Re: [Asrg] New proposal for spam blocking: Greylisting

Kee Hinckley <nazgul@somewhere.com> Sat, 21 June 2003 19:04 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA12854 for <asrg-archive@odin.ietf.org>; Sat, 21 Jun 2003 15:04:58 -0400 (EDT)
Received: (from exim@localhost) by www1.ietf.org (8.11.6/8.11.6) id h5LJ4Wc23803 for asrg-archive@odin.ietf.org; Sat, 21 Jun 2003 15:04:32 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19Tnf6-0006Bq-25 for asrg-web-archive@optimus.ietf.org; Sat, 21 Jun 2003 15:04:32 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA12778; Sat, 21 Jun 2003 15:04:27 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19Tnf2-0000dA-00; Sat, 21 Jun 2003 15:04:28 -0400
Received: from ietf.org ([132.151.1.19] helo=optimus.ietf.org) by ietf-mx with esmtp (Exim 4.12) id 19Tnf1-0000d0-00; Sat, 21 Jun 2003 15:04:27 -0400
Received: from localhost.localdomain ([127.0.0.1] helo=www1.ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19Tneb-00065o-0y; Sat, 21 Jun 2003 15:04:01 -0400
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by optimus.ietf.org with esmtp (Exim 4.20) id 19Tne1-00065K-GY for asrg@optimus.ietf.org; Sat, 21 Jun 2003 15:03:25 -0400
Received: from ietf-mx (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id PAA12658 for <asrg@ietf.org>; Sat, 21 Jun 2003 15:03:21 -0400 (EDT)
Received: from ietf-mx ([132.151.6.1]) by ietf-mx with esmtp (Exim 4.12) id 19Tndy-0000cj-00 for asrg@ietf.org; Sat, 21 Jun 2003 15:03:22 -0400
Received: from www.somewhere.com ([66.92.72.194] helo=somewhere.com) by ietf-mx with esmtp (Exim 4.12) id 19Tndx-0000cf-00 for asrg@ietf.org; Sat, 21 Jun 2003 15:03:21 -0400
Received: from [66.92.72.194] (account nazgul HELO [192.168.1.104]) by somewhere.com (CommuniGate Pro SMTP 3.5.7) with ESMTP-TLS id 2471329; Sat, 21 Jun 2003 15:03:22 -0400
Mime-Version: 1.0
X-Sender: nazgul@somewhere.com@pop.messagefire.com
Message-Id: <p0600170cbb1a4847684f@[192.168.1.104]>
In-Reply-To: <200306210449.h5L4nBAI007729@calcite.rhyolite.com>
References: <NVTRD7185DFF@novitraq.com> <200306210449.h5L4nBAI007729@calcite.rhyolite.com>
To: Vernon Schryver <vjs@calcite.rhyolite.com>
From: Kee Hinckley <nazgul@somewhere.com>
Subject: Re: [Asrg] New proposal for spam blocking: Greylisting
Cc: asrg@ietf.org
Content-Type: text/plain; charset="us-ascii"; format="flowed"
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Sat, 21 Jun 2003 13:38:48 -0400

At 10:49 PM -0600 6/20/03, Vernon Schryver wrote:
>I saw some comments about available counter-attacks by spammers, but
>I don't recall seeing a clear description of the easiest.  Spammers
>do not need to do real queuing to get though a greylist.  They need
>only send to the same target list from the same SMTP client a few
>hours after an initial spew.  Mailboxes protected by a greylist will
>accept the second copy.  Other mailboxes will see two copies.  That
>wouldn't be remarkable, because some spammers are already hitting
>individual addresses with several copies per spew.

I agree.  In fact, I think this makes greylisting a very bad idea. 
It magnifies the tragedy of the commons.  Everyone tries to protect 
themselves and ends up making the problem worse for everyone else. 
In the short term it works well for individuals.  As soon as it 
becomes popular, it doubles the spam traffic and solves nothing.
-- 
Kee Hinckley
http://www.messagefire.com/          Anti-Spam Service for your POP Account
http://commons.somewhere.com/buzz/   Writings on Technology and Society

I'm not sure which upsets me more: that people are so unwilling to accept
responsibility for their own actions, or that they are so eager to regulate
everyone else's.

_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg