Re: [Asrg] Please critique my anti-spam system

Laird Breyer <laird@lbreyer.com> Mon, 10 January 2005 08:12 UTC

Received: from ietf-mx.ietf.org (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id DAA28012 for <asrg-web-archive@ietf.org>; Mon, 10 Jan 2005 03:12:22 -0500 (EST)
Received: from megatron.ietf.org ([132.151.6.71]) by ietf-mx.ietf.org with esmtp (Exim 4.33) id 1CnusY-0005ad-Cs for asrg-web-archive@ietf.org; Mon, 10 Jan 2005 03:26:25 -0500
Received: from localhost.localdomain ([127.0.0.1] helo=megatron.ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1CnucN-0005j3-HY; Mon, 10 Jan 2005 03:09:39 -0500
Received: from odin.ietf.org ([132.151.1.176] helo=ietf.org) by megatron.ietf.org with esmtp (Exim 4.32) id 1CnuTb-0004Dw-3D for asrg@megatron.ietf.org; Mon, 10 Jan 2005 03:00:35 -0500
Received: from ietf-mx.ietf.org (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id DAA27157 for <asrg@ietf.org>; Mon, 10 Jan 2005 03:00:33 -0500 (EST)
Received: from gizmo09ps.bigpond.com ([144.140.71.19]) by ietf-mx.ietf.org with smtp (Exim 4.33) id 1Cnuh6-00057f-Qt for asrg@ietf.org; Mon, 10 Jan 2005 03:14:36 -0500
Received: (qmail 28277 invoked from network); 10 Jan 2005 07:59:55 -0000
Received: from unknown (HELO psmam12.bigpond.com) (144.135.25.103) by gizmo09ps.bigpond.com with SMTP; 10 Jan 2005 07:59:55 -0000
Received: from cpe-60-226-75-250.qld.bigpond.net.au ([60.226.75.250]) by psmam12.bigpond.com(MAM REL_3_4_2a 234/32397570) with SMTP id 32397570; Mon, 10 Jan 2005 17:59:55 +1000
Received: from ender (ender.scoobynet [192.168.0.3]) by scooby (Postfix) with ESMTP id ABDE628FF for <asrg@ietf.org>; Mon, 10 Jan 2005 18:01:46 +1000
Received: by ender (Postfix, from userid 1000) id A9F43C4F0; Mon, 10 Jan 2005 17:45:47 +1000
Date: Mon, 10 Jan 2005 17:45:47 +1000
From: Laird Breyer <laird@lbreyer.com>
To: asrg@ietf.org
Subject: Re: [Asrg] Please critique my anti-spam system
Message-ID: <20050110074547.GA11598@ender>
Mail-Followup-To: asrg@ietf.org
References: <20050110070609.10905CA07A@ws7-4.us4.outblaze.com>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
In-Reply-To: <20050110070609.10905CA07A@ws7-4.us4.outblaze.com>
User-Agent: Mutt/1.5.6+20040523i
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 9466e0365fc95844abaf7c3f15a05c7d
Content-Transfer-Encoding: quoted-printable
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.1.5
Precedence: list
Reply-To: laird@lbreyer.com
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www1.ietf.org/pipermail/asrg>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
Sender: asrg-bounces@ietf.org
Errors-To: asrg-bounces@ietf.org
X-Spam-Score: 0.1 (/)
X-Scan-Signature: 97adf591118a232206bdb5a27b217034
Content-Transfer-Encoding: quoted-printable

On Jan 10 2005, Michael Kaplan wrote:

> I would also reiterate the impossibility that a company can exist in
> the developing world that would decode CAPTCHA for a legitimate
> company (Paypal, Amazon, etc.), then also sell the same decoded list
> spammers, and expect to keep that company's business for more than a
> week.  It would become INSTANTLY obvious that the company was
> dishonest when every decoded address is then flooded with spam.

Where else but the developing world would you send the CAPTCHAs for
decoding? Nowhere in the developed world can you offer decoding at 0.1
cent per CAPTCHA.

Figure $5 per hour minimum wage, at 10 seconds per CAPTCHA, that's 
a pure labour cost of slightly more than 1 cent per CAPTCHA. Add in other
expenses, frequent pauses, mistakes etc and probably 3 cents / CAPTCHA is
a basic developed world estimate.

Given this huge difference in cost, the fact that decoded addresses are
being resold is largely irrelevant. Who is going to offer a competing
service and take away their business? 

Moreover, companies in the developing world are usually quite safe
from legal attacks originating in the developed world. So it's easy
money. You really have to make sure the decoded CAPTCHAs are useless
if you want to stop them being sold.

-- 
Laird Breyer.

_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg