Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Spam

Would you Warranty Your Email? 395

Kurt writes "A team from the University of Michigan is proposing an economic solution to spam. Instead of relying on technical solutions or government regulations, they use a sender warranty system. In some cases, they argue, it can even be superior to a perfect filter with zero cost, and no errors. Their working paper is available at SSRN. With the caveat that some infrastructure is necessary (isn't it always?), they also claim their approach restores control to the recipient, halts spam, and creates a marketplace for valuable information exchange."
This discussion has been archived. No new comments can be posted.

Would you Warranty Your Email?

Comments Filter:
  • by inertia187 ( 156602 ) * on Friday February 06, 2004 @11:50AM (#8202444) Homepage Journal
    I wonder how well this would work if everyone on Slashdot could warranty their posts. It could be implemented by adding a checkbox next to Post Anonymously, call it Post With Warranty. Your comment then gets bumped up to "+5, via Warranty." If people think it's not worthy of being +5, and they have mod points, they can moderate it down. If they mod it down, they take subscription points from the poster. If the metamoderator disagrees, the moderation is reversed as expected *and* the subscription points are returned to the poster.

    I think this could work. But it sounds like a pain to implement.

    (fp)
    • The problem is, there are a TON of moderators that will go and mod-bomb people because they don't like them, regardless of how well-reasoned their post is. Posts are supposed to be moderated, not individuals, but that's not how a lot of people do it.
      • Personally, I treat slashdot like the rest of the internet. you all are a faceless lot of text for my consumption :-)
      • by Josuah ( 26407 ) on Friday February 06, 2004 @12:29PM (#8202899) Homepage
        The problem is, there are a TON of moderators that will go and mod-bomb people because they don't like them, regardless of how well-reasoned their post is. Posts are supposed to be moderated, not individuals, but that's not how a lot of people do it.

        Then does starting at +5 and going down really make a difference from starting at +1 and going down, in that respect?

        Two problems I can think of: reading at +5-only becomes just as bad as reading at -1 until enough moderators run through the _entire_ thread culling out the stupid. The penalty for "voiding your warranty" (as proposed by the parent-parent) isn't worse than getting modded down regularly.

        Possible solutions? Warranty puts you up to +X where X is a preference setting. Maybe the default threshold you read at. People who have liked what you said in the past will see you at +X+1 (friend/foe system). The first mod-down removes the warranty completely and pushes the post to +Y where Y is what the poster would have posted at without warranty.
      • by Anonymous Coward
        The problem is, there are a TON of moderators that will go and mod-bomb people because they don't like them, regardless of how well-reasoned their post is

        Who are these mod-bombers? I mean, what does it take to earn the wrath of people on Slashdot? Who takes Slashdot that personally?

        Myself, if I've got mod points, I mod up when I find value to the post, I mod down if I feel it's overrated, and very rarely I'll mod down for other reasons.

        How do these mod-bombers get mod points? doesn't the meta moderation
      • Mod parent down. :-)
      • I thought that's what the point of M2 was? If an M2 "unfair" will reverse the penalty, then what we really have is a problem with M2, not with moderators. Obviously M2 would have to be tweaked with, but so would normal moderation. Isn't that what they alwasy say? It's not perfect, but it works well enough?
      • by gosand ( 234100 ) on Friday February 06, 2004 @01:06PM (#8203392)
        The problem is, there are a TON of moderators that will go and mod-bomb people because they don't like them, regardless of how well-reasoned their post is. Posts are supposed to be moderated, not individuals, but that's not how a lot of people do it.

        And yet, there are moderators who will mod down anything that goes against the "geek norm", regardless of content. On some recent thread about movies, I posted what I thought were reasons why LOTR-ROTK was just a good movie and not fantastic. I was modded as a troll faster than you can download a picture of Natalie Portman. See for yourself [slashdot.org] Now granted, I didn't go on in great length about my points, but I still think that if you can let go of the fanboy fanaticism and look at it honestly, what I said holds. I was by no means trolling.

        The problem with moderators is that meta-moderating is just a little-too-late. And even if it did work well, it wouldn't be able to stop biased moderating. Or it would plunge it into the void of predictable moderating. Or are we already there? There is a mod of "Troll", but not of "Karma Whore".

        • by Vellmont ( 569020 ) on Friday February 06, 2004 @01:55PM (#8204098) Homepage
          I've noticed the same thing. If you attack peoples cherished beliefs (LOTR is the greatest movie EVAR!, Macintosh is Sup3r k00l) people will hate you.

          Personally I think there should be a special "controversial" tag to a post. It doesn't give points one way or another, but identifies posts where (gasp) you might not like what the person is saying! Those are often the posts I want to see, not the same old opinions rehashed over and over. You could then set up a +3 to posts marked "controversial", or if you're an establishment type and don't want to hear anything that challenges your views, you mark it down -3.
          • by 4of12 ( 97621 ) on Friday February 06, 2004 @03:08PM (#8205284) Homepage Journal

            where (gasp) you might not like what the person is saying!

            I find this is where MetaModeration enters the picture for me.

            Moderating, I get so few points (how are you ever going to do a good moderating job with just 25 points, I mean) that I'll use them up quickly, mostly doing +1 on well-written, well-reasoned posts that I agree with, and maybe 10-15% of the time pushing trolls and flamebaits down into the basement.

            But Meta Moderating I've re-inforced +1 ratings that other Moderators have given to well-written comments that oppose my own views.

            Is there anything more boring than listening to like-minded people? Are we so insecure that we need constant ego inflation that "we're right. we're good. we're valued."?

            • by Reziac ( 43301 ) on Friday February 06, 2004 @06:10PM (#8207702) Homepage Journal
              Are we so insecure that we need constant ego inflation that "we're right. we're good. we're valued."?

              Actually, yes -- that, in my observation, is the quintessential geek psychosis, for geek types who don't have a life outside of "traditional" geek pursuits.

              It's whence comes that ivory tower perspective we've all seen from [insert-OS-here] bigots. It's what fuels the idea that there are geeks and lusers -- that is, someone to feel superior to (meaning anyone who doesn't share the geek's understanding of the topic, or who might, gods forbid, disagree with the Approved geek opinions.)

