ietf-asrg
[Top] [All Lists]

Re: [Asrg] Collecting IP reputation data from many people

2010-10-21 09:53:36
On 10/21/2010 1:05 AM, der Mouse wrote:

I would warn you against inferring from successful preliminary tests
that it would be equally successful if widespread; there are zillions
of techniques that work fine provided few enough people do them that
spammers don't notice or don't think they're worth bothering to
circumvent.  (I depend on a few myself.)

I think it's worth pointing out that _everybody_ does to one extent or another. Anti-spam is like security in general. No protection is absolute. You're always relying on setting the bar high enough to not being worth the ROI. Part of that equation is trying to avoid being too much alike someone else who it _is_ worth bothering with.

IOW: don't make yourself too much similar to Hotmail, Gmail or AOL, because the incentives to break them are far higher than "little ol' me", and if they get broke, you're toast.

I'm with der Mouse. I'm not sure you're going to be able to build a prototype with broad enough reach to derive useful conclusions, and if you do manage that and it starts to become more broadly used, you'll become a target with entirely new massive problems to solve. I know there are things that can help, but I think you'd get swamped so badly that even, say, 99% suppression of malicious (and just dumb) input won't be enough to yield a useful signal.

Also like der Mouse, I think it might a useful instructive exercise. But be prepared for the exercise proving itself to you that it won't work and why. And please publish the result, at least here.
_______________________________________________
Asrg mailing list
Asrg(_at_)irtf(_dot_)org
http://www.irtf.org/mailman/listinfo/asrg