Lessig Wagers His Job On Anti-Spam Theory
kien writes "Lawrence Lessig is betting his position at Stanford on his anti-spam legislative recommendations. From his blog:'First the analysis: Philip Jacob has a great piece about spam and RBLs. The essay not only identifies the many problems with RBLs, but it nicely maps a mix of strategies that could be considered in their place. But, alas, missing from the list is one I've pushed: A law requiring simple labeling, and a bounty for anyone who tracks down spammers violating the law. Here goes: So (a) if a law like the one I propose is passed on a national level, and (b) it does not substantially reduce the level of spam, then (c) I will resign my job. I get to decide whether (a) is true; Declan can decide whether (b) is true. If (a) and (b) are both true, then I'll do (c) at the end of the following academic year.' The Declan referred to in point (b) is Declan McCullagh." Update: 01/07 02:45 GMT by T : Speaking of whom, here is Declan's acceptance of Larry's bet.
Lawrence Lessig is betting his position at Stanford on his anti-spam legislative recommendations.
Umm...
You *don't* need LEGISLATION to fix this problem (isn't that what technology is for?). Fix the technology (or lack thereof), and you've fixed the problem. There are several very good ideas floating around out there that don't require an office of homeland spam in the whitehouse.
Stupid lawyers...
Life is the leading cause of death in America.
They missed the link to his idea
While I appreciate Lessig's intentions here, it usually takes a bit more than a wager to get Congress to pass a law. Perhaps if he backed it up with some cash, Capitol Hill might pay attention.
NO CARRIER
Fix the technology (or lack thereof), and you've fixed the problem.
Right up until someone comes up with new technology to get around your technology.
Because he knows that the legislation won't pass.
... joke, joke).
But if it *did*, he'd be majorly screwed, since a large percentage of the spam I receive, for example, comes from regions outside of the jurisdiction of U.S. National Legislation.
The spammers who are U.S.-based would merely move offshore. (Just think of the headlines -- evil legislation driving away lucrative American internet jobs
Eloi, Eloi, lema sabachtani?
www.fogbound.net
You *don't* need LEGISLATION to fix this problem (isn't that what technology is for?).
Especially since the legislation will do nothing.
Here goes: So (a) if a law like the one I propose is passed on a national level, and (b) it does not substantially reduce the level of spam, then (c) I will resign my job.The problem is it's being addressed on a national level. That won't stop the African scam artists "whose money is tied up" - hopefully their oppressors will beat them in the face with a rusty camshaft - or the Chinese wishes of good fortune and prosperity that I was continually getting from some shitty company selling latex products until I finally decided to blackhole China from my mailserver.
This might keep the Florida 21-year-old unwed mother of 6 children from spamming me from her dial-up ISP of the week. But the funny thing about national laws is that they don't apply outside the nation...
Fire and Meat. Yummy.
A cute gesture, true, but ultimately pointless.
I'm trying to teach myself to set people on fire with my mind... Is it hot in here?
Those are the same tired old complaints against blacklists, but now it looks like a 'visionary' has blessed them so everyone's going to ooh and aah all over again - "Now I get it, blacklists are bad!" Except they're not, and all the arguments he presents against them have been refuted in the past.
The point is, receiving mail is voluntary and blacklists are voluntary. If I'm an ISP, I damn well have a right to block all e-mail from China and Argentina and it has nothing to do with "geopolitics and democracy." Gimme a break! He's saying that developed countries are actually preventing more troubled countries from entering the democratic utopia that's supposed to be the Internet. Because 99% of the e-mail coming from those countries happens to be spam. The way he puts it, RBLs might as well be responsible for all the poverty and oppression in the world - how can we blame people, after all we took away their God-given right to send e-mail!
Listen to him complain about collateral damage - collateral damage is the point of blackhole lists! Damaging a rogue ISP's users is the solution, not the problem. If we didnt' punish these ignorant subscribers they would continue supporting spammers. Every subscriber to a spam-friendly ISP is voting with their dollars - for spam. Rogue ISPs have proven that they will not act against spammers until they are financially threatened, and the only way to do that is to damage their user base to the point that they start losing subscribers. Collateral damage IS the point of blacklists - otherwise they're useless.
He also exhibits a fundamental misunderstanding of blackhole lists, lumping them in with open relay lists. SPEWS doesn't list open relays, and this entire rant is tainted by the fact that he seems to think all blackhole lists do is block open relays. Relays are just one small source of spam. Spam-friendly ISPs are a greater threat to the well-being of e-mail, by far.
Answer me this Mr. Jacob, where will our utopian "geopolitics" be when the entire e-mail system is destroyed by spam? Hey, at least we didn't silence any of the poor starving people in third-world countries who were just dying to send their democratic message of hope and peace. Oh, what was that inspirational message from that wide-eyed Argentinian eager to join the global village? The message is "CUM-GUZZLING SLUTS LOVE THESE HORSES."
Did bounties do anything to curb crime in the Wild West? Significantly? Plus way back then people only cared if the bounty was high. $100, $500, $1000 was a boatload of money back then. Heck if I could make that much now per message I'd be happy. But it won't happen.
