Daniel J. Bernstein's IM2000 email proposal is not a good idea
utcc.utoronto.ca
utcc.utoronto.ca
I think that’s the fundamental strength of email, and what has given it staying power. I can email a person in government or an old friend or a scientist and be reasonably certain they will read it without knowing who I am.
Email is the only tool where I still regularly have meaningful conversations with strangers. Several times a week I get emails from strangers asking for help with something they’re working on and I am almost always happy to oblige them. I have built a number of meaningful relationships through these chance encounters with random strangers.
It would be all to easy on other services just to say “I don’t know this person” and ignore them, as I regularly do on Facebook. With email on the other hand I always read a message before deleting it.
Sure, there would still be a (smaller) pointer (or metadata) saved by the recipient. But such pointers/metadata might've allowed identifying certain originators/remote-stores as sources of unwanted mail, earlier, before transmission/storage elsewhere.
That, and the need for senders to provide an enduring server for the mail to be read, could've forced some of the same sender-side stability/reputation that's since become central to mail-delivery, via other mechanisms (DKIM/etc).
I'm not sure it was ever much more than a rough concept/prototype, not a complete solution. Its central idea – "reverse the responsibilities" – could still be part of an improved messaging system, even if it doesn't solve everything.
Email infra is unnecessarily complex and painful to operate yes, but that isn't the big problem today. If anyone wants to tackle a big problem in email space (even infra problems), they have to start with UX and justify their reasons for redesign from that.
Just like in academia exploring what didn’t work helps us either not waste time or maybe even ‘fork’ the idea and attempt to fix the original flaws.
Also the bit about email lacking “revocable authorization to send you things”, at least in a more decentralized and standardized way, is a good concept that could potentially be reexplored.
At the time of IM2000, an eternity in Internet time, most of this was done using open or poorly secured relays. Reputation score worked well for that too and that spam vector is closed now. Remaining vectors are hacked infrastructure and the large cloud and free email providers. Storage cost could be relevant to escalate the problem for the latter.
In the early days of email, fire-and-forget mailing, from fly-by-night servers, imposing costs on all recipients, was an actual problem.
When I read it this time I started wondering about how the "notifications" would work. How would we tell a genuine notification for something we want to retrieve from one that is just a front for some "attention seeker"?
* http://jdebp.uk./Proposals/IM2000/
You, the Hacker News participant, are using a pull-style electronic communication system right now.
That objection is invalid, as common and widespread DKIM message signature can be pushed with other headers. Author is likely aware of this, so he inserted a qualifier "in some potential realizations". Then it follows that this is not objection to IM2000, but to an easily fixed realization flaw.
This makes the author look like he has an agenda.
Your post advocates a
( X ) technical ( X ) market-based
approach to fighting spam. Your idea will not work. Here is why it won't work. (One or more of the following may apply to your particular idea, and it may have other flaws which used to vary from state to state before a bad federal law was passed.)
( X ) Mailing lists and other legitimate email uses would be affected
( X ) Requires immediate total cooperation from everybody at once
Specifically, your plan fails to account for
( X ) Lack of centrally controlling authority for email
( X ) Public reluctance to accept weird new forms of money
and the following philosophical objections may also apply:
( X ) Ideas similar to yours are easy to come up with, yet none have ever been shown practical
( X ) Sending email should be free
Furthermore, this is what I think about you:
( X ) Sorry dude, but I don't think it would work.
Technology is constantly advancing in ways that are related to the problem domain in non-obvious ways, so repeating that old saw puts us in a reverse boiling frog situation. We never jump in the pot because it doesn't seem hot enough. Well, until someone ignores people saying things like this and does it anyway.
> Mailing lists and other legitimate email uses would be affected Allowing people to "opt in" to emails from people and companies they support could help, but you're right that this becomes a "spam tax". Which I'm mostly ok with, despite working for a company that sends a LOT of email.
> Mailing lists and other legitimate email uses would be affected
The receiving server could require proof-of-work for the first message from a sender to a given receiver, but not for subsequent messages. If spammers try to abuse this, it's easy for the user to click "block this sender"; if the spammer changes their sending address, they have to do a new proof-of-work.
