4 ms·
Here's the fix to e-mail: Centralization. You can't curb abuse in a federated model. This is an issue that's been plaguing the fediverse as well. IRC networks,
by beefhash 6y ago
Here's the fix to e-mail: Centralization.
You can't curb abuse in a federated model. This is an issue that's been plaguing the fediverse as well. IRC networks, though not federated, have had to each individually ban spammers and other problematic users.
Google (GMail), Yahoo, Microsoft (Live/Hotmail), Yandex, QQ Mail. That ought to be enough for everyone. EDIT: and mail.ru
- CodesInChaos 6y agoI don't know QQ Mail. The rest doesn't allow anonymous signup, which I consider essential for privacy. Google&co extort a phone number if they don't have enough tracking information about you and yandex shadow bans you (you can login, but don't receive any emails).
- wyxuan 6y ago> Google&co extort a phone number if they don't have enough tracking information about you and yandex shadow bans you (you can login, but don't receive any emails). Uhh no. Its for anti spam. Imagine if someone created a bunch of email addresses in one go without the phone requirement. You could abuse the 15 gb per account allocation pretty easily, or you could use those emails for spamming others.
- AnthonyMouse 6y agoIf that was it then they would only require a phone number after there has already been a new account creation from your IP address that month, or support any number of alternative rate limiting strategies that don't have the same privacy implications. Any website that requires your phone number is doing it for tracking purposes. Which is the same reason why you should never give it to any of them.
- ckwalsh 6y agoMy ISP gives me a dynamic IP. I could turn off my router for a few minutes and be someone "brand new". Or I could use IPv6 (if my ISP actually invested in it), and have every web request use a different IP. The only surefire way to curb abuse is to make sure the abuse is not cost effective for the abuser. For spammers trying to make a buck, make it so it costs them more to send their spam than the value they reap from it. For non economic spammers (politics, trolls, etc), it's a lot harder, but there's always some price that it becomes not worth it for their influence/"fun". This was the approach Bernstein was trying to do, but based on the article it sounds like he underestimated the cost of storage as technology improbed. The hard part is adding this cost in such a way that does not drive away or punish real users. An email system that costs $10/month isn't going to be used by many spammers, because any reasonable administrator will ban obvious spam and they won't get their $10 to cover costs before being shut down. But it also limits the customer pool; most people are not going to pay $10 a month of email when free services are available. Phone numbers are definitely not perfect, but they are trying to solve the problem of "What do most people have and would not invoke any additional cost on them, but would invoke additional cost on spammers?" Yes, phone numbers are relatively cheap, but there is still some backtracing/ownership checks that can be performed, and ones from more "trustworthy" blocks will still cost a buck or so. Suddenly spammers need to make at least a $1 from the account or they are losing money. Domains are another way spammers are often dealt with: if it costs $10 for a domain, you have to make $10 from the domain before it is blocklisted, or again, you are losing money. I can't think of any myself, but if you have any ideas for a model with comparable high costs to spammers but low cost to real people, that fulfills your privacy expectations, I'm all ears. However, costs generally are better enforced in a more centralized model as opposed to a federated/privacy respecting model, so I suspect it will be incredibly difficult to find a solution that actually enforces the appropriate economic goals.
- zelphirkalt 6y agoI would like to know how it is done at protonmail, where, last I checked, one does not need a phone number to register an account.
- beagle3 6y ago> Or I could use IPv6 (if my ISP actually invested in it) and have every web request use a different IP. But you'd be using the same prefix, which I'm sure some good soul would map, so you anyone who cared would correlate all of your accesses just as if you had a fixed IPv4
- CodesInChaos 6y agoI have a 10 year old gmail account. Every time I log in (from a residential IP) there is a 50% chance that it'll reject me despite entering the correct password, demanding a phone number. > Its for anti spam. Imagine if someone created a bunch of email addresses in one go without the phone requirement. You could abuse the 15 gb per account allocation pretty easily, or you could use those emails for spamming others. That may be the goal. But it also makes using the internet anonymously very hard, since getting a phone number are linked to real names in my country. There should be less invasive solutions, like rate limiting sending of emails from new accounts.
- nix23 6y ago>using the internet anonymously Use: -Protonmail not Gmail -Swisscom myCloud not Drive -Neocities not blogger -Matrix (Element) or Signal/Wire not Talk/Whatsup/etc
- threentaway 6y agoI don't think so. We could win so much of the spam fight by just making signed messages mandatory. Would there still be some spam? Sure. But it's better than handing over all email to a few select companies.
- AnthonyMouse 6y agoThe problem right now is that big email providers commonly regard all of your email as spam even if it is signed.
- luckylion 6y agoA lot of the spam these days is being sent via hacked computers. You'd get signed emails from individuals, only those individuals wouldn't know they are sending them. It's the same problem with DDOS. Some providers tried to mail out letters "hey, your computer is involved in malicious things, please get it fixed", but that just lead to a lot more support requests that the ISPs can't handle. So we just accept that botnets are a thing.
- upofadown 6y agoIt is unlikely you would know the people that had the hacked computers. So that case would be the same as no signature at all. Otherwise the spammers could just make up their own valid signatures.
- Lex-2008 6y agohey, can you please add mail.ru to the list above?
- feanaro 6y agoNo, the poster already said the above should be enough for anyone. /s
- Animats 6y agoIn China, your national ID is required to get a phone, and when you sign up for WeChat, that identity is tied to your WeChat account, and then to your bank account. That's the centralized solution. Soon, the US will have "Real Americans have a RealID". That was supposed to turn on next month, but it's been put off for a year due to the epidemic.
- swiley 6y agoMeh. I’m not bothering with “RealID.” I live somewhere that driving isn’t required so I don’t need an up to date drivers license and I very rarely fly anyway. I’m sure I won’t be the only person doing this. I’m hoping (and reasonably hopeful) that some lawsuit will nerf it before I ever actually need it. Many people already argue it’s illegal.
- vulcan01 6y agoMany people in the US (if they can afford one) will continue to drive a car, RealID or not. You're in the small minority...
- incompatible 6y agoIt seems like it's still a federated model, or will you only be able to send Google mail to another Google user? I suppose the joke is that email has already evolved into this model, for most people.