We already have $50 per message laws on the books (at least in CA) and with the exception of a hand full of publicized cases, there has been little uptake.
In a world where one should be able to retire off the earnings of a family AOL account, it's a wonder existing laws aren't enough. It's simply too much work for too little return. It's too time consuming to plow through the forged headers, sue Yahoo for account information for user 123jlk213lkj and then still get nowhere.
If there was a tough national anti-spam law I'd support it. But for the love of God, give it teeth. Include a sliding scale for infractions ($500 for first, $5000 second, $50000 third). Include jail time for forged headers, and force persons operating under the "business relationship" clause to offer proof of such relationship in the message (at least a link one can follow to verify the relationship as well as request that the relationship be terminated). Require that the transfer of such a relationship be opt-in.
If this type of bounty system was put into place, the war on spam may actually be effective. Otherwise, good luck.
I'll answer that in one word:
Ralsky.
This leaves me thinking: shouldn't it be possible to use the ham-fisted anti-hacking laws against these bastares??? Not for spamming, but for hijacking peoples' computers to do the spamming with. I'd love to treat these bastards to 6-10 behind bars. Far better than a $100K fine that would be little more than a locense fee.
I tried to get an agreement with the company for the right to sue on their behalf in return for me helping to lock down their systems... They didn't go for it. My alternative approach is that I'd like to set up a similar system, wait for them to hack into it, and then do a hunt for the bastards running the scam. Any holes in this plan? (other than the probable difficulty in properly trackingg these people down?)
OS Software is like love: The best way to make it grow is to give it away.
that is, even if the law was ever passed.
How can this guy forget that the internet is not contained entirely within the jurusduction of the US?
It's nor like the spammers need to move elsewhere anyways, all they need is some non-logging proxy outside US borders and they can post with impunity.
Let's not forget the number of spammers already located outside of the US, either.
The internet just does not work the way this guy thinks it does: there is never going to be a day when everyone just follows the rules and plays fair
The way to handle spam is not with laws, it's with technology. Legislative bodies move too slowly and don't understand the technology, nor the scope of the internet.
What needs to be used is a combination of many different technologies: filtering, blacklists, whitelist, etc.
The internet is a huge shared network. So big, that prentending that you can trust every node on it is moronic. Software needs to be designed to recognize when a node is misbehaving and deal with it as well as possible. This goes for not just spam but other types of internet abuse, such as DOS attacks, trying 100 passwords in a row, etc. If a computer is going to be connected to an untrusted network it needs to be able to properly handle all kinds of unwanted data. To me that's just common sense.
Fraud laws don't stop me from getting Nigerian scam emails, do they?
The best way to fight spam is to develop software that isn't vulnerable to it, just like we fix other vulnerabilities. The reason we have spam is because our software isn't good enough.
Think of an unfiltered email systen as accepting input from a web form without doing any checking on the data it's recieving. It leaves you open to tons of really easy attacks. (If someone puts a meg of text in a field and submits it, your cgi scripts are probably going to go apeshit.) It's just bad design and it's about time we fixed it.
Life is too short to proofread.
yes they will be once they're out there - it's something that can't even be helped now. your argument is a good one for using digital certificates rather than imposed centralized record keeping, but not a good one for copyrights. sorry.
IP has a more prominent place in the information age, not less. Without it there would be no information age. It's central to running an economy. Having cheap knock-offs of your designs or technology made by China or whoever is fine for consumers, but who put up the money to create the technology in the first place?
if I loose a million in IP rights but gain a trillion worth if IP from everywhere else in the world then that is not a net loss. ps necessity is the mother of all inovations not IP.
Even something like Linux is merly a knockoff of technology created by large corporations who rely on IP to make a profit.
you mean like how MS innovates by using all the FreeBSD code?
And no, the next big breakthrough will most likely not be created by some lone geek in his bedroom, but by groups of researchers being paid for what they do.
Uhh 90% of the utilities in your kitchen or anywhere else were not invented by a big corporation. not even 1% of the new innovation in music.
um, 24. Do I get modded up or down?
-Ted
-=-=- Quantum physics - the dreams stuff are made of.
1) The internet is international, so you can't have a US law.
2) A technological fix will fix everything.
These are silly arguments and here's why:
1) The US contains a large quantity of pc's and internet connections (if not most internet connections anymore). A law in the US alone will reduce the flow of spam massively, as these 300 million people use the internet disproportionately. Remember: he's just betting on reducing the flow, no eliminating it.
2) The second argument is a false dichotomy -- you can have both a law and a technological fix. There's no harm in having both, as often neither is a comprehensive solution. Why so negative?
The baby's fine -- please stop sending business cards.
If the cost could be driven up just a bit by legal and technical means, that would make it unprofitable and therefore it would disappear.
Finally, whilst pr0n can be served up from anywhere it's legal, there are a lot of products that require a US presence, and thus present a target for civil and criminal law.
Any sufficiently advanced technology is indistinguishable from a rigged demo
--Andy Finkel (J. Klass?)
"He simply refuses to understand that we are quickly entering into an age where either all information will be controlled or all information will be free."