              Not to pick on geeks, since the same mindset appears in other specialty fields as well, but most other fields don't so actively select for this narrow-minded bigotry by not only publicly roasting nonconformists, but also thinking it's perfectly good social behaviour to do so.

              IOW, kids who bully in meatspace can usually be made to feel embarrassed about it afterward. Hereabouts, the response to being called on such behaviour is "But he's a moron, and he deserved it!"

              As to "warrantying my posts" or my email or anything else that falls out of my brain -- as slashdot so amply demonstrates, ANY system that relies on anyone's opinion of what's worthwhile or not is going to apply unfair pressure against whatever is currently perceived as dislikeable, unworthy, or defective. Survey-taking outfits recognise that those who are willing to take surveys already have certain biases, and they allow for this bias when parsing survey results. That's a bit harder to do in an uncontrolled environment, where bias is applied by those deciding what's worthy or not.

              BTW, I never mod down -- that would be a waste of mod points.

      • Actually, mod-bombing works for a while, as I discovered. Then, suddenly, you're no longer given the ability to mod. I got ticked at someone and mod-bombed them for a few weeks. Then it all came to a sudden end about 2 years ago and I haven't been able to mod since. Oh well.
    • by FileNotFound ( 85933 ) on Friday February 06, 2004 @12:07PM (#8202653) Homepage Journal
      You would need to record the moderator and make him visible in such a case.

      This way any mod bombing would be obvious. Since you are taking a direct financial loss due to poor moderation, you need to know 'who' is causing it.

      Kinda like you can't sue people anonymously.
    • by milkman_matt ( 593465 ) on Friday February 06, 2004 @02:32PM (#8204689)
      I think something you could add to this plan to fight abuse is -- If someone mods it down, they guarantee that that's what they want to do by agreeing that if the moderation is reversed, it takes THEIR subscription points to repay the person who's points were originally taken?

      -matt
  • by ka9dgx ( 72702 ) * on Friday February 06, 2004 @11:52AM (#8202459) Homepage Journal
    I favor an alternative approach, which the authors concede has some merits, but quickly dismiss, sender authentication.

    If I start rejecting all email which is not from a verifiable sender, I'll quickly cut spam, and impose some costs onto those who wish to sent me email. I'm willing to pay those costs when it becomes my turn to send an email. I would start with the recent authorized sender protocols, in addition to Public Key Infrastructure, to begin to authenticate a sender.

    Once PKI starts to take hold, there would be an incentive for the spammers to start creating throw-away identities, which we could counter with a reputation system for the sender's domain. We could also create a "web of trust", automatically managed by our mail servers, or ourselves, to nip the counteroffensive.

    So, there it is... my alternative... sign and validate all email.

    --Mike--

    • The worst part about all this is that suddenly everyone who writes an email is required to be identified.

      Email is one of our last few partially anonymous methods of communication. Emailing (and posting) as "Anonymous Coward" is a seriously useful thing and taking it away from people will probably be more disasterous than originally imagined.
      • Hotmail (Score:5, Insightful)

        by cgenman ( 325138 ) on Friday February 06, 2004 @12:27PM (#8202878) Homepage
        Email is one of our last few partially anonymous methods of communication. Emailing (and posting) as "Anonymous Coward" is a seriously useful thing and taking it away from people will probably be more disasterous than originally imagined.

        There was some drama recently around an anonymous e-mail communication this past few weeks at my roommate's place of employ. What did the sender use? Hotmail.

        Hotmail, yahoomail, and other free mail services use ciphers to identify people as human beings, and track IP's to resist automated signup scripts, but the medium is still essentially anonymous. Except for the IP address of the sender, which can be masked via a little wardriving or a trip to the library, the system is as anonymous as the sender wishes.

      • by gcaseye6677 ( 694805 ) on Friday February 06, 2004 @12:34PM (#8202947)
        Anonymity vs. accountability is always a tradeoff. If it is easy for anyone to send emails without disclosing their identity, this can have its advantages. But if they start spamming, how will you stop them? People should have the option of receiving only email from trusted sources, which can pretty much eliminate spam for them. They can easily filter out any source they do not wish to receive from. Someone who is not comfortable with this idea can always choose to receive from anyone and then use appropriate filtering techniques that work for them. Its kind of like setting your slashdot filters. You can choose to include everyone, or you can filter out ACs, low rated posts, foes, etc. You could even choose to only read posts from people you trust, if that's your preference. Having a moderation type system for email, combined with other filtering systems, is by far the best way to cut down on spam.
      • by Phillup ( 317168 ) on Friday February 06, 2004 @12:51PM (#8203207)
        Whoa there partner...

        You are only required to be identified if the receiver requires it .

        While you have every right to "free speach"... you have no right to force someone to listen to said speach.

        Quite frankly, I don't want any "Anonymous Cowards" in my home.

        I go to Slashdot... and other web sites. But, I bring my mail into my house. At least, in the social sense of things.

        So, right off the bat... to me there is a huge difference between encountering information I might not want to encounter because I went somewhere, and encountering the same information because it was sent to me.
        • it's a shame... (Score:5, Insightful)

          by *weasel ( 174362 ) on Friday February 06, 2004 @01:02PM (#8203359)
          ... that i have no mod points.

          I agree completely and emphatically. Email is not a free-speech/privacy issue, and i think people are forgetting that.

          There is no provision in the constitution that guarantees an audience for free speech, yet this is precisely what anonymous email does. It puts a burden on me, the recipient, to sort through the garbage of others.

          If you want more anonymous speech, get a blog, post to a web board, post to usenet.

          Your freedoms stop when they infringe on the freedoms of others. Your freedom to be heard is wholly consitutionally blocked with my right to post a no soliciting sign.

