4 ms·
Every solution needs to be robust in the presence of an adversary who is more technically savvy, motivated, organised, numerous and dedicated than an average us
by erpellan 8y ago
Every solution needs to be robust in the presence of an adversary who is more technically savvy, motivated, organised, numerous and dedicated than an average user. That's why it's really hard. Any tool you give an individual to protect themselves can be turned against them by an army.
- naasking 8y agoThat's why white/blacklisting and similar measures will never work. What you need is proper delegation with an incrementally built web of trust. Instead of your email address being a human-readable public address, it should be a revokable cryptographically unguessable address that's unique to each person to whom you're introduced. Introductions happen via a protocol which generates a new address given to that person, and you then assign a purely local pet name you use to refer to them [1]. Given any generated address, you can trace back the history of introductions that led to it. This very clearly solves spam problems since it completely upends the traditional approach with a bottom-up solution. I'm not sure anything else could be immune to abuse to the same extent though. [1] https://en.wikipedia.org/wiki/Petname https://en.wikipedia.org/wiki/Petname
- yorwba 8y agoI think distributing the work of verifying new accounts as non-spammers to over all existing users is the only way a social network can grow without losing to the spammers or overloading their human moderators, so I like your idea. But how do you solve the problem of people wanting to join who have no existing contacts in the network to invite them? Most likely they would use some other channel to request an invitation from a stranger and hope that they'll grant them access. If that happens, then it dilutes the power of the web of trust. A spammer could manually create a bunch of accounts in the same way, and then use them to grow botnets at the edges of the web of trust. If only a few bots are used to spread spam, it would take a while to accurately determine which part of the network is controlled by the spammer.
- naasking 8y agoBut spamming has no power in this system. You can collect a huge list of addresses, but as soon as you abuse them once they would be revoked. One-time spamming isn't a viable business strategy. The bootstrap problem is indeed challenging with this approach. Normally you could connect with people you know in real life using an NFC or QR code exchange, but social networks have created an expectation of being able to find people by searching an open directory. That's a spammers dream. As soon as you can send a friend request that's just reintroducing open addressing. I haven't spent much time thinking about this since I rarely use social media, but my first thought is that you voluntarily join some groups and find people that way, ie. High school groups, etc. Perhaps friend recommendations by randomly asking existing members could be used to very the validity of newcomers.
- zrm 8y ago> I'm not sure anything else could be immune to abuse to the same extent though. There are multiple solutions that work if you design the system that way from the outset (which is the same issue yours has). One was suggested above. You can have a human-readable public address but the first time a message is sent the sender has to commit $1 (or however much is necessary as a deterrent). If the recipient approves the message you get it back right away, if they ignore it you get it back in 30 days, if they mark you as spam you lose the money (and you know this and know that sending them more messages will be expensive). Then if you send a message (including a reply) to someone it automatically (but revokably) whitelists them, and whitelisted peers don't have to commit money to send to you. This also works for mailing lists, because then you subscribe by sending a request message, which whitelists the mailing list, and then they don't have to hold a huge reserve as long as they only send messages to people who actually asked for them. But none of that works for email because it wasn't implemented that way originally and it's hard to change it now.
- naasking 8y ago> You can have a human-readable public address but the first time a message is sent the sender has to commit $1 (or however much is necessary as a deterrent). Requiring payments destroys the anonymity though, that's why I don't like it. > But none of that works for email because it wasn't implemented that way originally and it's hard to change it now. Actually, my system can be adapted to email but you have to give up typing in email addresses manually. Most people don't do that anyway, so no big loss.
- zrm 8y ago> Requiring payments destroys the anonymity though, that's why I don't like it. Isn't that what all of this Bitcoin and Ethereum is supposed to be good for? > Actually, my system can be adapted to email but you have to give up typing in email addresses manually. Most people don't do that anyway, so no big loss. Don't they? People put email addresses on business cards and billboards and things like that. That's where you would need people to upgrade -- the fix would be to use QR codes but then you need everybody to support that (and understand what to do with it). Of course, people who have their own domains have long been doing something similar but with human readable names. You have example.com so you can create foo@example.com, bar@example.com, a hundred names for a hundred services. It would also be possible to do this with subdomains. So if you were bob@gmail.com, gmail could theoretically let you create aliases like foo@bob.gmail.com and use it for your business with Foo Corp. They do let you do something similar by ignoring dots in the address, so john.smith@gmail.com is automatically an alias for johnsmith@gmail.com, but if you use dots in different places for different activities then when one of them starts getting spammed you discontinue it and add a rule to trash everything sent to that alias. The inconvenience there is it's harder to remember what you used each variation for (and which ones you've already used) when it's time to rotate.