ietf-asrg
[Top] [All Lists]

Re: [Asrg] Please critique my anti-spam system

2005-01-09 10:19:07
No it would not be. You can't have it both ways. On one side, you
say it would be cheap to decode CAPTCHAs by an army of human beings,
but now you say it would be expensive to decode CAPTCHAs by an army
of human beings.

The legitimate list-owner has to handle 1,000 CAPTCHAs a week (for a
huge list).  That's $1.00.

The spammer sends 100,000,000 messages per week.  That's $100,000.

No. The CAPTCHA based addresses are worth much more than an ordinary
address. The CAPTCHA addresses don't filter spam, mail sent to them
are guaranteed to be seen prominently by the recipient. So a spammer
only needs to send 1000 spams to find a gullible person who'll respond.

These CAPTCHA based addresses are nearly worthless as compared to an
ordinary email address.  A spammer can use an ordinary email address 
for years.  A spammer can pay 0.1 cent to have a sub-address decoded
but the receiver will almost certainly deactivate this sub-address after 
the first time they receive spam.

Also there is no concern that any service that decodes the CAPTCHA on
behalf of a commercial entity will then secretly sell the list to spammers.
Paypal could have a company decode 20,000 of these CAPTCHA.  If this list was
given to spammers then it would be instantly obvious what happened after
the Paypal customers instantly deactivate these newly decoded sub-addresses
in response to spam.  The customers would also know that the spam was sent
using a sub-address sent to Paypal; go see Reflexion.net and how each email
will list the original owner of the sub-address whenever that sub-address is 
used
by an unknown entity.

Michael Kaplan
-- 
_______________________________________________
Find what you are looking for with the Lycos Yellow Pages
http://r.lycos.com/r/yp_emailfooter/http://yellowpages.lycos.com/default.asp?SRC=lycos10


_______________________________________________
Asrg mailing list
Asrg(_at_)ietf(_dot_)org
https://www1.ietf.org/mailman/listinfo/asrg