          I see no reason why I can't effectively put a similar sign on my email box. (let alone my meatspace mailbox)

          the only reason bulk mail persists, is because it's effectively privately subsidizing the outdated and inefficient USPS. Spam, on the contrary, is wholly an economic drain on the delivery system. there is no benefit to anyone to retain spam, except those corporations who wish to have no responsibility to maintain an honest opt-out policy.

          sure, spam finds willing recipients, so someone must want this garbage - but so do door to door salesmen. And I'm perfectly within my rights to forbid them from coming onto my property. a right which does not in any way infringe on their right to be heard, or their ability to simply bug my neighbor.
        • by jsebrech ( 525647 ) on Friday February 06, 2004 @01:48PM (#8204009)
          First of all, there is no credible difference between holding a discussion over slashdot or holding a discussion over email. Do it through a hotmail account and you're even using the same program to do it. You can come to slashdot and read something you find offensive without warning in advance that it is, just like can happen with email. So trying to draw an arbitrary distinction between anonymous cowards on slashdot and anonymous cowards in email is just that, arbitrary.

          One might also argue that shielding yourself from that which you find offensive is bad for the mind. If you shy away from extremes, inevitably your comfort zone shrinks, and you become close-minded. It's only by trying to see the viewpoints of those who disgust you that you can come to truly new realizations about how the world works. Treading the trodden moral paths doesn't take you into uncharted lands, though it does guarantee you a pretty average and "normal" life.

          Secondly, the problem is that if a pki system were to take hold to identify senders, eventually it would become required to be identified just for someone to SEE the mail you're sending to them. Although it is possible to devise a system where the net identity of someone is thrustworthy while at the same time not revealing their real life identity, it is ridiculously unlikely that such a system would be promoted by the big isp's. They've already got the riaa and friends breathing down their neck wanting identification of customers, they're not going to back a system that helps people stay anonymous while comitting crime.

          Too bad the founding fathers didn't recognize privacy as a right that could be threatened. Until a few decades ago, it wasn't feasible to tie together the knowledge the world has amassed on someone into one large fount of dirty details. Today it is. Most people can have their lives ruined just by the not-so-secrets that are spread around the globe about them (don't believe me? think about everything you've ever purchased with a credit card, now think about everyone in your life knowing about those purchases... unnerving, isn't it?).

          There are two ways out of this, force privacy by law, or admit there is no privacy and stop holding people's pasts above their heads. Both are unlikely, and any other system leads to major abuses.
          • First of all, there is no credible difference between holding a discussion over slashdot or holding a discussion over email. Do it through a hotmail account and you're even using the same program to do it. You can come to slashdot and read something you find offensive without warning in advance that it is, just like can happen with email. So trying to draw an arbitrary distinction between anonymous cowards on slashdot and anonymous cowards in email is just that, arbitrary.

            There are one very important dif
      • I agree, Anonymous Coward is a very important feature that doesn't need to be scraped lightly. For intance ever now and then someone will says something so assine that I'll just have to log in as "Anonymous Coward" and call them a dumbass or even point out there are medications for thier problems.

        This serves two purposes, first dumbass finds out how stupid that he is and should really seek professional help. All the time while allowing me to save my valuble and hard earned karma for trolling like it sho

    • Once PKI starts to take hold, there would be an incentive for the spammers to start creating throw-away identities, which we could counter with a reputation system for the sender's domain. We could also create a "web of trust", automatically managed by our mail servers, or ourselves, to nip the counteroffensive.

      Your argument is flawed. PKI and "web of trust" are in essense incompatible. PKI is hiarchic in its design : depending on a root CA to sign certificates. "Web of trust" (like in PGP) does not ha

      • PGP is a type of Public Key Infrastructure... SSL keys aren't the only game in town. The only difference between the whole "Root CA" and PGP is that the "Root CA" list gets distributed with most SSL implementations, with PGP, you make your own lists.

        Technically, anyone can make themselves a root CA, just like anyone can set up their own DNS root. [twiki.org] It's a simple matter of consensus, the roots are as valid as the users believe the are.

        --Mike--

    • by Anonymous Coward
      Their system relies on a sender verification system How else would the link between email message and escrow account be made?

      Once a reliable sender verification system exists, then is the proposed system of any extra value (except to the people running the escrow network)?

      I saw this presentation at MIT, and it reeked of a VC presentation. I bet the term "the VISA of the email network" comes up a few times in their actual biz presentation.

    • You are describing Domain Keys. Oh, and the Web-o-Trust [web-o-trust.org].
      -russ
    • by hta ( 7593 ) on Friday February 06, 2004 @12:43PM (#8203089) Homepage Journal
      -----BEGIN PGP SIGNED MESSAGE-----
      Hash: SHA1

      There's a slight problem .... in that until everyone signs their
      email, you'll have to be willing to handle unsigned email as well as
      signed. That leaves the signing people worse off than the non-signing
      people (more pain, no gain).
      Difficult deployment problem.

      -----BEGIN PGP SIGNATURE-----
      Version: PGP 7.0.1

      iQA/AwUBQCOn5jjI/tvlmNBeEQLIdwCfTzU3AFyy3vAyqJ1T re ICmreO16YAoJ3J
      Yl8AGPs6HHxEEGJfkmV857m1
      =XHyf
      - ----END PGP SIGNATURE-----
    • Or better yet, why not a real warranty, like the kind you get with your toaster.

      The government could simply make a word ("warrentemail" for example) and a law that includes the exact legal definition of the word as it relates to email.

      The legal definition would state that all people that put this word in the subject line of their email warrant that either a)the email is for personal, non-business purposes only or b) if it is for business purposes then the sender has a preexisting relationship with the rec
  • Bah (Score:5, Funny)

    by Quasar1999 ( 520073 ) on Friday February 06, 2004 @11:52AM (#8202461) Journal
    I propose that any and all spammers be subject to possible castration when caught. No infrastructure required... although verification of actual spamming may be a good idea, I say we fly by the seat of our pants... As a positive side effect, Open relays would be fixed pronto... for many admins would fear for their manhood...

