ietf-asrg
[Top] [All Lists]

Re: [Asrg] A response to the critique of my anti-spam system]

2004-12-13 14:30:12
I have several objections to your system, which I have not seen you
respond to.

1) I am in charge of a fairly popular web-accessible database, which requires
   a password for access.  Sometimes people will forget their password, but
   then they can type in their ID number and have the password sent to the
   e-mail addresss they provided when they registered.  This is a fully 
   automatic process.  If those users were using your system, my mail to
   their address might well bounce, as the address hight have become
   invalid.  I am not willing to accept the extra burden of processing
   those bounces, and I assume the same will be true for many others who
   maintain a similar system, and this might mean a significant
   inconvenience for anyone actually using the system - a system which
   involves brealing a number of existing systems will not be popular.

2) Your mails might look like spam to some spam filters - there are
   filters that notice the transmission of a large number of substantially
   identical messages and attachments, and automatically learn to
   identify those mails spam.   This will happen quicker if your
   system ever responds to a forged mail address which happens to be
   a spam trap.  There are systems that will consider anyone who mails
   to a spam trap to be a spammer, and censor all future mail from that
   user/server combination.  Basically, what I am saying is that your
   system is just not compatible with some existing anti-spam solutions.

3) Your system does not work at all for addresses which people expect to
   find like "postmaster", "webmaster", "sales", "support", "info",
   "abuse" and so on.  People are just not going to appreciate a message
   telling them to use a different addres - in particular if it arrives as
   a graphical attachment.

4) Old e-mail addresses never die.  I am still receiving the occasional
   spam to an address I used ONCE to post a Usenet message back in '89.
   That address is now redirected to a spamtrap and working nicely as
   such.  Now, if I started constantly switching e-mail addresses, I would
   eventually be receiving multiple copies of every spam message - one 
   or more to each address.  This would just mean increased load for my 
   server, and as I have to pay for my incoming traffic, I do not 
   appreciate tht increase.  

You also asked what I meant by a typical user.  Some people cannot use this=
system such as certain business people, people who insist on keeping an ac=
tive email address in an easily harvested form on website, or people who ar=
e afraid of being cut off from correspondents who use a graphics incapable =
email system. 

Also include everyone wanting to participate in a public discussion board,
Usenet group or any other similar servide which publishes your e-mail.

In fact, just about the only ones who could use the syetem are those who
can keep their e-mail address secret - but even that does not work in
practice unless they never send out mail.  E-mails will get out and
spammers will harvest them.....no matter what.

-- 
Fridrik Skulason   Frisk Software International   phone: +354-540-7400


_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg


<Prev in Thread] Current Thread [Next in Thread>