A few weeks ago I wrote the resigned and beaten words: “I’d like to officially announce that the war on spam has been lost.” And I meant it. Given today’s technology, spam has gone beyond the point where we can do anything about it. The flood not only continues unabated but grows week by week.
After talking to shameless spammers like those at SIXNET, SiteHoster and Feng Shui Paradigms, who all apparently feel that spamming is OK because they have bought an “opt-in only” list or that they are “educating” people about their technology or their bizarre philosophy, I know that something must be done. Something that works.
My despair stems from the use of today’s technology. But what might we do tomorrow?
I have seen a hint of tomorrow: I’ve been running an experimental spam filter developed by some friends that appears to identify something better than 90% of spam messages. This has enormously reduced the amount of spam I have to handle, but what could we do nationally?
How about this: Last week I suggested that the government should implement a top-down strategy to creating a national cyberspace security strategy.
Briefly, the idea was that the government should set and adopt standards for their own use and require everyone who deals directly with the government to use those standards, and everyone who deals with those organizations to abide by those same standards. Thus we’d create a network of security that would enforce and maintain good security practices.
Add to the top-down national cyberspace security strategy the requirement that everyone who wants to play in this trust hierarchy also uses Pretty Good Privacy (PGP) or something similar to communicate (we’d all have to use compatible systems).
PGP has the concept of a “web of trust,” where people who know you sign your “key” – a virtually unforgettable digital certificate – by attaching their key to your key as a reference. When they sign your key they effectively vouch for you. And if the person you present your key to trusts that person who sent you key, then by implication they can trust you.
There’s a whole rich architecture to this concept – see PGP: Establishing Trust and PGP Trust Models .
PGP isn’t that complicated and can be added to pretty much any mail system. And not only can it be used to establish trusted relationships, it also can be used to encrypt and sign any message or document.
Better still, the PGP concept works without centralized certification authorities, which would mean the government wouldn’t have to control a complex administrative infrastructure (whew!).
Once this system was in general use, when a message arrived your e-mail client would automatically first check whether it was from someone in your address book, and if so, then check to make sure that the message really was from that person. And if that sender wasn’t in your address book, your e-mail program could check to see if that person is trustworthy by checking who vouches for them.
By using rules such as no mail from untrusted sources and no HTML mail or attachments from anything less than completely trusted sources (PGP has the concept of partial trust), it would remove many security issues.
Further, it would make anonymous spamming effectively impossible and, where a known user tried to spam, they quickly would get the signatures on their keys revoked by the signers.
As a side effect, it also would have a huge affect on the spread of viruses and worms by making their transmission vectors completely known.
Such a strategy would not only preserve privacy, it would actually support a national cyberspace security policy. Will we ever get such a solution implemented, or am I dreaming?
Secure thoughts to backspin@gibbs.com.