    Laugh, it's a joke! ;)
    • Re:Bah (Score:5, Funny)

      by Prince Vegeta SSJ4 ( 718736 ) on Friday February 06, 2004 @11:55AM (#8202507)
      That would drive all of the males out of the market, thereby making all spammers female. Now male /. users would not only be scared of girls, they would loathe them as spammers as well. Given the difficulty of the /. user in getting a date as it is, this is not a good idea.
      • I dont know, I thank many people here would enjoy having a girl who grocks sendmail asking about the size of their penis. Perhaps if we get rid of all the male spammers geeks wont mind getting spam as much.
  • by squarefish ( 561836 ) * on Friday February 06, 2004 @11:52AM (#8202465)
    A team from the University of Michigan is proposing an economic solution to spam.

    if you stop sending me spam now, I won't kill you
  • by teamhasnoi ( 554944 ) <teamhasnoi@yahoA ... inus threevowels> on Friday February 06, 2004 @11:52AM (#8202467) Journal
    will I get charged a restocking fee when someone replies?
  • Bad idea (Score:5, Insightful)

    by ObviousGuy ( 578567 ) <ObviousGuy@hotmail.com> on Friday February 06, 2004 @11:55AM (#8202509) Homepage Journal
    One benefit to having email is the ability to post information anonymously in order to avoid possible repercussions. Slashdot has that feature with the "Post Anonymously" checkbox (which should be pointed out, is not 100% anonymous and can be tracked by IP and logged-in account name) and it also exists with anonymously emailers.

    Forcing someone out into the open by the use of such 'warranties' imposes a chilling effect on free speech through email.

    I hate spam, but I hate the idea that important speech could be stifled by the use of badly considered spam 'solutions'.
    • Re:Bad idea (Score:5, Insightful)

      by ceritus ( 719474 ) on Friday February 06, 2004 @12:05PM (#8202625) Journal
      Yep, and this is the crux of the whole spam problem: We want to be able to send as many emails with any content in it to anyone we want without any cost yet, we don't want someone to send us tons of email that we consider crap. You just can't have both these things; it's impossible to seperate the two. We can't be hypocritical and say to someone "I should have the right to this free speech medium while this guy over here can't have the same because he's doing something we don't like". I think we're going to have to give up some of our "rights" in e-mail to get rid of this junk mail. I don't like it but I have the feeling that it's going to have to happen.
      • Yep, and this is the crux of the whole spam problem: We want to be able to send as many emails with any content in it to anyone we want without any cost yet, we don't want someone to send us tons of email that we consider crap. You just can't have both these things; it's impossible to seperate the two.

        There is a difference: the first is sent individually, the latter in quantity. You don't have to have a prohibition based on content. It should focus on mass mailings alone. I don't have a solution beyond th

    • Agreed.

      I've said it before, and I'll say it again. The only solution is to be able to take action against the people who advertise their products in this manner.

      Make reasonable anti-spam laws (for instance, standardized subject tags for advertisements, valid and truthful headers, etc.) and allow us to go after the companies whose e-mail marketers don't follow the law.

    • Re:Bad idea (Score:2, Insightful)

      by freepath ( 745838 )
      NO! Email is not anonymous by definition. Headers contain a lot of information, including IP addresses. It can be made hard to track if the sender spoofs their identity or uses a third party email service. This is what spammers do.

      The difference between email and postal mail is that email is FREE! Oh, and postal mail is easier to send anonymously because there aren't computers recording header information. (It's up to the sender to put their return address.) Now imagine how much junk mail you'd receive i
    • Re:Bad idea (Score:3, Insightful)

      by localman ( 111171 )
      I strongly disagree.

      I think that anonymity is _very_ important, just as you do. But I don't think it applies in my inbox any more than it applies in my house. If you are going to make a direct 1-to-1 communication to me (an intimate event) I have the right to know who you are.

      If you want anonymity, then use a public forum, like Slashdot. Or put it on the web.

      I think the usefulness of having verifiable senders outweighs the benefits of anonymity in this case. In fact, email, a certainly useful medium,
  • Summary (Score:4, Informative)

    by iota ( 527 ) * on Friday February 06, 2004 @11:56AM (#8202518) Homepage
    The idea is basically this: You (the recipient) put a value (say $10) on incoming mail from strangers. If someone wants to send you mail, they have to put that in an escrow account. Then if they meet your requirements, you can recieve the mail. -- If you don't like the mail from any reason, you can take the money from escrow. If you don't do anything, escrow will be released after some time. Oh, they mention that this might not be neccessary for people you already know (whitelists).

    This is just lame. The amount of "infrastructure" required is totally ridiculous.
    They ignore the fact that email is a general communications media / People who do not like eachother do email because it's practical / but under this nutty system, people would only email people they trust not to "steal" their money in escrow. Mailing lists, anyone?

    Once again, someone thinks that you can "solve" spam for the recipient at a huge penalty to a legitimate sender.

    Arrg! I hope they didn't get paid to write this tripe.

    • Gotta agree. (Score:3, Insightful)

      by khasim ( 1285 )
      They spend way too much of their paper on analysis of why this would work, but nothing on how to implement it securely.

      And because you ARE talking about money, it would have to be secure.
      • Sounds secure to me... Perfect idea. No flaws at all, either social or technical.

        Not only is this the perfect solution to the Spam problem, this is the perfect solution to my jobless problem.

        Now if you'll excuse me, I've got some mail from the University of Michigan to mark as spam.

    • Re:Summary (Score:2, Insightful)

      by radixvir ( 659331 )

      It seems like everyone is coming out with their own pay email scheme these days. and they always boil down to 2 things

      • change smtp
      • use whitelists

      i wish these people would stop writing these elaborate papers when the solutions are so clear

    • Re: (Score:3, Insightful)

      Comment removed based on user account deletion
    • Not only is there a problem with the infrastructure, there are several moral hazards to worry about, such as mass refusing unpopular people. Now there is scope for things like document services which involve both parties and actual money to avoid junk but I fail to see how the transaction cost will ever come below the "PKI and do it yourself" level.

