You are here: Resources > FIDIS Deliverables > HighTechID > D3.11: Report on the Maintenance of the IMS Database > 
Shibboleth feedback  Title:
SPAMGOURMET FEEDBACK
 

 

Spamgourmet feedback

 

Spamgourmet Identity Management System 

 

Verification of data – Instructions  

 

Please indicate with a Yes/No in the respective field of the following table the correctness / completeness of the data held in our database. If you find that the data is not correct and/or complete, please proceed with making the appropriate corrections / additions by appropriately filling in the next field (“Correction / Completion”). 

 

For a description / definition of each field, you can refer at Table B. 

 

TABLE A – Verification of Data 

Data held in database 

Yes/No 

Correction / Completion 

  1.  

Evaluation of IMS 

    1.  

Evaluator:  

Christian Krause 

Yes 

 

    1.  

Organisation:  

ICCP 

Yes 

 

    1.  

Date of evaluation:  

14-Oct-2005 

Yes 

 

  1.  

Identification of IMS 

    1.  

Sources of information:  

http://www.spamgourmet.com/

Yes 

 

    1.  

Version:  

 

No 

1.22 

    1.  

Manufacturer:  

diverse 

Yes 

 

    1.  

Nature:  

private 

Yes 

 

    1.  

Country:  

n.a. 

No 

USA 

    1.  

Regions:  

Global 

Yes 

 

    1.  

Language:  

ENGLISH 

No 

Various (15 total for user interface) 

    1.  

State:  

Available 

Yes 

 

    1.  

Open/Closed:  

Open IMS: the identities work with several systems or applications. 

Yes 

 

  1.  

Platform & Environment 

    1.  

Requirements:  

Browser, E-Mail client 

Yes 

 

    1.  

Number of users:  

>100.000 users. Server-software is OpenSource, but no installation-base apart from the developer’s service is published. 

Yes 

(there are other installations, but not published) 

    1.  

Standards:  

none 

No 

SMTP (but I may be misinterpreting this question – if it’s referring to privacy standards, then yes, it’s correct) 

    1.  

Description of Server - Side components:  

software is written entirely in PERL 

Yes 

 

    1.  

Description of methods:  

An account is created wherin the user’s mail-address is being stored. After registration, users can generate one-time addresses connected to their account. Mails sent to this address are forwarded only for a specified period, e.g. four times. 

No 

Text is correct, but I would substitute the phrase “limited use” for the phrase “one-time” 

    1.  

Descriptor of Client -
Side components:

Browser to register with the service, E-Mail client to receive one-time mail 

No 

Same comment as immediately above – substitute “limited use” for “one-time” 

    1.  

Seals:  

No  

Yes 

 

    1.  

Which seal:  

 

Yes 

 

    1.  

Third party:  

no 

Yes 

 

    1.  

Which third party:  

 

Yes 

 

    1.  

Features:  

The service hides the original mail-address. Since the specific username appears in every generated one-time address, there is only pseudonymity given. 

Yes 

 

    1.  

Screenshot picture:  

spamgourmet-screen.png

Yes 

(will have to trust you on this one) 

    1.  

Flowchart:  

none

Yes 

 

  1.  

Cost 

    1.  

Price:  

Yes 

 

    1.  

Comment to the Cost:  

 

 

 

  1.  

Type & Class of IMS 

    1.  

Type of IMS:  

Type 3: IMS for user-controlled context-dependent role and pseudonym management.  

Yes 

 

    1.  

Class of IMS:  

Class 2: Systems/applications with another core functionality. 

Yes 

 

    1.  

Functionality:  

Spamgourmet’s main purpose is avoiding spam. Generating multiple addresses is used as an instrument. 

Yes 

 

  1.  

Suggestions:  

There are two ways spamgourmet can be operated: 1. Make up addresses like "someword.x.user@spamgourmet.com", where "someword" is a randomstring and x is the number of mails that shall be received. 2. The above structure can be combined with "watchwords". These are user-generated and stored in the service. Only mails to addresses containing one ore more watchwords are forwarded. This makes it harder for attackers to construct a valid address from scratch. The service allows to create arbitrary mail-addresses and thus avoid spam, although linkability of these created addresses is not averted due to identical unique strings (the username) in all generated addresses. 

No 

Text is correct, but there are other features, including the ability to send email as if it came from a disposable address 

 

 

 

Shibboleth feedback  fidis-wp3-del3.11.report_ims_database_02.sxw  
15 / 15