Danny Angus

Vague but Dire

[blog home] [web home] [flickr] [twitter] [contact me] [subscribe by email]
Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

Thursday, July 26, 2007

I Told you so!

In the previous post I predicted that postmaster@xxx would be too busy to reply, I got his reply just now..

Thank you for contacting XXX's E-mail Postmaster.
Because of the large volume of postmaster e-mail traffic, this response is automated.

LOL!

We keep spending most our lives living in the living in the Spama's Paradise

I just got an email today which appears from its headers to be a bona-fide bounce triggered by spam with my @apache address on it. I also googled for some of the people on the list, and they do indeed work where where it says they do. So I think its genuine.

I've quoted the whole thing below, the scary part is summed up by this sentence "A list of all the people to whom these addresses might refer appears below" and sure enough right below the stuff I quote there's a list of people who's address might match michael@xxx formatted like :

name: Michael xxx
send_email_to: mikex@xxx
phone: 007-234-4354
address: 695 XXX Road
department: XXX-Housekeeping

For heavens sakes! I've spent years trying to explain why returning "mailbox does not exist" can be used by spammers to harvest addresses, and then I find out that people are still doing this. Priceless. I've sent a mail to the postmaster@xxx asking him if he's insane. I don't expect a reply from the current incumbent any time soon, he's probably fighting off a mail-storm.

The text of that message:

I'm sorry, but we had problems delivering your mail.
The errors we encountered appear below. If you have any questions,
contact the xxxxx Postmaster as postmaster@xxxxx.yyy.
Please include a copy of this message with your correspondence.
--------

The following addreses each refer to more than one person in our
directory.
A list of all the people to whom these addresses might
refer appears below. You should resend to your intended recipient
using the address in the 'send_email_to:' field.

If your intended recipient is not on the list, then the person is
either not registered in the central directory or the address is
misspelled.

Thursday, January 18, 2007

Criteria for judging proposed "solutions" to the problem of spam

At:
http://www.killerbees.co.uk/draft-irtf-asrg-criteria-00.html

You will find a document which outlines an idea I've had for a while.

The thrust of the document is that while we don't know what the silver
bullet solution for spam is we do know some of the characteristics
which we expect it to exhibit.

We also know that very many ideas are presented on the asrg@ietf.org list which
fail to meet one or more of those criteria, this draft is intended to
provide a reference which describes those criteria, and could be used
as a partial statement of requirements for a technique to solve the
problem of spam.

Obviously this is just my own 2c at the moment, so let me know, preferably on the asrg list) what
your opinions are and I'll modify, abandon or replace this as
necessary.

FYI the abstract reads:

"The Internet Research Task Force Anti-Spam Research Group (ASRG) is
frequently presented with proposals for techniques for managing spam
from authors who wish to elicit an expert critique of their
proposals. In many cases proposals fall foul of issues and risks
which are well known and understood by members of the ASRG. This
Internet Draft is intended to enumerate and explain a number of the
more important of the criteria which tend to be applied. This
document will then serve as a normative checklist for anyone wishing
to present a technique to the ASRG."

Is spam going to kill SMTP?

I read this post about the scale of the spam problem today. Its pretty chilling, but I guess it was meant to be. As far as I can tell the question it poses is, are we're really looking at a doomsday scenario and if so should we now be considering the unthinkable and pull the plug on SMTP?
I'm assuming that we all agree that the problem of spam is a direct result of SMTP being designed without any of the controls necessary to protect the network from this abuse.
Can SMTP be revised or does it need a flag day? I don't want the character of email to change, but I'm fed up with trying to explain why the problem of spam is so intractable, perhaps its time to get some traction and stop flogging a dead horse. WDYT?