      Its a good job they didn't warrant their paper or I'd be a little richer by now 8)

    • Re:Summary (Score:4, Insightful)

      by shic ( 309152 ) on Friday February 06, 2004 @01:31PM (#8203740)
      I disagree with your position. The fundamentally different thing about this warranty idea is that it presents a payment system which would permit cost free maintenance of legitimate mailing lists. When a user wishes to subscribe to a mailing list they send an email with warranty to the list maintainer, who claims (or puts this sum in permanent limbo) the warranty funds, which should exceed the warranty demands of the subscriber. The subscriberwould then remain subscribed at no additional cost until such time as they either request to unsubscribe (under which circumstances the funds are released back to them) or they claim the warranty on an email sent on the list... which would be detected by the list maintainer and effect a termination of the subscription. I personally suspect a very low warranty value would prove remarkably effective... $1 associated with each of millions of spam messages would get expensive, whereas tying up $20 for a typical user with only a handful of messages in limbo at any one time is unlikely to be a significant burden.

      I agree that the infrastructure would be considerable - but I for one, remembering how useful email was a decade ago, would be willing to pay whatever it takes to establish a system in which any individual can contact me easily but where a few dozen arrogant cretins don't bother me every few hours with their typically criminal mass mailed proposals. I like the idea of warranties far more than I like the idea of micro-payments which (in my opinion) are likely to prove a far more significant burden for honest email users.
  • vacuous (Score:4, Funny)

    by CGP314 ( 672613 ) <CGP@@@ColinGregoryPalmer...net> on Friday February 06, 2004 @11:57AM (#8202533) Homepage
    A team from the University of Michigan is proposing an economic solution to spam. Instead of relying on technical solutions or government regulations, they use a sender warranty system. In some cases, they argue, it can even be superior to a perfect filter with zero cost, and no errors. Their working paper is available at SSRN. With the caveat that some infrastructure is necessary (isn't it always?), they also claim their approach restores control to the recipient, halts spam, and creates a marketplace for valuable information exchange.

    Would you mind writing a little more and saying a little less. I found this description too short and full of specific information.

    -Colin [colingregorypalmer.net]
  • by shystershep ( 643874 ) * <bdshepherd.gmail@com> on Friday February 06, 2004 @11:59AM (#8202550) Homepage Journal
    Stripped of jargon and graphs, their idea is to create a system based on whitelists. If you're not on a whitelist of the person you send a message to, they can deduct money from an escrow account that you have set up for that purpose. The premise is that people won't open mail from people not on their whitelist unless there is money in that escrow account to pay for their time, thus imposing sufficient costs on spammers to make the current model unprofitable.

    The primary problem I see with this is getting enough people to start using this system. The majority of people probably aren't going to bother with it unless they have to, which means that most emails will be accepted whether or not it costs the sender money, good or spam, because most of a given recipient's contacts will not have the escrow set up. Unless creating the escrow account is mandated, which makes it no different than most of the 'tax' systems, I don't see this model working any better than what we have today.

    What looks good in an academic paper doesn't always translate into the real world. Would their idea work? Yes, with sufficient participation. Will there ever be sufficient participation? No. Look at pgp keys/signatures. There are means of validating the sender's identity now that would stop spam, but they are not used because it requires people to opt-in and most people don't care enough (no matter how much they complain about spam).
  • marketplace (Score:2, Insightful)

    by er_col ( 664618 )
    and creates a marketplace for valuable information exchange.

    There we go. It creates a marketplace!

    If it didn't, wouldn't it be one worthless invention?

  • by serutan ( 259622 ) <snoopdoug AT geekazon DOT com> on Friday February 06, 2004 @12:03PM (#8202601) Homepage
    These guys must be going for their Advanced Circumlocution degree. After the usual introductory review of existing solutions that don't work, they dive directly into graphs proving how their system will increase everyone's well-being. I gave up halfway through. Could somebody briefly sum up the mechanics of their solution -- what exactly are they proposing that the sender and receiver (and the third party) do? Maybe it was so obvious that I just missed it.
    • They're pointing out that there is a nonzero amount of spam which is valuable to the recipient, and wondering out how to strain that baby out of the bathwater (it's a very small baby). They're suggesting that they can make the baby bigger (that is, discernable to the naked eye) by arranging a system whereby spammers can pay to spam you.
      -russ
    • Simplified. (Score:5, Informative)

      by khasim ( 1285 ) <brandioch.conner@gmail.com> on Friday February 06, 2004 @12:16PM (#8202761)
      I send you email. I have to put money in an account.

      You receive my email, but you've set a monetary level to be checked before it is delivered to you. If I didn't put enough money in my account to meet your level, it doesn't get delivered.

      Now, you read my email and don't like it. You get to collect the money I have in my account at the level you set.

      If you do like my email, I go on a whitelist.

      Example #1: I put $1 in my account, you set your level at $5. None of my email will ever be seen by you.

      Example #2: I put $5 in my account, you set your level at $1, you get my email. You don't like my email, you collect $1 from me.

      Example #3: I put $5 in my account, you set your level at $1, you get my email. You like my email, so I go on your whitelist.

      Simple, really. In theory.

      In practice, almost impossible to work.
    • Stupid idea. (Score:3, Insightful)

      by TheLink ( 130905 )
      Good enough summary?

      The sender deposits money with a third party to send an email. Once enough money is in, the email is delivered to the recipient.

      The recipient can choose to take the money for whatever reason (needs a beer etc). If the recipient doesn't do anything, after a while the money returns to the sender.

      The recipient can put the sender on a white list which means the sender doesn't need to put up money.

      The authors/proposers say that the alternative of making everyone digitally sign their email
    • Step 1: Release a document in a format that nobody can read.

      Step 2: Convince Windows users put money in an escrow account to warranty their good behavior

      Step 3: Have Gator send spam through the Windows user's machine to the University of Michigan

      Step 4: Profit

  • why does evry problem in life have to be solved by creating a free and open market?

    I for one think that there are some things that can not be solved simply by attaching a price tag to it.

    do you want to polute? how much money do you have to buy pollution credits?
    do you want to send email? how much money do you have to buy a warenty?
    do you want to get laws passed how much money do you have to "lobby" with.

    sigh...:(
    • why does evry problem in life have to be solved by creating a free and open market?

      Isn't that why spam exists in the first place?

