8 ms·
Spam is also a problem. How do you do spam detection if you cannot read the message?
by bluecmd 11y ago
Spam is also a problem. How do you do spam detection if you cannot read the message?
- irixusr 11y agoA few years (almost two decades!!!) when the filters weren't as good I read a proposal to make an email system that charges $0.01 to the sender. Spammers would be bankrupt. It was difficult to implement and up against an already entrenched tech. With Bitcoin I've been thinking of that idea again. Could a payment system on top of existing email be created? The receiver of the email could get the senders penny and Bitcoin might get a killer app that doesn't involve drugs...
- derefr 11y agoIt could be even more convenient, if it only charged for unauthorized contacts. Emails back and forth between friends/coworkers? No charge. Email newsletter you signed up for? One-time cost to them to send you the opt-in message. Random spammers? Never get authorized; have to pay every time. It would also put a slight amount of friction in place for contacting people out-of-the-blue (when e.g. sending fan-mail to famous people)—but the fact that some stranger paid $0.05 to say something to you could also make you just fractionally more interested in what they have to say. On the other hand, for accepting bug reports, help tickets, etc., there'd have to be some kind of email equivalent to an "800 number", that is free to initiate contact with. Either that, or a lot of behind-the-scenes pairing magic to get your email address into the directory service of all the products and services you use.
- irixusr 11y agoYou're assuming people want to be contacted by people in their address list :D For me there's an annoying aunt who periodically send the latest get-mad-at-this email. Or, how many times do we receive a mass email from friends who use CC instead of BCC and then we're flooded by everyone's replies? If you're in my address book, then you should be charged more!
- derefr 11y agoThe difference, I think, is that you can at least apply individual filtering to the problems of annoying aunts and mass-emailing friends, of the same sort as you see with Facebook's "remain friends but unfollow" option. Spam is hard because there's no manual filter you can write that targets "everyone you don't know", without removing the ability to be reached-out-to by real people who have a genuine desire to tell you something you care to hear.
- colechristensen 11y agoIt's pretty simple, create an email client and/or server which bounces emails from new addresses indicating delivery costs 1¢ paid to the receiver.
- kpcyrd 11y agoObligatory: http://craphound.com/spamsolutions.txt http://craphound.com/spamsolutions.txt
- irixusr 11y agoLove it. But seriously, does it still fail if I have a local filter were I strongly prioritize emails of ppl who show up on the BC ledger? If ppl in high tech start doing this to lower their own email burden, I can envision normal business ppl copying the technique to lower their own.
- scintill76 11y agoOr use Hashcash, which is a proof-of-work algorithm created for anti-DoS and anti-spam, and the inspiration of Bitcoin's mining algorithm. It's possible the botnets are strong enough to create Hashcash or mine Bitcoin and still spam enough to annoy us... and it would probably take either Google, Yahoo, or Microsoft announcing they would stop accepting legacy emails (where "legacy" could just be ones without Hashcash or BTC), for anyone to make a change.
- bad_user 11y agoSMS messages are somewhere around $0.01 to $0.04 for sending in bulk, depending on region. Doesn't stop spammers. And a fee will also never, ever fly for email, being not a matter of entrenched tech, but rather one of artificial scarcity, being the reason for why SMS is dying.
- irixusr 11y agoThe artificial scarcity argument is interesting, but I don't think it applies here. I'm not proposing paying a third party to send me email. You'd be paying me for my scarse resource - my time and inbox space
- deleted 11y ago[deleted]
- tkinom 11y agoIf you have the public keys of all senders, one can easily white/black list the known known/non-spammers. All the undecided goes into just one folder. Probably not be that hard to sort out.
- peterhunt 11y agoThis is actually very hard to sort out and is a deal-breaker for end-to-end email encryption. https://moderncrypto.org/mail-archive/messaging/2014/000780.html https://moderncrypto.org/mail-archive/messaging/2014/000780....
- mattmcknight 11y agoBut why would you need the sender's key? They need to encrypt with your public key, which you only provide to a limited list, and change when it gets blown. What we need is an automated way for requesting someone's key, approving or disapproving that request, and then storing their key for future use....in gmail.
- devit 11y agoDo spam detection on the local machine, although unfortunately it will performs worse.
- mtgx 11y agoClient-side.
