Live data from Hacker News

The Hostile Email Landscape

liminality.xyz

211–220 of 251 posts

Re: The Hostile Email Landscape

#211
post #85

Earlier quoted context omitted.

Bernstein is an incredibly smart guy. But he's also an example of how the social stuff matters. His software would run the internet if he put a little more effort into the social/political side of things. The big problem with IM2000 is that it doesn't solve the real problems. It's focused on the economics of storage of mail, which, yeah, are a thing for a few mail administrators, but generally is considered less impo…

That his software does not "run the internet" does not make it any less good. It's there for whoever chooses to use it. That he focuses on the software instead of pandering probably makes his software better than the alternatives that aim to please even the most foolish of users. At least I think so. Maybe I interpreted the proposal incorrectly, but I always saw IM2000 (minus the "notifications") as a "pull" solution…

"A smart IM2000 recipient perhaps would not pull spam from the sender's server."

Based on what criteria? You wouldn't have the message headers/content, so you couldn't filter based on that. All you can filter on is the IP address. But you can already do that with SMTP by just responding with a 5xx code as soon as the sending server connects anyway... Or you could actually fetch the message and then spam filter it. But then, you may as well use SMTP...

What difference does it make which side initiates the TCP connection? If I was a spammer, IM2000 wouldn't concern me one little bit.

Re: The Hostile Email Landscape

#212
post #59
post #16

I've run into similar issues with a similar setup. It's frustrating. You can convince gmail user A to whitelist your messages, and so they'll get through to user A, but gmail user B probably still won't see messages from you unless you tell him to dig them out of the spam trap. And your messages to A might still be classified as spam if they have attachments or hyperlinks in them. (Even if you've been corresponding w…

http://cr.yp.to/im2000.html Internet Mail 2000 IM2000 is a project to design a new Internet mail infrastructure around the following concept: Mail storage is the sender's responsibility.

IM2000 is a good idea. However, I would propose at least one additional idea [0]: Linked attachments. That should drastically reduce storage space in a corporate environment.

[0] http://beza1e1.tuxen.de/articles/better_email.html

Re: The Hostile Email Landscape

#214
post #84

I sometimes see similar tales of woe, and I can only say that this does not match my experience. I’ve done this many times, you set up the mail server, configure DNS correctly (including reverse lookup), and that’s it. Never had problems being blacklisted or mail getting classified as spam. I suspect that people having trouble are sending a lot of mail , like “newletters”, etc. But I can’t prove this hypothesis.

I think I might be able to offer another explanation.

People talk about the reputation of their individual IPs, but networks matter a lot too. DigitalOcean for instance is an occasional source of spam; Linode is very rarely; 1and1 is a HUGE headache; and so on.

I have some custom software in place that temporarily drops entire netblocks for abuse, and I did that to keep up with the spam filtering offered by larger services. With so many spammers now switching between cheap VPS hosts, it was getting impossible to do single-IP-only bans.

Ever since the software was put into place the amount of spam actually making it into users mailboxes has fallen off a cliff.

You have to be very very careful about which network you choose to host your mail server from.

Re: The Hostile Email Landscape

#215

> this server was configured perfectly: (...) SPF, DKIM and DMARC policies in place SPF, DKIM and DMARC are no indicators of spamminess of a source. These systems have a completely different purpose.

They should shift IP reputation to domain reputation though.

Re: The Hostile Email Landscape

#216
post #209
post #34

>This isn't how the internet is supposed to work. The email architecture was started back when it was a smaller network of researchers at universities, governments, etc. Everybody basically trusted each other. Once the "internet" is available to the general public and commercial interests, it becomes vulnerable to the "bad actors" problem (e.g. spam abuse). That's why we have the inevitable situation today of a few e…

How do you solve the problem of "cold call" with a trusting system ? How does one build up trust with a new account ? Spammers could create million accounts at once and fake trust build up between them. That's why I'm not convinced that trust will solve the abuse of messaging. A messaging application must allow "cold calls". Relying on trust built up by others is not a reliable system because it can be abused.

>How do you solve the problem of "cold call" with a trusting system ? [...] That's why I'm not convinced that trust will solve the abuse of messaging.

You can't remove "trust" or "reputation" from a viable messaging system. The concept of trust always exists whether informally or formally.

When the internet was a small private network between universities and government, how did a new unknown scientist "cold-call" an email? It was not an issue. The scientist just sent the cold email. There was already implicit trust within the system to allow that scenario. Everybody trusted that researcher@someuniversity.edu didn't send a million emails about Nigerian money transfers to researcher@army.mil.

Back then, email users didn't need "spam filters". The trust was informally created because the institutional "system" outside of the email system vetted email users. (The "system" being the hiring procedures of SomeUniversity, DepartmentOfDefense, etc.)

All those gates for reputation are gone when we expose that simplistic email architecture to the general public. Trust doesn't go away. You now must recreate trust at a massive scale.

>Spammers could create million accounts at once and fake trust build up between them.

That's not the type of "trust" people are talking about in this thread. That type of incestuous "trust" between bad actors won't work because it doesn't have an initial authority (good actor) to "bless" them which starts an acceptable "chain of trust". The concept is similar to Certificate Authorities. We trust Chrome because we trust Google Inc; and in turn, Google Inc trusts Verisign; and in turn, Verisign EV-certificate processing trusts government offices that register businesses.

Re: The Hostile Email Landscape

#217
post #216
post #209

Earlier quoted context omitted.

