[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Asrg] Email Postage (was Re: FeedBack loops)



All parts of the system must be accountable, but that need not be government and the penalties need not be financial.
 
Consider what happens in a medium sized organization when a mid level manager hits the end of the quarter, is behind on quota and sends out a spamming run that nets $500K in additional earnings. Let us consider the following two penalities:
 
A) Company is fined $50K through immediate forfeiture of a performance bond that was posted.
B) Other companies stop accepting email from the company
 
Penalty A is not likely to be effective. The manager might get a slap on the wrist but they brought in $4From asrg-bounces at irtf.org  Thu Nov 13 13:01:22 2008
Return-Path: <asrg-bounces at irtf.org>
X-Original-To: asrg-archive at optimus.ietf.org
Delivered-To: ietfarch-asrg-archive at core3.amsl.com
Received: from [127.0.0.1] (localhost [127.0.0.1])
	by core3.amsl.com (Postfix) with ESMTP id CFFAE3A6965;
	Thu, 13 Nov 2008 13:01:22 -0800 (PST)
X-Original-To: asrg at core3.amsl.com
Delivered-To: asrg at core3.amsl.com
Received: from localhost (localhost [127.0.0.1])
	by core3.amsl.com (Postfix) with ESMTP id CD7373A69D6
	for <asrg at core3.amsl.com>; Thu, 13 Nov 2008 13:01:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.152
X-Spam-Level:
X-Spam-Status: No, score=-5.152 tagged_above=-999 required=5 tests=[AWL=0.050,
	BAYES_00=-2.599, HTML_MESSAGE=0.001, MIME_QP_LONG_LINE=1.396,
	RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.32])
	by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id Ou1vmCIq1ivL for <asrg at core3.amsl.com>;
	Thu, 13 Nov 2008 13:01:20 -0800 (PST)
Received: from robin.verisign.com (robin.verisign.com [65.205.251.75])
	by core3.amsl.com (Postfix) with ESMTP id 6A15A3A69DE
	for <asrg at irtf.org>; Thu, 13 Nov 2008 13:01:17 -0800 (PST)
Received: from MOU1WNEXCN03.vcorp.ad.vrsn.com (mailer6.verisign.com
	[65.205.251.33])
	by robin.verisign.com (8.12.11/8.13.4) with ESMTP id mADL1Hji011895
	for <asrg at irtf.org>; Thu, 13 Nov 2008 13:01:17 -0800
Received: from MOU1WNEXMB09.vcorp.ad.vrsn.com ([10.25.15.197]) by
	MOU1WNEXCN03.vcorp.ad.vrsn.com with Microsoft
	SMTPSVC(6.0.3790.3959); Thu, 13 Nov 2008 13:01:18 -0800
X-MimeOLE: Produced By Microsoft Exchange V6.5
Content-class: urn:content-classes:message
MIME-Version: 1.0
Date: Thu, 13 Nov 2008 13:01:17 -0800
Message-ID: <2788466ED3E31C418E9ACC5C316615572FFB47 at mou1wnexmb09.vcorp.ad.vrsn.com>
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
Thread-Topic: [Asrg] Email Postage (was Re:  FeedBack loops)
Thread-Index: AclFztWFFmvGD+9NTqCiRpqM0TwTLAAAyZan
References: <13922482.481226608289371.JavaMail.franck at franck-martins-macbook-pro.local>
From: "Hallam-Baker, Phillip" <pbaker at verisign.com>
To: "Anti-Spam Research Group - IRTF" <asrg at irtf.org>,
	"Anti-Spam Research Group - IRTF" <asrg at irtf.org>
X-OriginalArrivalTime: 13 Nov 2008 21:01:18.0135 (UTC)
	FILETIME=[F9187C70:01C945D2]
Subject: Re: [Asrg] Email Postage (was Re:  FeedBack loops)
X-BeenThere: asrg at irtf.org
X-Mailman-Version: 2.1.9
Precedence: list
Reply-To: Anti-Spam Research Group - IRTF <asrg at irtf.org>
List-Id: Anti-Spam Research Group - IRTF <asrg.irtf.org>
List-Unsubscribe: <https://www.irtf.org/mailman/listinfo/asrg>,
	<mailto:asrg-request at irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/pipermail/asrg>
List-Post: <mailto:asrg at irtf.org>
List-Help: <mailto:asrg-request at irtf.org?subject=help>
List-Subscribe: <https://www.irtf.org/mailman/listinfo/asrg>,
	<mailto:asrg-request at irtf.org?subject=subscribe>
Content-Type: multipart/mixed; boundary="==============05985596=="
Sender: asrg-bounces at irtf.org
Errors-To: asrg-bounces at irtf.org

This is a multi-part message in MIME format.
Title: [Asrg] Email Postage (was Re: FeedBack loops)
All parts of the system must be accountable, but that need not be government and the penalties need not be financial.
 
Consider what happens in a medium sized organization when a mid level manager hits the end of the quarter, is behind on quota and sends out a spamming run that nets $500K in additional earnings. Let us consider the following two penalities:
 
A) Company is fined $50K through immediate forfeiture of a performance bond that was posted.
B) Other companies stop accepting email from the company
 
Penalty A is not likely to be effective. The manager might get a slap on the wrist but they brought in $450K net. Its not a close call to turn a blind eye. Senior management is not going to ever know it happened.
 
Penalty B has immediate effect and visibility right the way up the management chain. I would say that it was likely to be rather more effective.
 
 
Accountability = Authentication + Accreditation + Consequences
 
I make this case in my book on stopping Internet crime, the dotCrime Manifesto. I also compare the development of solutions to the spam problam problem to the problem of 'finding the longitude'


From: asrg-bounces at irtf.org on behalf of Franck Martin
Sent: Thu 11/13/2008 3:31 PM
To: Anti-Spam Research Group - IRTF
Subject: Re: [Asrg] Email Postage (was Re: FeedBack loops)

And penalize inappropriate use, is generally a government function. If there is success in shutting down botnets, is because gov resources are affected to the problem.

I think feedback loops are for the good guys. The bad guys will not play by any rule.

----- Original Message -----
From: "Phillip Hallam-Baker" <pbaker at verisign.com>
To: "Anti-Spam Research Group - IRTF" <asrg at irtf.org>, "Anti-Spam Research Group - IRTF" <asrg at irtf.org>
Sent: Friday, 14 November, 2008 8:16:49 AM (GMT+1200) Auto-Detected
Subject: Re: [Asrg] Email Postage (was Re:  FeedBack loops)

Actually the underlying intellectual conceit of market fundamentalism is that the market is a perfectly tuned feedback loop.
 
We do not need to charge for inappropriate use of email, we only need to penalize inappropriate use.

_______________________________________________
Asrg mailing list
Asrg at irtf.org
https://www.irtf.org/mailman/listinfo/asrg