Re: [Asrg] Adding a spam button to MUAs

"Chris Lewis" <clewis@nortel.com> Thu, 17 December 2009 17:07 UTC

Return-Path: <CLEWIS@nortel.com>
X-Original-To: asrg@core3.amsl.com
Delivered-To: asrg@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 388153A6774 for <asrg@core3.amsl.com>; Thu, 17 Dec 2009 09:07:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.128
X-Spam-Level:
X-Spam-Status: No, score=-6.128 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4, SARE_MILLIONSOF=0.315, SUBJECT_FUZZY_TION=0.156]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Z9jIL2BAMWQI for <asrg@core3.amsl.com>; Thu, 17 Dec 2009 09:07:04 -0800 (PST)
Received: from zrtps0kp.nortel.com (zrtps0kp.nortel.com [47.140.192.56]) by core3.amsl.com (Postfix) with ESMTP id D44FB3A6942 for <asrg@irtf.org>; Thu, 17 Dec 2009 09:06:58 -0800 (PST)
Received: from zrtphxs1.corp.nortel.com (casmtp.ca.nortel.com [47.140.202.46]) by zrtps0kp.nortel.com (Switch-2.2.6/Switch-2.2.0) with ESMTP id nBHH6dn19288 for <asrg@irtf.org>; Thu, 17 Dec 2009 17:06:39 GMT
Received: from zrtphx5h0.corp.nortel.com ([47.140.202.65]) by zrtphxs1.corp.nortel.com with Microsoft SMTPSVC(6.0.3790.3959); Thu, 17 Dec 2009 12:06:22 -0500
Received: from [47.9.28.157] (47.9.28.157) by zrtphx5h0.corp.nortel.com (47.140.202.65) with Microsoft SMTP Server (TLS) id 8.1.340.0; Thu, 17 Dec 2009 12:06:22 -0500
Message-ID: <4B2A650D.5020800@nortel.com>
Date: Thu, 17 Dec 2009 12:06:21 -0500
From: "Chris Lewis" <clewis@nortel.com>
Organization: Nortel
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.23) Gecko/20090812 Lightning/0.9 Thunderbird/2.0.0.23 Mnenhy/0.7.6.666
MIME-Version: 1.0
To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
References: <20091216145533.68982.qmail@simone.iecc.com>
In-Reply-To: <20091216145533.68982.qmail@simone.iecc.com>
Content-Type: text/plain; charset="ISO-8859-1"; format=flowed
Content-Transfer-Encoding: 7bit
X-OriginalArrivalTime: 17 Dec 2009 17:06:22.0872 (UTC) FILETIME=[427C4980:01CA7F3B]
Subject: Re: [Asrg] Adding a spam button to MUAs
X-BeenThere: asrg@irtf.org
X-Mailman-Version: 2.1.9
Precedence: list
Reply-To: Anti-Spam Research Group - IRTF <asrg@irtf.org>
List-Id: Anti-Spam Research Group - IRTF <asrg.irtf.org>
List-Unsubscribe: <http://www.irtf.org/mailman/listinfo/asrg>, <mailto:asrg-request@irtf.org?subject=unsubscribe>
List-Archive: <http://www.irtf.org/mail-archive/web/asrg>
List-Post: <mailto:asrg@irtf.org>
List-Help: <mailto:asrg-request@irtf.org?subject=help>
List-Subscribe: <http://www.irtf.org/mailman/listinfo/asrg>, <mailto:asrg-request@irtf.org?subject=subscribe>
X-List-Received-Date: Thu, 17 Dec 2009 17:07:05 -0000

John Levine wrote:
> In article <20091216120742.GA28622@gsp.org> you write:
>> On Tue, Dec 15, 2009 at 05:50:24PM -0800, Steve Atkins wrote:
>>>> I think allowing end users access to such a button is a terrible idea.
>>> Data from actual reality contradicts your (otherwise plausible) reasoning.
>> Not my data.  I have a rather large collection of incidents involving
>> message recipients who have marked as spam:
> 
> Unless your collection is at least tens of millions of messages, I don't
> think it counts as large.
> 
> More to the point, your collection has severe sample bias.  If you're
> looking at incoming reports on a network that doesn't have bulk
> senders and doesn't have a lot of consumer PCs that get botted, you're
> not going to see many real complaints.

I explained that to RSK about a year ago.  Guess he forgot.

We've had a "this is spam" mechanism since 1997, averaging perhaps 
500-1000 hits/day over the past year (down from considerably more when 
our filters weren't as good).

It's quite accurate - probably well in excess of 99%.  We've never made 
an incorrect blocking decision based on an incorrect "this is spam" from 
one of our users.

On the other hand, we occasionally get one of our users accidentally 
marking an internal email as spam.  Those are unfailingly wrong.  Go 
figure ;-) I usually find out because I get a followon email saying "oops!".

It's a simple matter of sampling and biases.  If you emit a million 
emails per day, and 50% of it is spam, a 1% FP rate in spam reporting 
will probably not be detectable.  If you emit a million emails per day 
and _none_ of it is spam, a .00001% FP rate will make it look like all 
spam reporters are idiots worthy of derision on spam-l.

RSK falls into the latter scenario methinks (zero spamming, not "idiot" ;-)