    • Well, you could argue that basically, this is the way the universe works, except the basic currency of the universe is energy.

      You want to get off the planet, you're going to have to expend some energy. Same is true for bio-systems. You want to find some food, are you going to expend just a little energy and eat the grass right next to you, or are you going to expend a lot of energy and go hunt a buffalo? You want to attract a mate, how much energy are you willing to spend to do it?

      We use money because i
    • > why does evry problem in life have to be solved by
      > creating a free and open market?

      Yeah, why don't we just pass a law against spam?

      Oh, wait...
    • EVERYTHING is solved by simply attaching a price tag to it.

      The price on the tag isn't always in terms of cash money, but it's always there.

      Your first question is valid, though. Here's one answer:

      When beneficial actions need to be encouraged, or malicious acts discouraged, one can either attach a price tag to those acts or enable independent identification and enforcement processes. The former ("price tags") are enabled through the use of a marketplace involving those acts, while the latter ("processes


  • because I *have* been busy lately, but isn't this the same idea Bill Gates proffered a couple of days ago? Yeah, I know. It wasn't his idea originally, either, since I remember talking about this on /. AT LEAST a year ago, but somebody had to point this out.
  • by Russ Nelson ( 33911 ) <slashdot@russnelson.com> on Friday February 06, 2004 @12:08PM (#8202667) Homepage
    So these guys want our computers to spend our money? First they have to secure every machine. Of course, once you do that, you don't have DDOSes, nor proxy spam. The first step of their solution *is* the solution; the remaining steps would be a waste of time.
    -russ
  • by Anonymous Coward
    So you get infected with MyDoom.D and it warrants your email... then all the people in spams collect the small fee for each message and you're broke.

    Mailing lists would be a bit difficult too, not to mention usenet gateways. If I mail a gateway and it posts to usenet, does that count as one email? What about the other way around: I post to usenet, does the gateway owner have to cover the cost of the message going to all subscribers... I shouldn't, I didn't even send an email.
  • by norite ( 552330 ) on Friday February 06, 2004 @12:10PM (#8202684) Journal
    100% of the spam I get comes from America - Maybe over there they should simply legislate against the sending of unsolicited commercial emails, like they have here in Europe.

    Then people who get this nonsense in their inboxes can get together and take the companies who use spammers (and the spammers themselves) to market their junk to court. Once the companies who use this service start getting served with class action court orders to stop or else, they should soon get the message.

    Of course, there's nothing to stop the spammers moving/subcontracting to e.g. India or some other place where sending unsolicited emails isn't illegal, but it's a start. Ultimately we can hopefully have a worldwide ban against the sending of unsolicited commercial emails.

  • by Effugas ( 2378 ) on Friday February 06, 2004 @12:10PM (#8202694) Homepage
    I'm a geek. I'm a security engineer. I'm here to say -- the solution is not in the packets, but the dollars.

    Spammers have gotten to the point where they're breaking into people's machines to get them to illicitly send spam. Look at that carefully -- you can't even trust your friends not to spam you anymore. If you don't think Spyware is going to adapt to a spam transport, you're not paying attention. Ultimately, we need criminal prosecution for fraud that follows the money (because money transfers are really well traced). The money link needs to be broken.

    Nothing else has even a hope of working.

    --Dan
    • by mabu ( 178417 ) on Friday February 06, 2004 @12:40PM (#8203049)
      You are totally right.

      I am having to spend $8000 this month to build a new mail server.

      Why?

      Because 80% of the mail traffic to my system is unsolicited spam and now I need more resources to handle the mail services for my legitimate users because 80% of my resources are dealing with crap.

      Because the authorities don't prosecute the spammers, people like me have to pay for the resources they consume even though I didn't invite them to exploit my resources in this manner.

      Something needs to be done, and it has to do with enforcement, not figuring out yet another boneheaded way to inject profit motive into the SMTP stream.

  • They use what seems to me to be a backwards definition of false positive and false negative with respect to spam filtering. From the article:

    Better filters learn recipient preferences and eliminate unwanted messages while suffering from fewer false positives (passing junk messages) and false negatives (screening valuable messages).

    I think of this in terms of being tested for HIV. If someone has a false positive, that means they have incorrectly been identified as having the virus being checked for. Doesn

  • by cwernli ( 18353 ) on Friday February 06, 2004 @12:13PM (#8202731) Homepage

    After having introduced the concept of "whitelists" for known senders the article continues:

    In the case of strangers, the warranty mechanism is more suitable. Analogous to a standard bond mechanism, delivering email to an inbox requires an unknown sender to place a small pledge into escrow with a third party. In the case of screening, recipients determine the size of this bond, which they can dynamically adjust to their opportunity costs. The email is delivered only after the recipient receives suitable confirmation that the bond has been posted. When the recipient opens the email, she may act solely at her discretion to seize the pledge. Taking no action releases the escrow after a period of time.

    IMHO this means the end of mailing lists - what would prevent me from signing up (automatically, of course) to thousands of mailing lists and collecting all the bonds placed for messages posted through these lists ?

    "Of course mailing list operators would first get your approval that you let through all their messages".

    This is where it starts getting complicated. And complexity is exactly what I don't want with email - it is simple, and shall remain simple.

    Therefore I am perfectly willing to put up with the current spam levels - hey, I can deal with those five to ten messages a day which pass through my Bayesian filter. On certain days I get more than that in my smail box.

  • Shorter List (Score:3, Interesting)

    by Anonymous Coward on Friday February 06, 2004 @12:16PM (#8202760)
    Is there anyone who ISN'T proposing an economic solution to spam or email? Every day it seems like someone is proposing it and making it sound as though they are the first ones who are making the suggestion. Everyone making a proposal would a long, long way to show why all of the competing methodologies will fail or be compromised and why theirs will succeed (or have a greater chance of succeeding).

    Let us not forget what William Henry Gates III said [1], "I don't care what the information superhighway looks like as long as I've got a tollbooth on it." Everyone is making suggestions to charge for email not because the ideas are technically superior but because they want to be the tollbooth collecting a microcent for every piece of email running across the 'net. Unless|until there are certain issues taken care of online, micropostage will not solve the spam problem although it may still drop money in someone's open pocket (and they will likely not care about spam once that happens).

