Lessig On Bounties For Spamhunters
An anonymous reader submits: "Digital rights (as in yours, not the RIAA's) guru Lawrence Lessig comes up with a Swiftian idea of how to fight spammers -- $10,000 for the first ubergeek to hunt the offender down. The column is at CIO Insight. Wonder if it'll reach its audience there."
but it will only catch the stupid ones. The "smarter" ones, and I use the term loosely, will endure.
Sent from your iPad.
For a period of one month, all filters on spam and spam hunting should be suspended. Part of the problem is that anti-spam activities are masking the true magnitude of the problem. A wake-up call is needed. When people realize just how much spam is being sent out, the villagers will take to the streets with pitchforks and torches.
If tits were wings it'd be flying around.
I can see the sense in promoting our rights to privacy online, as michael and timothy (bless them) are wont to do, but then we see a sudden reversal. Sure, I guess it's a real pain when spammers send hundreds of unwanted messages over the Internet every day, but is offering a bounty to rob them of their right to privacy really the answer? This is just the government turning citizen against fellow citizen in a foul ploy to get us to turn in our rights to online privacy. Let's look at what's happened so far:
- Spammers send spam
- Geek gets pissed, deletes spam
Now that isn't that terrible, is it? Do we really need to go out and promote a database state and tie together all a person's Constitutionally private information into one big heap of spying and ratting out? I dislike spam as much as the next man, but I draw the line at violating others' online rights. It's a line nobody should be willing to cross.--sdem
From California Spam law:
and
Very similar...
The author compares the bill that the RIAA bought to allow them to crack any box they want with the "spam vigilantes" that blacklist sites that don't obey "proper" e-mail etiquette and then by organizing automated boycotts of the sites on the list.
His explanation of the bill is Through his bill, these vigilantes would be granted immunity from liability as they deployed tools to hack peer-to-peer systems that they "reasonably believe" violate copyright laws. He compares the two as unaccountable processes that wrongfully victimize people.
He then proposes (drum roll) a law that spammers would have to follow, and a reward for geeks who catch them if they don't. Like they'll follow laws. Blacklisting servers is better; it slaps the stupid admins pretty hard for victimizing everyone else. It also slaps folks like that stupid "internet lawyer" and Bernie Schifman. There's a public good- actual, relevant punishment for offenders.
I spent a year in Iraq looking for WMD and all I found was this lousy sig.
I go one step better. My sendmail server hangs up on the SMTP connection as soon as it finds ADV: in the subject line of an incoming message. They don't even get to finish unloading their message. As soon as it says ADV:, they're gone.
That's great for the recipients, but it does nothing to reduce the load on ISP servers; in fact, it may increase it as the advertisers will have to send out MORE mail to make sure at least somebody opens it.
More ISPs can do what I'm doing and hang-up as soon as they see ADV: in the subject.
In the short term it doesn't solve the problem, but when absolutely no-one is reading spam then the response rate will drop to zero--at that point there will be no-one that WANTS to spam.
Also, such a solution does nothing to help legitimate advertisers, who need to know the demographics of who is actually reading their ad.
What is a "legitimate advertiser?" Anyone that is mailboming advertisements to me isn't legitimate regardless of whether they are selling penis cream or Norton products (seems to be the latest thing I've seen in spam) or discount airfares.
If there is an easy way to filter, they may buy a list that is 90% middle class professional office workers, but they have no way of telling what mix actually read their ad.
I also don't care if an advertiser "needs" to know if I read their advertisement. That's none of their business. They have no clue who reads their advertisements in a newspaper nor who hangs around during commercials on TVs... Why do they suddenly "need" to know if I click their email?
So they would never buy a service that operated under the "ADV" rules
Good! The idea isn't that the whole world does bombing runs with ADV:. The idea is that the ADV makes it so easy to filter that NO-ONE reads the spam and, in short order, spam as a method of advertising goes away.
Result: only the scam companies would ever send the mail.
Which is MOSTLY the case now. This is where the bounty comes in... If you get spam that isn't identified with ADV, the spammer has broken the law and under the law you're entitled to $10k from the spammer if you are the first to identify him. A few of those and the scam companies will stop sending spam because it's no longer a good business model. So "legitimate" companies don't spam because all their spam is filtered with ADV, and "illegal" spammers stop doing it because they'll be liable for $10k.
Of course, the idea won't work. As others have said, it's too easy to frame an innocent person or company. Unless the spammer shows you his email log, how can you really "prove" he did it? You could just be making up the logfile that shows a conection from 192.110.121.99, or whatever.
The problem is that most spam isn't prosecuted based on other violations of the law. Porn spam should be blatantly illegal since much of it goes directly to the inbox of minors. The owners of porn sites that spam should be sought out by the FBI and charged with corruption of minors. Most of the rest of the spam is fraudulent or deceptive in some way--it should be prosecuted by the FTC or FDA. The problem is they apparently don't have time, which is sad since it's currently one of the largest sources of blatant fraud operating in broad daylight, and so many of them would be open and shut cases. You just have to go get the perpetrator.
Read the article. The 10k bounty for not labeling spam as spam isn't what you should be paying attention to. It's his attack on volunteer efforts to block spam relays, whom he calls "spam vigilantes", in the worst sense of the word. Essentially, he says that efforts to blackhole servers (presumably, because the admin of that server also needs to be whacked repeatedly with a cluestick) do more harm than good, and that we should just use filtering.
The 10k bounty is supposed to convince spammers to label their spam so we can effectively filter it.
Finished laughing? Let's dissect his thinking, shall we? He says we can handle spam just by making sure the spammers label it. This is the thinking behind a lot of bad legislation - it legitimizes it, instead of eradicating it. Second of all, he implies that vigilantism can work with government (finding spammers who don't comply with the ADV: rule) to fix what vigilantism by itself (blacklists) cannot do. Well, blacklists are meant to eliminate spammer havens - and we have plenty of anti-spam people hunting spammers as it is, FOR FREE. What the hell does he think 10k is going to do, if all the bounty-hunter does is turn the spammer's info over to the government? I mean, the FTC doesn't do much to the existing fax-spammers who are in violation of federal law. (The fax.com lawsuit was filed by a private individual, the FTC just levies paltry fines.) Or worse, what is the US government gonna do to foreign spammers who don't comply with our "label law"?
Essentially, Lessig says we should discard our current system of blocklists and anti-spam tech, in favor of simple client-side filters and a federal mandate to label spam, with a bounty to catch anyone who fails to label their spam. The threat is so feeble, and the undeserved side-effects so beneficial, I'm sure that spammers will love this idea.
The problem with spam is that the cost is basicly zero per-message. $X to send Y pieces of spam, X divided by Y works out to zero point zero cents per spam.
The only way to make it die is for people to stop buying from it
Not possible. Spam works at a response rate of 1 in 10,000. The general population contains a far higher rate of mental illness, senility, and retardation, not to mention just plain gullibility and stupidity.
To to missquote something P.T. Barnum never said,
The internet: a million suckers log on every minute.
It seems to me that the only solution will come by a switch over to a new E-mail system that can link a non negligible co$t to all E-mail, or just to offending E-mail. This could be done with crypographicly signed "stamps".
Would you be willing to attach 2 cents to each E-mail where the recipient of the mail gets the money? Send mail to your friend and he gets 2 cents, he send you mail and you get the 2 cents back.
The other proposal I saw has much more expensive stamps, from 32 cents up to a few dollars. In that plan you you can keep re-using your stamps unless the recipient "redeems" the stamp. The idea is that it is generally "rude" to redeem a stamp. If you get legitimate mail from a friend or stranger you do nothing and it costs the sender nothing, if you get spam or otherwise offensive mail you click a button to redeem the stamp and the sender is out the money.
-
- - You can't take something off the Internet! That's like trying to take pee out of a swimming pool.
After signing up, the number of unsolicited phone calls I get has dropped to zero.
So what if it forces a majority of the spammers into using the [ADV] tag in their Subject headers? What is that going to accomplish? Yes, most ISPs will instantly block anything with [ADV] in the subject header but the spammers will still be using bandwidth to bounce endless waves of spam off of your filters in an attempt to get at the remaining mail servers which don't filter for one reason or another!
Beyond that, an [ADV] flag is content. As the subject of this post points out: The fight against spam needs to be firmly grounded in a lack of consent -- not the slippery slope which any argument based on content quickly becomes!
It can't be just the first one. It has to be a bounty to everyone who tracks the spammer down and take them to court. Otherwise, it just wouldn't pay to do it. A better scheme:
1. Allow anyone to take spammers to small claims court for around $2K.
2. Make the person selling whatever is advertised in the spam be responsible for unless they are willing to file a criminal complaint against the spammer.
3. Explicitly make is illegal to advertise someone else's product without authorization (it's probably already illegal...). This is to enable #2.
4. If an ISP cannot identify the spammer, the ISP must pay the fine. This may already be the case, but making is explicit would help.
An engineer who ran for Congress. http://herbrobinson.us
The reason they're hard to catch is that for legal action, money and time is required. There has to be a real prove to have VISA lock you out. Otherwise a smart spammer could spam around your URL, and you'd be in trouble. So just whois records won't do.
Also, what about foreign spammers using foreign hosting-companies and banks. They're not likely to stop spamming.