How do you solve the problem of "cold call" with a trusting system ? How does one build up trust with a new account ? Spammers could create million accounts at once and fake trust build up between them. That's why I'm not convinced that trust will solve the abuse of messaging. A messaging application must allow "cold calls". Relying on trust built up by others is not a reliable system because it can be abused.

>How do you solve the problem of "cold call" with a trusting system ? [...] That's why I'm not convinced that trust will solve the abuse of messaging. You can't remove "trust" or "reputation" from a viable messaging system. The concept of trust always exists whether informally or formally. When the internet was a small private network between universities and government, how did a new unknown scientist "cold-call" an…

Ok my assumption of trust credit working model was inaccurate. Could you give an example how trust could be used to control abuse ? If a user is given initial trust credit, how can one prevent spammers to create million of such "trusted" accounts and let them be banned after the hit and run spamming ? That model us used in messaging systems like Twitter but has its limitation. But is known to have its limit. Or did I still got it wrong ?

Re: The Hostile Email Landscape

#218

Earlier quoted context omitted.

Right... their email providers, which they are paying to provide email from them . The money chain is still at your recipient's end. Note that I'm not suggesting you did the wrong thing here --- I don't see anything else you could have done. I'm just saying that pinning the entirety of the blame on the third party provider is wrong. ... Having read the rest of the thread: I'm sorry to say but the reason why you're ha…

>* pinning the entirety of the blame on the third party provider is wrong.* We disagree. It's certainly understandable that the third-party might raise false-positives. However, what is wrong is when a business can demonstrate that it is not engaged in such practices, yet the third-party provider still refuses to cease penalizing them. So, who else's fault would it be? Mine? The customer? The customer's e-mail provid…

> However, what is wrong is when a business can demonstrate that it is not engaged in such practices, yet the third-party provider still refuses to cease penalizing them.

They don't have any responsibility to help you do business. Comcast and your recipients are not required to accept your email. It's in their interest to do so, of course, because that's what their customers are paying them to do so... but their customers are also paying them not to accept email, because most email is spam, and they don't want to receive that.

Email is not a common carrier medium. You can't demand people accept your traffic. It just doesn't work like that.

> The ads I referenced are occasional sponsorships by businesses[...]

...which means, unfortunately, that people are paying you to send advertisements by email, which means that you're in the email advertising business. Which means that people will automatically assume you're malicious. Which sucks, but...

Re: The Hostile Email Landscape

#219

Earlier quoted context omitted.

How about let your members keep missing their emails. If they really want them, encourage them to sort out the problem with their email provider which is apparently failing to do its job? Since the recipients are the ones who choose to receive it, then they're also the ones to be upset when something goes wrong - especially since it's caused by their choice of an unreliable email provider. I use email for a slightly…

Unfortunately engaging users in a campaign to encourage their providers to sort it out is a bit of a quagmire. Meantime, our business suffers. It's a good thought. Just wish it were simpler to pull off.

What I mean is passively let them take up the problem themselves if they want your newsletters. Since it's something they expect and want, they might choose to pressure their email provider into solving it.

Of course if they don't really want it or just half-heartedly signed up because it seemed like it might be useful at the time then they're not going to make the effort. And I guess that's the situation almost everybody is in when they find they're not receiving emails due to false positive spam filtering. So it's basically a terrible situation for everyone :(

At least we have these magic solutions like MailChip or MailJet (what I use because the free plan fits my usage pattern) so you could turn to something like that if you really had no luck chasing the spam list company.

Re: The Hostile Email Landscape

#220
post #217
post #216

Earlier quoted context omitted.

>How do you solve the problem of "cold call" with a trusting system ? [...] That's why I'm not convinced that trust will solve the abuse of messaging. You can't remove "trust" or "reputation" from a viable messaging system. The concept of trust always exists whether informally or formally. When the internet was a small private network between universities and government, how did a new unknown scientist "cold-call" an…

Ok my assumption of trust credit working model was inaccurate. Could you give an example how trust could be used to control abuse ? If a user is given initial trust credit, how can one prevent spammers to create million of such "trusted" accounts and let them be banned after the hit and run spamming ? That model us used in messaging systems like Twitter but has its limitation. But is known to have its limit. Or did I…

>, how can one prevent spammers to create million of such "trusted" accounts

Notice what you did there? You characterized spam accounts as "trusted" even though you didn't specify why or how they'd get trusted in the first place. There's still a gap in your thinking of how the origination of real (not fake) trust happens.

It's like a 1970s email user asking, "how does the system prevent a 'trusted' Nigerian money scammer from spamming everybody?" Well, why would Department of Defense hire a Nigerian scammer? Would a UniversityOfWhatever hire a Nigerian scammer? No. In that scenario, the trust begins with the institution. For the Nigerian scammer to be trusted, somebody authoritative has to "bless" him.

>Could you give an example how trust could be used to control abuse ?

Well, we're still using trust right now to help control abuse. Today, reputable corporations and also millions of honest users (that's us) "trust" Google Inc, Microsoft, Yahoo, FastMail, etc. Spam on a massive scale does not originate from gmail/hotmail/etc because those corporations shut them down.

The issue is that it's centralized trust concentrated in a few big players instead of de-centralized trust. That's the thorny problem that's very hard to solve. All the clever decentralized proposals (sender pays for storage, outbound payment bonds, cpu-proof-of-work, etc) are basically roundabout proxies for recreating "trust" on a bigger scale. I don't know what the final answer will be. I just know that trust/reputation is an unavoidable part of a new solution.

Post reply on HN