Your assumption is based on the idea that nobody cares about copyright laws and will do anything they want no matter what. We're all born kleptomaniacs. But if that were true, the entire CD industry should have vanished the night Napster fist came on-line. KaZaa should be making serious dents in movie ticket sales. But neither you nor Valenti and Rosen can come up with information that supports your argument.
"He reminds me of the people who thought that the free states could peacefully get along with the slave states, but in the information age."
And you and those who hold similar opinions to yours remind me a little too much of John Brown for comfort.
I don't agree with you, but I certainly hope you're not modded out of existence. Yours is an interesting point of view; I'm going to have to think about your "slave-vs-free state" analogy.
:)
/. doesn't count. :)
However, I think Lessig's immediate resignation, as you suggest, would be a serious setback to the "freedom" of information. (And it's obvious you don't mean "as in beer".
If he is right that the middle way is viable in the long term, and he acieves it, then life will be pretty good. Information will be less free than in your ideal, but it will be much more free than it is now.
If he is wrong as you suggest, and the middle way is not viable in the long term, then his work does not harm your cause. In this case, it will be chiefly relevant for having moved people away from the belief that complete control is viable. Perhaps he will win a non-viable middle way, perhaps he won't... but either result improves the cause of freedom of information. (Keep in mind that this contest will take decades to win; the only close end is defeat.)
Information freedom doesn't have enough prestigious voices, speaking in places that matter, for any of them to be lightly cast aside. Whether you agree with him or not, Lessig is, at the moment, the most viable opponent to the idea of total information control*... and that idea must be defeated before we'll have the chance to quibble over the system that takes its place.
You may have valid reasons for spurning the middle way and its supporters. You should have a care, though, that in spurning the middle you don't end up on the side that you like least, for lack of allies.
*: This is a matter of opinion, of course... there are other candidates. But I haven't heard of anyone else arguing this before the US Supreme Court or other institution of similar importance. And no,
With reasonable men I will reason; with humane men I will plead; but to tyrants I will give no quarter. -- William Lloyd
What a great idea Mr. Lessig has. I've adapted his legislation to be Slashdot-specific. I'm convinced that if my legislation is passed, there will be a significant reduction in "In Soviet Russia" posts. If a) the legislation is passed, and b) it doesn't work, then I'll forfeit all my karma.
To add to the problem, you can't really make an effective commercial email without mentioning your product and where to get it.
Unless the spammer makes an HTML e-mail and puts the entire ad spiel in a PNG image.
You can't sell me a mortgage without mentioning mortgages in some way
You can't discuss your mortgage with your banker without mentioning mortgages in some way.
You can't ask me to help get your mail out of Nigeria without mentioning Nigeria
Your middle-school daughter can't ask you for help on a geography report on Nigeria without mentioning Nigeria.
I agree that an e-mail classification system can reduce false positives by including headers in the formula. In fact, applying Bayesian classification to specific header lines emulates the already-known spam blocking techniques, possibly with weaker drawbacks. For instance, Bayes on From: and Reply-To: creates a personal whitelist. Bayes on Received: creates a personal RBL.
Will I retire or break 10K?
It's information, not people.
Information is replaceable. That's what backups are for. People are not.
If someone nukes Los Angeles, then people are going to have more than just a little bit of a headache sending their e-mail. If someone nukes your mail server, then mail gets bounced for a few days, and that's it. It's not that important.
Collateral damage is *good* in this instance. Yes, people will have problems sending mail. Yes, people will complain to their ISP's about the REALLY IMPORTANT E-MAIL THAT MUST GET THROUGH. Yes, Tech support at said ISP (if there is any) will live through hell. Yes, customers will go elsewhere when the ISP doesn't fix the problem. And yes, people will be irritated, annoyed, and even lose money, but it's all because the ISP in question is run by boneheads who don't want to hire a sysadmin, and think that the spammer market is an untapped resource. Companies like this *deserve* to go broke. People who sell services to scammers are running around with huge blinking neon signs on their backs that say "kick me!"
The collateral damage we're looking for is exactly the sort of thing that unions do when they go on strike. They go out of their way to scare away the very customers that feed them in the hopes that upper management will starve first. When the workers go back to work, the company *will* be damaged in some way by the strike, but in the end, things advance, life goes on, and things improve for the better for everyone. The sooner people see the cluetrain coming, the better, but sometimes the whistle has to blow loud and long before anyone notices.
"No problem. I have the capacity to do infinite work so long as you don't mind that my quality approaches zero."-Dilbert
A US law can't have much effect, for the simple reason that most of my spam these days comes from outside the US. If you could wave a magic wand and stop all US-based spam, you'd hardly make a dent in it.
In fact, the majority of my spam these days comes in using one of the various eastern pictographic fonts. Not only can't I read it, I can't even make out the symbols. I might as well be getting 50 emails a day of line noise.
Technically, this is not a "bet". A wager requires that a potential direct consideration accrue to the winning party. Lessig more accurately labeled it a "guarantee", although it isn't clear how his resignation would be helpful to those who might harmed by ineffectiveness of his law.
I hope Larry doesn't have to resign: he doesn't seem to have much future as a professional gambler :-).