> Requires immediate total cooperation from everybody at once
It could be introduced gradually: if a proof-of-work is provided, then the message is allowed to skip the spam filter. Small mailserver operators often have trouble with their messages being caught in spam filters by GMail and other large webmail providers; even if GMail alone started accepting proof-of-work, that would probably be enough to convince a lot of senders to start generating proofs-of-work, which would drive adoption.
> Lack of centrally controlling authority for email
This is no more difficult than any other backwards-compatible extension to an existing Internet standard.
> Public reluctance to accept weird new forms of money
OP's post didn't mention a weird new form of money. The original HashCash proof-of-work proposal included a weird new form of money, but it's easy to imagine a proof-of-work system that doesn't.
> Sending email should be free
Suppose the proof-of-work cost is calibrated such that it costs about $0.001 per email. That would be enough to destroy spammers' margins, but the vast majority of legitimate users wouldn't mind paying that.
> Ideas similar to yours are easy to come up with, yet none have ever been shown practical
I kinda see the point here... But I'd like to understand _why_ it isn't practical, because none of the arguments make sense to me.
at this point mailing lists are dead
> It could be introduced gradually: if a proof-of-work is provided, then the message is allowed to skip the spam filter.
Yes, because that totally will not harm the small senders (often individuals) whose newsletters can easily reach thousands / tens of thousands.
> Sending email should be free
> Suppose the proof-of-work cost is calibrated such that it costs about $0.001 per email. That would be enough to destroy
all mailing lists, yes. Look at open source mailing lists.
Or, to put it a different way: $0.001 is very roughly equivalent to a few minutes of CPU time. So if you have a single-core server dedicated to running your mailing list, you can onboard several hundred new subscribers every day.
Remember, the sender only needs to pay the proof-of-work when someone first joins the mailing list and receives the initial message. So, I don't see how this will kill mailing lists at all.
Firstly, the financial burden should be on the owner of the SMTP server / domain, rather than on the users themselves. Of course, the owner would pass the costs onto their users, but the system doesn't have to require an ongoing fee, just a bond for good behaviour. (This could be done with cryptocurrency, a smart contract, and a "proof of burn" type of transaction).
Secondly, and perhaps most importantly to encourage adoption, all existing registered domains should be grandfathered in, so they wouldn't have to put up a bond, whereas any future competitors would.
Finally, and this is the controversial bit, there would have to be some set of entities who were able to determine whether a domain had acted in a way that should forfeit their bond (and, optionally, that a domain had acted in a positive way long enough that the bond should be refunded). In practice, though, such a cabal already exists, which is the Big Three email providers (Gmail, Outlook, Yahoo Mail). Together they already have the power to destroy any new email provider, so we might as well formalise that by giving them the power to burn these good behaviour bonds.
Yes, the first was approximately contemporary with dinosaurs roaming the earth, before NCSA Mosaic was released and images appeared in webpages also known as the year 1992.
> We present a computational technique for combatting junk mail in particular and controlling access to a shared resource in general. The main idea is to require a user to compute a moderately hard, but not intractable, function in order to gain access to the resource, thus preventing frivolous use.
https://link.springer.com/content/pdf/10.1007%2F3-540-48071-...
Dwork C., Naor M. (1993) Pricing via Processing or Combatting Junk Mail. In: Brickell E.F. (eds) Advances in Cryptology — CRYPTO’ 92. CRYPTO 1992. Lecture Notes in Computer Science, vol 740. Springer, Berlin, Heidelberg. https://doi.org/10.1007/3-540-48071-4_10
Metadata? It seems for some assumptions one cannot avoid a notion of sending at least metadata?
From the proposal: "All the receiver needs is a brief notification that a message is available."
If course it has flaws, it was never a fully developed idea.
You can't curb abuse in a federated model. This is an issue that's been plaguing the fediverse as well. IRC networks, though not federated, have had to each individually ban spammers and other problematic users.
Google (GMail), Yahoo, Microsoft (Live/Hotmail), Yandex, QQ Mail. That ought to be enough for everyone. EDIT: and mail.ru
Google&co extort a phone number if they don't have enough tracking information about you and yandex shadow bans you (you can login, but don't receive any emails).
Uhh no. Its for anti spam. Imagine if someone created a bunch of email addresses in one go without the phone requirement. You could abuse the 15 gb per account allocation pretty easily, or you could use those emails for spamming others.
Any website that requires your phone number is doing it for tracking purposes. Which is the same reason why you should never give it to any of them.
The only surefire way to curb abuse is to make sure the abuse is not cost effective for the abuser. For spammers trying to make a buck, make it so it costs them more to send their spam than the value they reap from it. For non economic spammers (politics, trolls, etc), it's a lot harder, but there's always some price that it becomes not worth it for their influence/"fun". This was the approach Bernstein was trying to do, but based on the article it sounds like he underestimated the cost of storage as technology improbed.
The hard part is adding this cost in such a way that does not drive away or punish real users. An email system that costs $10/month isn't going to be used by many spammers, because any reasonable administrator will ban obvious spam and they won't get their $10 to cover costs before being shut down. But it also limits the customer pool; most people are not going to pay $10 a month of email when free services are available.
Phone numbers are definitely not perfect, but they are trying to solve the problem of "What do most people have and would not invoke any additional cost on them, but would invoke additional cost on spammers?" Yes, phone numbers are relatively cheap, but there is still some backtracing/ownership checks that can be performed, and ones from more "trustworthy" blocks will still cost a buck or so. Suddenly spammers need to make at least a $1 from the account or they are losing money.
Domains are another way spammers are often dealt with: if it costs $10 for a domain, you have to make $10 from the domain before it is blocklisted, or again, you are losing money.
I can't think of any myself, but if you have any ideas for a model with comparable high costs to spammers but low cost to real people, that fulfills your privacy expectations, I'm all ears. However, costs generally are better enforced in a more centralized model as opposed to a federated/privacy respecting model, so I suspect it will be incredibly difficult to find a solution that actually enforces the appropriate economic goals.
But you'd be using the same prefix, which I'm sure some good soul would map, so you anyone who cared would correlate all of your accesses just as if you had a fixed IPv4
They can do the same thing with phone numbers. Buy prepaid SIM cards in bulk, use each one to create an email account, then sell them all again to recover the money because they still have 99% of the prepaid data left. This is less annoying for spammers than regular people who have to do this, because the spammers benefit from technical knowledge and economies of scale.
> An email system that costs $10/month isn't going to be used by many spammers, because any reasonable administrator will ban obvious spam and they won't get their $10 to cover costs before being shut down. But it also limits the customer pool; most people are not going to pay $10 a month of email when free services are available.
It doesn't have to be $10/month, it only has to be $10 on account creation, or $1. The legitimate user is going to have the same account for ten years, the spammer is going to lose their account inside of an hour.
The problem there is we still don't have an easy anonymous digital payments system, but requiring payment details is about as bad as requiring a phone number. In theory this is where cryptocurrency could be useful, but only if it becomes easier for regular people to use it.
You could also do similar proof of work things. For example, user doesn't want to provide a phone number? Fine, here's your email account, which can receive emails. If you want to send emails, install Folding@home or similar and submit X many work units. With email apps this could be completely automated; you install the app, your phone is plugged in overnight, the next day you can send emails.
> Its for anti spam. Imagine if someone created a bunch of email addresses in one go without the phone requirement. You could abuse the 15 gb per account allocation pretty easily, or you could use those emails for spamming others.
That may be the goal. But it also makes using the internet anonymously very hard, since getting a phone number are linked to real names in my country.
There should be less invasive solutions, like rate limiting sending of emails from new accounts.
Use:
-Protonmail not Gmail
-Swisscom myCloud not Drive
-Neocities not blogger
-Matrix (Element) or Signal/Wire not Talk/Whatsup/etc
It's the same problem with DDOS. Some providers tried to mail out letters "hey, your computer is involved in malicious things, please get it fixed", but that just lead to a lot more support requests that the ISPs can't handle. So we just accept that botnets are a thing.
Soon, the US will have "Real Americans have a RealID". That was supposed to turn on next month, but it's been put off for a year due to the epidemic.
I’m hoping (and reasonably hopeful) that some lawsuit will nerf it before I ever actually need it. Many people already argue it’s illegal.
I suppose the joke is that email has already evolved into this model, for most people.