Spam Links

Sunday, March 27, 2005

IBM shift costs of spam to forged senders

IBM have joined the growing body of users and promoters of challenge/response. IBM says

FairUCE eliminates any need for a "probable spam" folder, as well as the necessity of keeping up with the latest version of antispam software
but it can only achieve this by shifting the costs of dealing with hard to classify spam onto forged senders with real mailboxes.

There are some good concepts in their offering, FairUCE, but the authors state that their challenge/response part

alone catches 80% of UCE and very rarely challenges legitimate mail
and that
FairUCE sends a challenge only when the mail appears to be spoofed
which is a tacit admission that the system sends challenges to large numbers of forged senders. This can only contribute to the torrent of backscatter inflicted on receiving sites.

Choosing not to enter the filtering arms-race is an interesting idea, but using challenge/response to use forged senders as your filtering engine is not fair use of their resources.

Labels: ,