nanog mailing list archives

Re: anti-spam WKBIs, Worsening google service reputation and abuse


From: John Levine via NANOG <nanog () lists nanog org>
Date: 16 Aug 2025 21:49:40 -0400

It appears that Matthew Petach via NANOG <nanog () lists nanog org> said:
https://www.wisdom.weizmann.ac.il/~naor/PAPERS/pvp.pdf

OK, I read the paper through, and they put considerably more thought into
the calculation side;
however, this paper explicitly calls for a centralized Pricing Authority,
which is exactly what I'm
advocating *against*.

There's been lots of other work like their Penny Black, and Hashcash,
that let recipients decide how much work they want to see.  Dwork
worked for Microsoft and for a while MS tried a version of it in
their mail systems.  

They all failed for a variety of reasons, one of the most intractable
being that criminals with botnets have a lot more CPU power available
than legitimate senders. Tahe usual botnet blacklist techniques don't
work since the botted machines talk to the senders, not the
recipients.

Wikipedia has a summary of these WKBIs:

https://en.wikipedia.org/wiki/Cost-based_anti-spam_systems

R's,
John
_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/G2XYC3KUAHUXQ2K5HGQNRRXXTMDRUJPS/


Current thread: