing.


> In my world, there is no opportunity to modify desktops.
=========

it would've been entertaining to have been a fly on the wall when they 
folded, and accepted that email had to happen on the desktops. i can only 
imagine how they kicked and screamed.


> There is opportunity to use an interception box to implement stamped 
> mail enterprisewide.  There are insufficient resources to stamp every 
> single piece of e-mail every single time.  E-mail from known recipients 
> must be allowed through without subjecting them to content filters every 
> time.
============

white-listing a "secret in plain sight" might be the most feasible 
solution. just maintain contact with the IT dept of your suppliers, 
vendors, etc and keep each other updated as to what outgoing "secret" will 
be available.


> like it or not, political considerations come first, human factors come 
> second, technical considerations come pretty close to dead last.
===========

i think white-listing a secret in plain sight fits that mold. you can 
whitelist using the disclaimer in your supplier's email footer... or the 
phone number in your customer's email footer... these things are VERY 
unlikely to be in spam. it requires zero effort for end users on both 
sides of the transaction... only the sysadmin has to tweak anything. and 
you have the technology to implement it now (shell script, batch file, 
etc).


> 100 percent stamping is a political nonstarter with serious technical 
> problems.  This means, that any viable stamping system will consist of 
> something approximating stamping, a content filter and a forgery 
> friendly white list.
===========

a non-starter is actually ok with me... i'm a geek. all hashcash does is 
guide a message past my filter. currently, that makes it easier for other 
geeks to not be concerned with my filter.

if it catches on big, that's cool. if not, that's cool too. i'm using it 
because it seems like it's valuable for me. in a way, it could be more 
valuable if it doesn't catch on....


> Yes, the white list has the same risks as signing only more so because 
> you can send messages faster with a plain white list.  signatures could 
> protect us from simple forgery from anywhere.  signatures would improve 
> the ability is legal action against spammers (i.e. provable theft of 
> data), improve the ability to detect zombie sources and make the machine 
> owner accountable.
=============

spammers currently steal service, steal computer resources, and 
break-and-enter every single day (that's hardly a full list of criminal 
offenses). how often are they prosecuted? i don't think the threat of 
using stolen property (a signing key) will deter them. especially when a 
valid defense would be claiming that they didn't steal the key, the broke 
it. the only law against breaking a key is mathematical, not legal.

spammers have attacked address books and addresses in stored email, 
apparently targeting address-based whitelists (like the spam i got "From" 
my wife), but they haven't (yet) tried looking for other tokens that a 
whitelist can be based on. if you wanted a simple way to whitelist (or 
blacklist) my email, you could use the pgp fingerprint in my header of 
footer, or the URL for my key...


> so, let's just agree to disagree.
===========

let's also agree to let our adversarial ideologies (to the extent that our 
ideologies are adversarial) help us both to come up with things that work, 
and understand why other things won't work...


         ...atom

  _________________________________________
  PGP key - http://atom.smasher.org/pgp.txt
  762A 3B98 A3C3 96C9 C6B7 582A B88D 52E4 D9F5 7808
  -------------------------------------------------

 	"The incidence of disease has increased
 	 in proportion to the progress of science."
 		-- Akbarali Jetha
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.3.6 (FreeBSD)
Comment: What is this gibberish?
Comment: http://atom.smasher.org/links/#digital_signatures

iQEcBAEBCAAGBQJBNhjpAAoJEAx/d+cTpVciICMIALLcugmsE2qeux7wR+EtRIvY
m7zDDq7a/jDsQxjShwjagSDeah+EmNf4nHKxjNTsSQTO5LftHAzlt8E3yLxdK4A1
cKOfk9WritAMKlsYcEmffotVsxLth5DDnXo9Fi2g/LAQprsUMY3C74uFWQa3wbFl
2vXifNzqNEObPFzX/YxtKs7rvv/2EkSRSu/MuJKsB/mkRvvN2ycLfVqGbEz1x3mI
GjQut9RCINnYvPCfKh5GLbrgdF79KCbv0dU1PybZlYSH+/1zZHvImSPbLS+USf+S
lLD9HMcKp04oTvpPLqXBHjPOf5Kno0IylHeXwuuodiP2vXnp2gleKSRWzdU4eqs=
=uvQV
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.