Google Wave and Spam
jgc.org
jgc.org
How individual servers deal with malicious users and the disconnection/deletion process remains to be seen.
Also to be determined is what happens when spam content is added to a legitimate public wave. Presumably anyone else with access to that wave would have the ability to remove it (thus affecting everyone else on the wave as well) - this could be done by a bot.
Before the user can send you any information, they must send you a request containing a standardized block of information that gives you a clue to their identity. You can accept or deny the request, and only then can they contact you.
Obviously, even that block of information can itself be considered "spam", but there is only one of them and the social network has safeguards to prevent the creation of millions of accounts and millions of requests.
The way to translate that "account creation" safeguard is to whitelist not individual email addresses, but hosts -- either you trust gmail.com to have adequate safeguards that initial contact requests are unlikely to be spam, or you do (and of course, you need to build authentication to the sending address into the protocol).
It's complex to be sure, but not unapproachable, and lots of solutions already exist in the form of in-network messaging at all the various social nets.
Facebook controls who can sign up, the removal of users, the rate at which messages are sent, who is visible to who, etc. This is not the case for a decentralized system like Google Wave.
There's nothing stopping me from creating my own Wave server and starting to communicate with the other servers in the network. This is analogous to the situation with SMTP today where anyone can run an SMTP server and communicate with anyone else.
You can certainly whitelist known hosts such as gmail.com, but unless you are willing to ignore all non-whitelisted hosts then you will still have a problem as spammers bring on Wave servers on their botnets.
The Wave team has been trying to just get it work. They are not too sure of all the usecases for wave so they're in more of a discovery mode. The priorities for them is probably to get a minimum product out to users and developers then worry about spam.
For example, let's say you sign up to a website that uses wave to confirm you. You would just login, accept the request for that site to add you (thus allowing it to send future communications without this step), and that would probably be it, you shouldn't even really have to click a link or anything, since the site would be notified that you accepted it.
if it takes off, spam will happen. gmail's spam filtering is really good (can't remember the last spam message that made it through to my inbox), so maybe they can borrow that from gmail.
The only opportunity for spam is unwanted invitations to become a friend -- which can be a problem, but is a smaller problem than an open inbox that accepts messages from any principal.
Am I way wrong?
TFAuthor dismissed that as a non-option, because it would make Wave unsuitable for collecting unsolicited feedback and sales contacts.
But it seems to me that a single Wave account that auto-whitelisted contact attempts would solve that problem at the cost of reintroducing some capacity to spam, but at a vastly reduced level.
Simply applying existing tools and leveraging the other benefits of Wave over SMTP would seem to seriously marginalize spam as a concern.
All unsolicited communications could come via email instead of my Wave.