4 ms·
Even proof of work has a flaw. It underestimates some of the drive of these people to make make a few bucks. How much would say 200 raspberry PI's cost to net
by sumtechguy 6y ago
Even proof of work has a flaw. It underestimates some of the drive of these people to make make a few bucks. How much would say 200 raspberry PI's cost to network up? For proof of work to 'work' you need to get past the cost they would make on it. All you are doing is slowing them down which they can make up in volume of cheap devices. It does not 'solve' it. I have seen them setup rooms of low end Android devices to do things. This is not out of the realm of possibility.
- LinuxBender 6y agoTo add to this, you don't need any raspi's. Most spam today comes from malware running on PC's not owned by the spammer. All they need is a software library that does this math and 100% of the CPU cost is on the malware victim. The software library would have to already exist and be available to everyone or this concept would never be adopted, which means that the spammer gets this for free. They just have to plug the library into their malware. The only cost that would be forced onto spammers would be if the PoW used signed individual keys that could be revoked if abused.
- tboyd47 6y agoCheap, but not free. If it means that a spammer can send 100 emails before marked as spam instead of 10,000 or 100,000, it changes the landscape for sure.
- LinuxBender 6y agoIf the spammers implement PoW, I am not seeing how the numbers change. Instead of seeing for example 1 million infected PC's and VM's sending email, you would see 1 million infected PC's and VM's doing PoW. Ill give you an example of how this played out in the past. Up until about a decade ago, if I enforced TLS on my mail servers, about 80% of the malware bots could not connect as their libraries did not support TLS. As more smtp libraries added support for TLS, the malware was updated and now enforcing TLS only limits a smalll subset of spammers. There was no added cost to the spammer. So yes for a while, PoW will create a window of time where there is less spam for those that adopt this. The spammers will eventually catch up. Nowadays malware frameworks are much easier to update.
- sumtechguy 6y agoThe diff for a spammer of 100 boxes that run their bot vs 1000 makes no difference to them. The cost is negligible. Even if you make the process slower. They can just scale out or wait it out. If it takes 1 hour vs 2 hours to do their payload there is no real difference to them. They have also already built in the filtering as a % that fails. They are looking for less than 1-2% success which is all they need. The frameworks are no longer some simple script hacked up in VBS. They are packages they can buy from other spammers or rent the bot net with the proper libs built in.