    [1]ca. 1995-96 just after he returned from his annual sojourn and realized Microsoft almost missed the Internet boat.
  • Better links (Score:5, Informative)

    by Anonymous Coward on Friday February 06, 2004 @12:17PM (#8202773)
    The /. summary only links to the umich homepage. But, here are some better ones, pulled from the article. [Posted anonymously to prevent accusations of karma-whoring.]

    ---
    Proud UofM Alumnus

  • Only accept GPG or PGP encrypted and signed email.
    (okay - I don't really do that, but I would like to if only more folks cared enough)
  • by Thede ( 745407 ) <thede@boxbe.com> on Friday February 06, 2004 @12:20PM (#8202805) Homepage
    Hi, I'm one of the authors of the paper mentioned in this post. We have a short summary of reasoning behind the design posted here [umich.edu] It is a little less dense than the SSRN paper. Also, I'll get a protocol diagram up shortly, and a short FAQ, linked from the one pager.

    Thede Loder
    University of Michigan.

  • I think most of these solutions are overkill. If email was just a secured medium where you could reliably verify the sender (or at the very least the sender's server) everything else would work out. Blacklists would mean something. Abusers could be tracked down and put out of business using current law. It would work itself out if we just remove the anonymity. And nobody who wasn't spamming would have to do anything (but upgrade to a functionally equivalent mail package).

    Just secure the medium. Anony
  • by dpbsmith ( 263124 ) on Friday February 06, 2004 @12:25PM (#8202864) Homepage
    ...it assumes that all the mechanisms for posting and collecting these bonds are perfectly reliable, perfectly secure, and unhackable.

    Right.

    If they aren't this just opens fresh avenues for abuse.

    For example, you receive an email saying "Your PayPal account will be suspended if you don't reply." You find that in order to reply you will have to post a bond of $0.0001, which is the going rate for such things, so you do so without thinking about it. Later, you discover that due to some cunningly-engineered HTML, the part of your screen that you THOUGHT was telling you that the bond was $0.0001 was somehow faked, and that really you posted a bond of $1000 which the sender has collected.

    Or whatever.
  • Uh no. (Score:5, Insightful)

    by KalvinB ( 205500 ) on Friday February 06, 2004 @12:25PM (#8202866) Homepage
    Ohhh look another "best idea on the internet" that's the same old "charge them" idea that many others have had that's still stupid.

    Basically this idea annoys everyone and solves nothing. There would be a lot of rich people who simply spend all day signing up on lists and then collecting the "fine" when they get e-mails.

    The way to stop spam that doesn't require messing with STMP is to use web-forms. The web-form on my mail server is written in PHP and is basically a custom e-mail client. It connects to the mail server and sends to exactly one address that's hard coded in the script. Giving it random letters and numbers would prevent spammers from guessing it and users wouldn't care because they don't have to remember it. My particular PHP script only sends text only e-mails as well.

    If you use a non-generic web-form with a unique filename and unique variables, it makes it quite impossible for spammers to make bots to whore their spam automatically.

    What would be really clever if you want to prevent bots entirely you just have an array of images. And an array of questions, one for each picture. And the user has to answer the question like "what color is the apple?"

    No amount of image scanning by a bot is going to figure that out.

    Then instead of telling people an e-mail address you just give them your domain. It's still SMTP so you can contact people out side the script if you want.

    The other method I use on the server side is filtering domains that spammers use to host their product pages or images. I've gotten hundreds of e-mail attempts according to RinetD's logs and only a couple spams with domains I hadn't added to the filter yet have gotten through. Since the PHP script goes through the mail server and doesn't actually send the e-mails itself, all the spam prevention is also applied to the web-form. And since no legitimate e-mails use those domains, I've had 0% collateral damage.

    I get virtually no spam and have yet to break SMTP or charge anyone anything just to send me an e-mail. It's really not that hard.

    Ben
  • by rwash ( 16296 ) on Friday February 06, 2004 @12:36PM (#8202976) Homepage
    http://www.eecs.umich.edu/~tloder/one_pager.html

    That site has a shorter and easier to read description of the ideas presented in the paper. The paper is really a technical economics paper, not a mass-market thing. The one-pager is much easier to read, and its the same people.
  • Is it different than what we currently have?

    If so, it won't work.

    Looks, spam, spam mail, telemarketers all exist today due to profits. People profit from them, so people will continue to do it.

    "But take away the profit then!" far easier said than done. And even if you could, I would argue that you shouldn't. At least not legislatively. Let's see someone be half as creative in the private market as the spammers are. If they are creative, and their system works, then they get to be rich beyond belief. What
  • zero cost, and no errors ... With the caveat that some infrastructure is necessary

    Sounds to me like Christmas presents ...SOME assembly required. Ya! sure! ...

  • Anyone else getting this:

    Hotmail.com has added some interesting new filtering to their 'spam blocking' tools. Essentially, they're blocking mail based on the content of the message (what you send), but they won't tell you why it was blocked. There's a magical formula there somewhere. It is not blocked by IP address, as some messages go through and some do not.

    This is occuring from *all* senders, in *all datacenters*.........It's a hotmail specific problem. Here's a microsoft.com employees response to the
  • Escrow Management (Score:2, Insightful)

    by smartalecvt ( 748879 )
    What about the third parties who are supposed to manage the escrows? There would doubtlessly have to be very few of these companies (maybe even just one) doing the job, otherwise you have the problem of trust -- with thousands of companies holding escrow like this, you may well be wary of a company that comes along and says "don't worry, we've got the escrow, now give us your bank account number..." So we're primed for a monopoly of sorts. And whatever megacorp comes along and fills this position, they will
  • by Alric ( 58756 ) <slashdot@NoSPaM.tenhundfeld.org> on Friday February 06, 2004 @01:10PM (#8203440) Homepage Journal
    I might be missing a critical idea. I feel that I must be. (In my defense, I was up all night playing Crimson Skies and then preparing for an 8:30AM project status meeting.)

