I believe the solution to the spam problem was announced at some point. Basically, to send waves you must have an SSL certificate for your wave server. I'm not sure whether these can be self-signed, but if not this surely would be a great solution to the problem that spam has become. (I love self-signed certificates for websites as a lower-level security mechanism, but non-self-signed certs are nearly flawless for identifying who an individual is and who is accountable for that site, or in this case wave.)