• Home
  • Insights
    • About Customer Insight
    • Ad Hoc Poll Results
    • Customer Insight
    • Green
    • Musings
    • Research Statistics
    • Top Performers
    • 495
    • RSS Feeds
  • Mobile UC
    • Mobile UC Business
    • Mobile UC Observations
    • Mobile UC Product Reviews
    • Mobile UC Service Reviews
    • Mobile UC Applications Reviews
    • Mobile UC Devices Reviews
  • Coms
    • IP Video
      • Video Conferencing Consultants
      • Telepresence Consultants
      • Video Conferencing Strategy
    • Applications
    • E911
    • Email
    • LANs & WANs
    • Messaging
    • Quality
    • Security
    • SIP
    • VoIP
    • VoIP History
  • Scores
  • Reports
    • Register?
      • Be Heard. Join our Panel.
      • Prize Winners Do Surveys
      • Unregister
    • Research Catalogs
    • Recovery Series
    • Collaboration
      • Exchange Review
    • Fundamentals
    • Messaging
    • Mobile UC
      • Alcatel-Lucent Users
      • Avaya Users
      • Cisco Users
      • Nortel Users
      • Product Manager's Guide
      • Siemens Users
    • Web 2.0
    • Pre-2007 Research
    • Comments
    • Brainshark Content Network
  • About
    • About Peter Brockmann
    • Contact Us
    • News
    • In the News...
    • Request a User Briefing
    • Request a Vendor Briefing
    • Full Disclosure Notice
    • Famous Brockmann's
  • David
Coms Email Challenge-Response Backscatter is a Bogus Argument

Challenge-Response Backscatter is a Bogus Argument

Thursday, 20 September 2007 05:58 Written by Peter Brockmann
User Rating: / 2
PoorBest 

Many email security pundits like to rail against challenge-response technology arguing various issues. One of them is the backspatter argument which goes like this:

Since spammers use forged email addresses challenge-response users unwittingly send email to forged users who didn't send the original message unfairly penalizing them for the protection offered to the challenge-response user. All this extra email has been called 'backspatter'.

I think the ‘Backspatter’ argument is a red herring (smelly fish to distract people from the truth). Here’s the logic:

My research shows that people are getting 11.5 spams a day on average despite the best efforts of spam filters. And if they’re 95% successful at removing spam, that means that their email inbox is a target for 11.5/0.05 = 230 spam/user/day.

Another recent study just completed (not yet published) shows that C/R users represent 5.6% of business email users. Well behaved C/R systems send out only 2-6% challenges with about 1% going to legitimate first time senders.

The question is of the 2-6% how many are actually forged?

My address hasn’t been forged by a spammer in a long time, except to send a message to me from me.

If the forged address is count is low (likely) say 1% then the probability of getting a backscatter message is 0.0000224 or 1 in 44,643 email. At the rate of 230 spam a day, that would be about once every 194 days. Of course honeypot operators are likely to be more vulnerable than others.

So, although one can argue that challenge-response is unfair to forged address users, this math shows that it is trivially unfair to them and at the same time both correctly and completely unfair to spammers. I’d suggest that that is a very reasonable side-effect of the technology.

< Prev   Next >

Add comment


Security code
Refresh

Send
Cancel
JComments

22% of users in Large companies do not read blogs.

Related Report:  Blogs in Large Companies

Login

  • Forgot your password?
  • Forgot your username?
Follow us on Twitter

Posts: All-Time Highest Rated

  • Why Register?
  • Guest Blog: Convincing Business Leaders About The Green Value of Their Low-Carbon Products
  • Internet on Us
  • 10 Most Popular Blog Entries of 2009
  • Brockmann Guest Blogs for No Jitter
  • Cisco Cius
  • Swatting Is a New Dangerous Sport
  • Cost Saving Strategies: Why Video Managed Services?
  • Identity Thieves Masquerade as Job Sites
  • Video Conferencing Consultants

Posts: Year's Most Popular

  • Why Register?
  • Mobile Apps Are Addictive
  • Now, I Have Seen It All
  • Taxes and Telecommuting
  • Breaking News - Avaya to IPO
  • Android Users Suffer Security Problems
  • Google Removes More Mal-Apps
  • Innovations in Screen Technologies
  • Applying Email Marketing Features to Personal Email
  • Where Have I Been?

Reports: All-Time Most Popular

  • Forums in Small Companies
  • Forums in Large Companies
  • The Problem With Email
  • Video Communications 2.0: Tips for Improving The Experience
  • The Manager's Recession Survival Guide video

Reports: Year's Most Popular

(c) Brockmann & Company 2002-2011 Scroll To Top