    It seems that this warranty, escrow account system would not work well with hacked computers, viruses, et cetera. Here's a simple example; please tell me that I'm wrong. My grandma makes a reasonable attempt to secure her system but leaves some holes. Some hacker, working for a spammer, gets in her system and installs a nice little backdoor program. The spammer starts emailing people from her computer until the money in grandma's escrow account can no longer cover the warranties. The recipients are obviously angered by receiving this spam and collect the money on the warranty. How is she going to get her money back?

    I don't need to belabor this point, but does this plan assume that all email sent from a user's account was purposefully sent by that user? If so, I can't support that. Virus writers and hackers aren't going away. Computers may become more secure; users may become more experienced. But our increasingly interconnected world is simply too complex to eradicate every security hole.
  • by Tom ( 822 ) on Friday February 06, 2004 @01:22PM (#8203573) Homepage Journal
    Another solution that won't work, mostly because it doesn't contain the magical phrases "shotgun" and "spammers head".

    Seriously, though: Spammers have been breaking into computers for years now. The current international spam mafias run bot-networks of several hundred-thousand machines each.

    So sending mail will cost money (stamp, warrenty, tax - no matter the mechanics). Why exactly should the spammers care? It's not like they're sending from their machines or spending their money.

    The serious, working solution to spam is two words: Jail time.
  • by Twillerror ( 536681 ) on Friday February 06, 2004 @01:27PM (#8203655) Homepage Journal
    The best current solution is really the only one. Have a list of friendlies ( possibly with server information ).

    How often do you get an email from a complete stranger that you really want to read. For most personal accounts you have a limited set of email buddies, a lot like an instant messenging service.
    Building this list is the big issue.

    Say you buy something from amazon.com, or another site. The web application needs to be able to add itself to your friendly list. Of course this does not happen automatically, but with something you click. A simple standard would not be that hard to devise so any mail client could recieve the message. Upon receiving the message the user is asked if the email is a friendly. At this point the program could check for a valid MX record, and a slew of other tests to see if the record is valid and issue a warning, or give the green light.

    Now if the email is webmaster, or your the kind of person that does get lots of emails from people on the Web, like a CmdTaco you need some
    more tools. But current spam checkers matched with MX lookup could seriously limit the number of records. You could also do some kind of verification routine where your email program sends an auto-response with one of those pictures. This has gotten worked around with letting porn surfers answer the question for you, but I'm sure it won't be long before people write bots to answer the porn guys wrong.

    MX lookup I think will be the first step. If you can reverse an address, then ask that server if the email is authentic, and even give a CRC/timestamp to see if the email came from it. This would make it harder to run your own email server, but if you doing this you probably know what the hell MX records are.

  • by dasunt ( 249686 ) on Friday February 06, 2004 @01:32PM (#8203757)

    <spammer> Crap, this warrenty plan for email has destroyed my spamming.
    <spammer> **thinks**
    <spammer> **Writes email virus that causes the infected computer to send email to a dummy account in .ru. Spammer then invokes warrenty, quickly withdraws money, and continues the cycle with a new virus.**

    Your idea is borked, methinks.

  • by suwain_2 ( 260792 ) on Friday February 06, 2004 @02:33PM (#8204703) Journal
    Would you Warranty Your Email?

    No, I wouldn't. It's an interesting approach, but I'd never participate in it. It will COMPLETELY break the way things work, and make communications much more complicated. For example, friends/family/colleagues send me a ton of crap. Let's suppose for a minute that I set my cost as $50 per message. I have multiple addresses, so when people forward some ridiculous chain mail on some topic that I vehemently disagree with them on, I get multiple copies. So let's say I get three copies of this chain mail from someone. With the click of a button, I can set a friend out of $150. Obviously, they wouldn't remain a friend for long, and maybe there's something to be said for making people think twice about forwarding me crap.

    But now consider a corporate setting. Let's say I'm really sick of spam at work, and set the price to $500 a message. My boss sends me mail informing me of budget cuts; I'm angered by it, and thus flag it as spam, charging my boss $500.

    And I won't even get into the potential for abuse, where I try to impersonate someone else sending me spam, charging random people insane amounts of money.

    And this just won't work. Spammers have a 'spam and dump' mentality -- they're sign up for a server, or find a new open relay, dump a ton of spam, and move on. I would fully expect spammers to completely disregard this, running up hundreds of thousands of dollars of debt on a credit card they used to purchase the server. They never pay the bill, and move on. In some strange way, it's kind of like the "If you outlaw guns, only outlaws will have guns" -- spammers will find ways around this, and we'll only inconvience people trying to send legitimate e-mail. And the basic premise sounds to have a ton of potential issues.
  • by cgenman ( 325138 ) on Friday February 06, 2004 @03:48PM (#8205939) Homepage
    This technology requires a sender-verified, secure, trackable, unbreakable e-mail system that ensures the sender is who they say they are, the recipient is who they say they are, and the message is exactly what the sender sent. All mail-sending accounts must be registered and accessible in a centralized database, and must contact that database to send mail.

    The domain hosts then become responsible for the activities of the spammers, because the discovery of the spammer and their account address becomes trivial. Deal with the problem, or be black holed. Or, alternatively, the spammer can be locked out at the db level.

    No where does charging the spammer become necessary. The spammer is simply locked out. E-mail stays free. Nobody gets charged when hacked.

    Personally, I would support a domain-sender-message verification system, whereby a message is Md5'd (or some quicker form of hashing) on its way out and stored in a database for each 12 hour period. Upon receiving the mail, the recipient's mail server queries the reported sender's mail server with the message's listed Md5 key. The mail server goes through the databases for the last 3 12 hour periods (in reverse order) and searches for the listed key. If the key matches, it gives a positive response. If not, the message is destroyed.

    Bingo, verification that the message originated in the particular domain, and that domain is responsible for the activities of its constituents. If that domain owner refuses to take action, their domain and their IP addresses would be blacklisted.

When the weight of the paperwork equals the weight of the plane, the plane will fly. -- Donald Douglas

Working...