- dredmorbius 11y agoMost spam isn't encrypted. The overhead's too high. Behavioral methods might still work, particularly whitelisting/greylisting. Whitelisted senders will be passed, greylisted ones filtered. Spam can still be filtered locally with a key, if necessary, though that misses the leverage of delivery-time notification. A notify-and-fetch dynamic might also work. Rather than delivering messages at send time, a notification that there is a message is sent, an on its strength, the message is later requested. Spammers have a much larger mail storage problem. Whitelisted senders might have mail delivered automatically. And collaborative spam filtering could mark and downrate spammer reputations before many recipients get to requesting the message, sparing them the spam. Greylisting / teergrubing / delayed receipt (even just 1-2 retry intervals) cuts down much on spam as well. Play the costs. There are also distributed anonymous reputation systems, designed mostly for Tor / Web, though similar concepts for email might work. FAUST and Fair Anonymity: https://gnunet.org/node/1704 https://gnunet.org/node/1704 http://arxiv.org/pdf/1412.4707v1.pdf http://arxiv.org/pdf/1412.4707v1.pdf
- Panino 11y agoA Spamhaus DNSBL alone drops 99% of spam with almost no FPs. Add DROP, fullbogons, and greylisting to increase the percentage further. None of these methods read the message body, and there are plenty of other options as well. I self-host and receive about 5 spam messages per year, all without looking at the message body.
- ryanlol 11y agoI'm not sure if you know how spamhaus DNSBL works, "no FPs" is ridiculously far from the truth. They make it near impossible for bigger hosts not to get blacklisted unless they fully comply with spamhaus.
- DanBC 11y agoDo you have any cites for this? Everything I've seen suggests that Zen has a very low false positive rate. That's the point of Zan - block a decent amount of spam and no real email so that your slower better filters can work.
- ryanlol 11y agoSpamhaus has a history of extorting larger ISPs into dropping their customers instead of just blocking said customer. https://www.virusbtn.com/blog/2011/10_13.xml https://www.virusbtn.com/blog/2011/10_13.xml It's worth noting that spamhaus had no real reason to do this as they had already blocked the hosting company a2b was providing bandwidth to, so blocking all of a2b didn't actually stop any more spam. Zen is far far from not blocking any real email, they regularly block large ISPs that refuse too indiscriminately drop customers on their request.
- DanBC 11y agoFrom your link: > Update: Spamhaus has now commented on the case in a blog post, explaining how Cyberbunker (also known as CB3ROB) has been involved in hosting malware and phishing sites. Ironically, this very week Spamhaus has been working with the Dutch hi-tech crime unit to investigate the criminal activity hosted by Cyberbunker and routed by A2B. This is really your example of false positive blocking?
- escaped_hn 11y agoMake encrypting an email cost something. not necessarily money. kinda like minimg bitcoints but instead of getting bitcoins, you get to encrypt and send an email.
- phire 11y agoAs in, each email requires a bruteforced hash that takes about half a second to calculate on a desktop CPU, before it will be accepted by the mail server? That's actually the best idea for spam reduction I've heard so far (which is not really saying a lot). Half a second won't be noticed by a normal user, but it will be noticed by people sending thousands or millions of emails. Sure Spammer will install large GPUs hashing rigs and still manage to send thousands of emails per second, but it would cost them a lot more than it does now. One problem will be phones, a hash that takes about half a second on a desktop will take tens of seconds on lower end mobile phones, which is hardly unworkable but you could offload the calculations to a 3rd party server (with a large GPU based hashing rig) for say a fraction of a cent, especially if the email contents were encrypted by the phone before hashing. And it could be introduced without breaking the email system. Initially the presence of a hash will just be used as an additional spam filtering signal, but as support grows over time you can make it harder and harder for emails without a hash to get through. Like bitcoins, you would need a mechanism to increase the required work over time, though it could just be ad-hoc based on what mail server operators choose to accept.
- drblue 11y agoYou may want to take a look at hashcash[1]. It was a proof of work scheme for email invented in the late 90s, and they claim it was adopted by bitcoin[2]. (Sadly, it never caught on for its 'intended' purpose.) [1]: http://www.hashcash.org/ http://www.hashcash.org/ [2]: http://www.hashcash.org/bitcoin/ http://www.hashcash.org/bitcoin/
- Sanddancer 11y agoThe problem I can see there is with legitimate large mailing lists. Think security announcements, etc. Putting a burden like that on smaller teams, or teams without a lot of funding, could prove problematic.
- mattmcknight 11y agoDon't give your public key out freely.