ietf-asrg
[Top] [All Lists]

Re: [Asrg] Please critique my anti-spam system

2004-12-05 14:05:21
I have developed a system to eliminate spam.  [...] I would
appreciate any criticism you might have, [...]

http://home.nyc.rr.com/spamsolution/An%20Effective%20Solution%20for%20Spam.htm

It has most of the problems of C/R; in particular, early adopters will
end up spamming everyone whose address is forged into spam to them,
just like approximately all C/R systems in use today.  (This is
unavoidable by any system which sends challenges to new
correspondents.)

You claim it doesn't suffer from the problems endemic to C/R because
you "distribute a fully functional email address".  In that case,
spammers harvest a fully functional email address and spam it.
(Whether they harvest it from a webpage or from a correspondent's
address book or whatever is more or less irrelevant.)  It may go away
the next morning when you wake up to a mailbox full of spam, but your
next address is then promptly harvested from your webpage and spammed.
And $DEITIES help you if you put an address on your business card and
it gets scraped from someone's address book; all of a sudden all your
business cards are worthless (or almost), because they no longer
contain a "fully functional email address".

As described, it is completely unusable for the blind, and will not be
as effective at defeating bots as you think - there is some very good
work being done on extracting shape from images, and with synthetic
images such as you describe it becomes duck soup.  (It will defeat
current bots; if it becomes widespread enough to bother, bots will
arise that can defeat it.)  You dismiss the problem of the blind by
suggesting the hire someone to do the work, but you give no reasons why
spammers cannot invest in the same "trifling expense".

The system is completely broken at dealing with correspondents that do
not understand the language the challenge is in (either the text itself
or the picture-part labels).

You are apparently unaware of the work being done to get people to
decode such images by offering them free porn.

Your technique demands fairly drastic changes to outgoing mail
handling.

You take no account of the psychological pressures against C/R.  I
almost always reflexively ditch C/R challenges, and I know I am far
from the only one.

You do not describe any experience with implementations of your system;
your "case studies" appear to be entirely fictional.  Indeed, you give
no reason to think there _are_ any implementations.  No matter how good
it sounds, I am not impressed by vapourware, especially when it has all
the above problems.

/~\ The ASCII                           der Mouse
\ / Ribbon Campaign
 X  Against HTML               
mouse(_at_)rodents(_dot_)montreal(_dot_)qc(_dot_)ca
/ \ Email!           7D C8 61 52 5D E7 2D 39  4E F1 31 3E E8 B3 27 4B

_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg