Slashdot Mirror


Open Relays, Free Speech, and Virus Propagation

sirsnork writes: "There is a story about John Gilmore running an open relay that is being used by a virus to propagate running over at Newsbytes. His defence? He wants his friends to be able to send email through his server from whereever they are. You'd think he'd know better." Gilmore has been skirmishing with Verio for some time over his open mail relay. Is it a good thing because it promotes the free flow of information? Is it bad for promoting the free flow of spam? Do the ethics change because someone writes a virus that uses the server to propagate? Interesting questions.

452 comments

  1. What's his IP address? by Tony+Hoyle · · Score: 3, Funny

    I'll add his domain to my blacklist.

    I suppose he leaves his front door unlocked too so his friends can watch cable whenever they like?

    1. Re:What's his IP address? by FransUNC · · Score: 5, Insightful

      I suppose he leaves his front door unlocked too so his friends can watch cable whenever they like?

      I've done this plenty of times. I guess that's why the last time I came home my air conditioning was set on 50, the oven was still on, and all my french bread pizzas were gone. :[

      Jokes aside, there are sometimes that you just have to take responsibility for something. And this is one of those times. His refusal to close it is just plain a) apathy b) want for attention c) pathetic.

      Ok, maybe his defense is the same of that used by file sharing programs, which unfortunately might make hypocrites out of a lot of us who complain, but anybody with common sense would know how to handle this situation. Don't be rude, Gilmore, close the damn relay!

    2. Re:What's his IP address? by ichimunki · · Score: 1

      I don't see any similarity between file sharing programs and open email relays. File sharing requires me to sign on, and usually gives me fine control over who can access my files (just like if I set up a web or FTP server). I am not required to accept files from anyone who clicks my name in the user list. An open relay, however, forces me to accept mail from pretty much anyone (email that often has forged headers, etc).

      --
      I do not have a signature
    3. Re:What's his IP address? by RedOregon · · Score: 1, Flamebait

      That's right. And if his friends start selling crack out of his house, by gum, it's not his fault or his responsibility!

      Sheesh.

      Who's gonna hit him a few times with the cluestick?

      --
      Skivvy Niner? Email me!
      HEY! Look left just ONE MORE TIME!
    4. Re:What's his IP address? by FransUNC · · Score: 1

      I'm not making a comparision between the two, I'm saying that might could deny reliability just as file sharing programs do. These programs say that they just exist, it's the users that are providing and actually making the connection to share content. So no, there is no relation between open relay and file sharing...but there could be in how it's handled legally.

    5. Re:What's his IP address? by Zocalo · · Score: 4, Insightful
      Quoth the article:

      The address of the server, Toad.com, is one of 25 open mail relays hard-coded by its unidentified author into the W32.Yaha worm, according to analyses by anti-virus firms Symantec and Sophos.

      Quoth my shell:

      # nslookup toad.com

      Non-authoritative answer:
      Name: toad.com
      Address: 140.174.2.1

      # echo 140.174.2.1 >> /etc/mail/BannedIPs
      # /etc/rc.d/init.d/sendmail restart

      --
      UNIX? They're not even circumcised! Savages!
    6. Re:What's his IP address? by TRACK-YOUR-POSITION · · Score: 1

      I suppose open relay allows person A to send person B information they do NOT want to receive, while file sharing allows person B to get information that person A wants to share.

      To block the first to indulge in privacy and common sense, to block the second is censorship (unless you're just blocking p2p because of bandwidth concerns).

      But yeah, legality as always a different matter than truth...

    7. Re:What's his IP address? by Anonymous Coward · · Score: 2, Interesting

      The sad thing is that you think it's abnormal to leave your front door unlocked. When I was growing up in a small community in Ireland in the 1980s, we used to do just that. People looked out for eachother.

      (Now, in the same place, you wouldn't dare leave your door unlocked. Some drugged-up git from Dublin would drive down for the evening and trash you house, perhaps stopping to hold up the local post office.)

      It's sad.

    8. Re:What's his IP address? by Bonker · · Score: 2

      An SMTP relay can also be configured to use either password, email address or IP-based verification. There's no reason for him to be running an open server unless his 'friends' change email addresses regularly and cannot remember a password.

      --
      The next Slashdot story will be ready soon, but subscribers can beat the rush and slashdot the links early!
    9. Re:What's his IP address? by Jumperalex · · Score: 1

      I always get a kick out of seeing how nitch things find their way into mass culture. In this case making analogies between meat-space and cyber-space. Leaving the door unlocked, the crow-bar (horrible I might add), etc.

      Like once in an official Air Force performance report I read someone wrote that a troop was a "true McGyver" and I thought that was funny that McGyver has so become a topic for analogy.

      Well the point I'm crawling towards is I wonder how long it will be before people (not geek-types) start using cyber-topics as analogies.

      Anyone have any examples of things that originated in geek-dome but have pervaded their way into analogies and comparisons used by everyday folk?

      --
      If you can't be good, be good at it!
    10. Re:What's his IP address? by geekoid · · Score: 4, Insightful

      Just because you leave your door unlocked, doesn't mean strangers can legally come into your home.

      I'd love to see your statement if a cable company went after someone whoi did that.

      In other news: Just because you leave your car unlocked doesn't mean you want it stolen, either.

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    11. Re:What's his IP address? by ichimunki · · Score: 1

      That is why I specifically used the phrase "open mail relay". FWIW I consider Yahoo and Hotmail to be open mail relays as well and block them accordingly. However, I generally consider spam an end user problem, which requires us (users) to work together to create services that assist us in building blocklists and/or software that is intelligent or easy to use that allows us to build our own filters. Of course, one of the best ways to start is to just block all open known open relays. I agree, there's no good reason to run one.

      --
      I do not have a signature
    12. Re:What's his IP address? by Thuktun · · Score: 1
      Just because you leave your door unlocked, doesn't mean strangers can legally come into your home. [...] Just because you leave your car unlocked doesn't mean you want it stolen, either.


      Even though you many not want your car stolen if you leave it unlocked, and even though strangers can't legally enter your home if you leave it unlocked, anyone who deliberately avoids locking them, just to make a statement, shouldn't be shocked to find that someone abused the unlocked property.

      The time for leaving things unsecured for principle's sake is behind us, I think.
    13. Re:What's his IP address? by jon+doh! · · Score: 1

      interesting point i think. so if i leave my car unlocked and someone steals it and eggs someone else's house, am i liable for the damage done because i didn't lock my car? what about if i leave the keys in the car and the engine running?

      what if they steal the car specifically to run into a person?

      i'm all for turning off open relays, but i dunno..

    14. Re:What's his IP address? by jazman_777 · · Score: 1
      Just because you leave your door unlocked, doesn't mean strangers can legally come into your home. I'd love to see your statement if a cable company went after someone whoi did that. In other news: Just because you leave your car unlocked doesn't mean you want it stolen, either.

      Which goes to illustrate that laws don't stop criminals. They will steal cars with unlocked and locked doors, even though the law says it's illegal.

      --
      Slashdot: Failed Car Analogies. Amateur Lawyering. Anecdote Battles.
    15. Re:What's his IP address? by Tardigrade · · Score: 1

      To your insurance company; yes, you are liable. Your rates will go up in proportion to the damage caused.

    16. Re:What's his IP address? by autopr0n · · Score: 2

      FWIW I consider Yahoo and Hotmail to be open mail relays as well and block them accordingly.

      Why? You can't actualy send spam through those systems... it's just that people forge mail headers.

      --
      autopr0n is like, down and stuff.
    17. Re:What's his IP address? by Anonymous Coward · · Score: 0


      They will steal cars with unlocked and locked doors


      Locks are not a defense against thieves. Locks are a defense against other honest people.

  2. Jackass by the+eric+conspiracy · · Score: 2, Insightful

    This guy is a jackass. There are a number of ways to allow his friends to send mail without running an open relay.

    1. Re:Jackass by tcr · · Score: 5, Interesting

      I agree.

      But weird how the article said Gilmore, a life member of the Libertarian party, has accused Verio of censorship and said he configured the mail server to accept and forward e-mail from anyone in part so that friends could use it while traveling around the world.
      (Emphasis mine).

      Seems to imply there are other motives...

      --


      Information wants to be beer.
    2. Re:Jackass by SuiteSisterMary · · Score: 2
      has accused Verio of censorship and said he configured the mail server to accept and forward e-mail from anyone
      So, I'm assuming he doesn't lock his house, or car, because that would infringe upon my freedom to travel? Christ, my four year old used to use logic like that.
      --
      Vintage computer games and RPG books available. Email me if you're interested.
    3. Re:Jackass by eam · · Score: 4, Insightful
      My first thought after reading the materials on his web page was: Man, what an idiot.

      It is unfortunate that Verio caved. On his page he says:
      When thugs come onto your block and go from door to door telling you that if you don't change how you run your business, your knees will be broken, and your children harassed until you leave town, what do you do? Lots of people change their business or quietly leave town.
      Unfortunately, he doesn't seem realize that HE is the thug who is forcing Verio to change how they run their network.
    4. Re:Jackass by lexarius · · Score: 1

      Actually, he was there first. Verio bought up the people who provided the T1 the isp he runs and now they want him to run his isp differently.

    5. Re:Jackass by Anonymous Coward · · Score: 0

      You think this Gilmore is a fruit, take a look at this site, www.ds-darkdesires.com. Talk about people that need a cluestick!

  3. Why an open relay? by Spock+the+Vulcan · · Score: 2, Informative

    If he wants his friends to use the server from anywhere, why not use an authentication scheme like SMTP AUTH or POP-before-SMTP?

    1. Re:Why an open relay? by aNonMooseCowherd · · Score: 2, Insightful

      An open relay is a public nuisance, like leaving loaded weapons out where anyone can take them.

    2. Re:Why an open relay? by sharkey · · Score: 2

      Or, possibly more apt, mounting a loudspeaker on your car, a la Blues Brothers, and playing Yoko Ono albums at full blast.

      --

      --
      "Outlook not so good." That magic 8-ball knows everything! I'll ask about Exchange Server next.
    3. Re:Why an open relay? by wampus · · Score: 1

      No, people operating open relays need to be kicked in the balls a few times... people playing Yoko Ono in public should be decapitated and their head mounted in a prominent place.

    4. Re:Why an open relay? by ethereal · · Score: 1

      "You two girls!"

      --

      Your right to not believe: Americans United for Separation of Church and

    5. Re:Why an open relay? by Anonymous Coward · · Score: 0

      shhhhh. he's not smart enough to run a POP3 authenticated SMTP server.

    6. Re:Why an open relay? by Arker · · Score: 2

      Obviously because he wants them to be able to send anonymously as well. I can see that. What I can't figure out is why he won't disable *bulk* anonymous access. The ISP in this case is being quite fair, that's all they are requiring from what I read.


      John Gilmore is a great guy. He deserves boukou respect, he's really one of the founding fathers of the internet. But it sounds like he may be suffering from a bit of senility at the moment *sigh*.

      --
      =-=-=-=-=-=-=-=-=-=-=-=-=-=-
      Friends don't let friends enable ecmascript.
    7. Re:Why an open relay? by Anonymous Coward · · Score: 0

      it sounds better than the beatles, man they suck, the funny part is I'm not trolling, I really hate the beatles, which is why i'm posting AC

    8. Re:Why an open relay? by Thuktun · · Score: 1

      I find it difficult to believe that no one has informed him of these in the past. Therefore, one has to conclude either that he is (a) stubbornly sticking to open relays due to principles or nostalgia or (b) unable to figure out how to implement these methods.

      I'm not sure which is the case, but either way he'll claim (a).

    9. Re:Why an open relay? by Anonymous Coward · · Score: 0

      then, he could set up a mixmaster / anon remailer,
      like the ones at anon.lcs.mit.edu and such

      OK, 90% of those are now used by mailing list and
      usenet trolls, rather than people in danger of their
      lives or jobs trying to post anonymously ... but still..

      If he just wants roaming users (and yup, toad.com does
      stamp the IP of a guy sending mail through it ...) then
      I don't see any need to run an open mail relay at all.

      Gilmore falls into the idiot savant category. Clued
      enough to have been around the *nix world for years - and
      to write tar. Stupid enough not to realize that the
      'net is no longer the old fashioned wild west days, where
      you could just rope one of your neighbor's horses, ride
      him off somewhere, and then set the hoss loose when you
      were finished so he'd come home. Or butcher one of your
      neighbor's cattle for food when you were passing through
      and hungry... with the understanding that your neighbor
      would do so as well. Within limits, this "me casa, su casa"
      thing worked quite well.

      The 'west got out of that habit courtesy range wars and
      barbed wire fencing. Anyone borrowing horses and cattle
      would later be called a horse thief and a rustler, and shot
      or hung.

      The 'net got out of that habit because of spammers and 31337
      h4x0r d00dz.

      Gilmore is a maverick, in the same sense that Sam Maverick was.
      He would not brand his cattle, so riders moved in and branded
      them as one of Maverick's.

      --srs (suresh @ hserus . net gpg EDEDEFB9)

  4. It's bad. by strredwolf · · Score: 4, Insightful

    Gilmore should know better. Verio's being majorly blocked by this person, and when Verio gets a clue, they may get their laywers in on the game and sue him.

    He should at least know how to lock the server down to use SMTP Authorization. Even better, if he wants his friends to communicate freely, he should give them Unix shell access. Open relays being free speech? YEAH RIGHT! There's no goverment there, so the First Admendment does not apply! (If you think otherwize, REREAD your Admendments.)

    --

    --
    # Canmephians for a better Linux Kernel
    $Stalag99{"URL"}="http://stalag99.net";
    1. Re:It's bad. by Anonymous Coward · · Score: 5, Insightful

      So basically, you're saying that instead of going after the people that are breaking the law, we should go after the people that are facilitating it? It's not his fault people are using his service illegally, just like it's not the fault of Morpheus or Kazaa, as I've heard justified many times on this forum. Perhaps we should outlaw computers, because after all, they enable people to break the law. Same for cars, right?

    2. Re:It's bad. by xonker · · Score: 2, Interesting

      when Verio gets a clue, they may get their laywers in on the game and sue him.

      I don't see why they don't just cut him off entirely. Surely their ToS allow them to disconnect any customer who has an open relay.

      Since they have that option, I can't see that they'd have grounds for action. But it's insane that Verio is letting this loudmouth intimidate them into continuing his service.

      I do wonder if it'd be possible for another ISP or the recipients of spam sent through his relay to sue him for negligence. Wish I had the money to do so.

    3. Re:It's bad. by RazzleFrog · · Score: 1

      So basically, you're saying that instead of going after the people that are breaking the law, we should go after the people that are facilitating it?

      Why can't you go after both? In a way he is an accomplice. He knows that illegal activity is being committed through his server and there is an easy way to prevent it and yet he doesn't. It is like owning a gun, knowing that somebody is using it to kill people, and not putting it under lock and key.

    4. Re:It's bad. by strredwolf · · Score: 5, Insightful

      You're missing the point, already. Verio has a ton of spammers that it knows about -- spam complaints keep flooding in, SPEWS/SBL keeps tightening the noose, independent sysadmins keen adding them to their own private lists. Verio should of gotten a clue by now... and it hasn't. It's forgotten.

      However, to address your question: Only in a few states is it illegal to spam, and even then the spam has to violate a few basic rules. Fortunately, spammers are stupid (Rule #1) and spammers lie (Rule #3). There is no federal anti-spam statue because our (USA) goverment is that slow! (The only good thing they're doing about spam is prosecuting the fraud that results from the spams to begin with. Eh, as much as we can get, we'll take it).

      BUT, the entire Internet community has said "Close your servers, they are being abused." The guy hasn't. It's being abused. Negligence? Aparently so. Conspiracy to spam? Maybe. The server's listed on blocklists. The guy hasn't fixed it yet. He's virtually required, or his ISP gets wind. His ISP is Verio. They've been sent notice. Neither he nor Verio has fixed the problem in a timely matter. The only recorse is to block all of Verio, because they're not playing nice.

      Now, you say about outlawing the tools. Is Napster/Gnutella commiting copyright violations? No, they make software that shares files eazily. Any file. Every file. You configure it. It's a *general purpose tool*. It's like a car or a computer. That's ok, we shouldn't outlaw that. We should outlaw *specific purpose tools* -- programs which have only one or two functions which allow the user to break laws. Spamware falls under specific purpose tools. E-mail gatherers/spiders fall under specific purpose tools.

      --

      --
      # Canmephians for a better Linux Kernel
      $Stalag99{"URL"}="http://stalag99.net";
    5. Re:It's bad. by b1t+r0t · · Score: 4, Insightful
      Even better, if he wants his friends to communicate freely, he should give them Unix shell access.

      Even better yet, give them SSH access. Then they can port-forward to his mail server from the inside, where there are no open relay problems.

      Either way, if he's really only leaving the relay open for his friends, and not for so-called "friends" whom he's never met before, he should make them prove their identity as his friends through some means of authentication. There is no reason that I can think of that should require him to run an un-authenticated server so that a handful of people can use it.

      --

      --
      "Open source is good." - Steve Jobs
      "Open source is evil." - Microsoft
    6. Re:It's bad. by schon · · Score: 1

      OK, I realize you're just trolling, but I'll bite..

      It's not his fault people are using his service illegally

      Yes, it is.

      It's his decision to run an open relay. There is no reason for anyone, anywhere to have one.

      He knows that people are using it "illegally", and yet he allows it to continue, therefore, it IS his fault.

    7. Re:It's bad. by prizog · · Score: 2

      "E-mail gatherers/spiders fall under specific purpose tools."

      Not so. I wished I had had one earlier today. I was pursuing a GPL violation for the FSF. I had found out who was doing it, and what they had done. I drafted a letter to be sent pending approval by RMS. Then I went to fill in the To: field, and realized that nowhere on the site could I find an email address (but I didn't check every page -- it's a big site). I ended up putting in webmaster@ and crossing my fingers. If I had had one of those email spiders (and if they were Free Software, of course), I could have used it for this legitimate purpose.

    8. Re:It's bad. by Elik · · Score: 1

      I agree it is bad. Gilmore should realize that since he is advocating the Open Relay on his email server, he also opening himself up to various blacklists and potential lawsuits, particularly in California.

      What I understand, he is one of the outstanding members in the Internet Community, but it seems he have lost some sense of the internet honor system and common sense. He have several methods of closing off the open-relay but his refusal to do so just make it lot harder for him.

      Not sure which version of the SMTP Dameon he is using, but pretty much all have several options of how to close off the Open Relay to secured server.

      There is SMTP-Authentication, which he can do with /etc/password or virtual /etc/mail/password list for non-shell accounts. There also POP before SMTP, which is little less secure, but still works well.

      First Amendment do not apply when it comes to Open Relay Server, since the email server is just basically a means of transferring the traffic of the emails from one person to other. And also look at the fair use policy of the bandwidth as well. If the Open-Relay Server is used excessively, the Upstream Provider have every right to cut off the service due to the contract of fair use policy of the bandwidth on their network along with Spam Usage. This guy must have missed the point about the spam since people can get around by writing a program to change the sender's email address everytime for each spam so he can stuff tons of emails though the open Relay dispite of his modification.

      I know I can, since it is sort of trivial to write a program to forge the email headers and rewrite all the sender's email address for every emails to bypass his mechanism at his email open-relay server. Plus...since he is maintaining the Open Relay Server, he is considered an ISP, even not officially since he run the email server for others to use. So...he have liability factor that he have to deal with people who can take him to court for aiding the spammers to use his service. Look at the several companies that was target of lawsuits because of the spamming methods they have done. So..he is making himself one of them.

      Verio have legal options to deal with him since he is the user of the Verio's service, not the other way around.

      --
      -- Amazing how the Internet still humms along.... -- Dispite all the flaws of Micro$oft in their software!
    9. Re:It's bad. by Dimensio · · Score: 2

      In absence of known contact addresses I go with webmaster@, postamster@ and hostmaster@. Sometimes support@ and abuse@ if it's abuse.

      You might have been able to get what you needed with the assistance of a standard webspider and grepping the output for "@" or "mailto:". There are legitimate spider programs (that's how most search engines get their data), the illigitimate ones are the ones that are specifically designed to search for addresses, especially if they ignore robots.txt.

    10. Re:It's bad. by Dimensio · · Score: 3, Interesting

      Verio allows postmastergeneral.com, a known spamhaus, to operate. I don't think that they are going to be concerned with the negligence of one of their customers facilitating criminal activity when another of their customers is openly engaging in criminal activity.

    11. Re:It's bad. by JohnnyX · · Score: 1

      Now, you say about outlawing the tools. Is Napster/Gnutella commiting copyright violations? No, they make software that shares files eazily. Any file. Every file. You configure it. It's a *general purpose tool*. It's like a car or a computer. That's ok, we shouldn't outlaw that. We should outlaw *specific purpose tools* -- programs which have only one or two functions which allow the user to break laws. Spamware falls under specific purpose tools. E-mail gatherers/spiders fall under specific purpose tools.

      But is an open relay a specific purpose tool? Methinks not. Not that I disagree that everyone's within their rights to block or not block whomever they please, but an open relay has more uses than spamming.

      Yours truly,
      Mr. X

      ...complicated problems don't have simple solutions...

    12. Re:It's bad. by xonker · · Score: 2, Insightful

      It's not his fault people are using his service illegally

      It's his fault that they are able to, however. He is aware of the potential for harm and does nothing (or very little) to abate the problem.

      The question is really this: does Verio have the right to cut him off? I'd say they do. It's their network, they receive lots of complaints, ill-will and their other customers suffer because of this man's actions.

      The difference between his situation and the file-sharing services is this: He is buying a service from Verio, they have a right to set the terms of service. They are not a government entity, they are not bound by any first amendment considerations -- even if this is a free speech issue, which I would say it is not.

      OTOH, the file-sharing services have done nothing wrong by providing their service. The record companies should be going after individual users, not Kazaa or Napster or Morpheus if they're guilty of trading copyrighted material. They offer a legitimate service and there is no easy way to filter "legal" content from "illegal" content. There are easy ways to filter who can use a mail server and who can't. The fact is that this jackass doesn't want to set up authentication, which would solve the problem quite handily

      Does this guy's open relay have legitimate uses? Sure, but the fact is he's not providing it on his own network -- he's providing it on someone else's service. Verio has the right -- even the responsibility -- to terminate his service. The whole thing about MAPS and so forth is a red herring -- they simply publish a list of offending servers, which many ISPs and users choose to subscribe to. If people didn't feel so strongly about getting spam, they wouldn't use these lists.

      I don't believe the record companies should have the right to terminate the existence of a service that might infringe on their interest when it also has legitimate uses -- they should have to pursue the people who are actually guilty of sharing copyrighted material. Whether Morpheus or Kazaa should cancel the service of people who abuse their service or assist the RIAA in prosecuting them is the real question. They probably should, though that would make them very unpopular.

      The fact here is that the RIAA is loathe to try to sue 200,000 people who are illegally copying material because that would be a PR disaster. Even if they could make their case in court, they would piss off millions of people -- and that's not good for business. Verio is already pissing off people by allowing this open relay to continue to exist.

    13. Re:It's bad. by wunderhorn1 · · Score: 2, Informative

      RFC 2142 outlines the standard mailbox names that every organization should have. (I tried to paste the list in, but the stupid lameness filter kept complaining about "junk characters".)

      --
      Karma: Bored. (Thinking about resurrecting the "Anyone else is an imposter" joke.)
    14. Re:It's bad. by Grylle · · Score: 2, Informative

      postmaster@domain is required to exist (RFC-822) (see http://www.ietf.org/rfc/rfc0822.txt)

    15. Re:It's bad. by MisterBlister · · Score: 1
      Yes, it is.

      It's his decision to run an open relay. There is no reason for anyone, anywhere to have one.

      He knows that people are using it "illegally", and yet he allows it to continue, therefore, it IS his fault.

      All of the arguments you make apply equally to Napster and other P2P sharing networks. That's the original poster's point. The general population of Slashdot has very different views of P2P (go after the user!) vs open relays (shut it down!) even though at its heart they are the same issue. The reason is obvious -- everyone likes free warez and porn, but nobody likes spam, but that doesn't change the fact that there's a double standard at play.

    16. Re:It's bad. by mkettler · · Score: 2, Informative


      Yes, but in this country there is a concept referred to as negligence. I am not a lawyer, but if my understanding of the law is correct if you are knowingly negligent in securing a resource which is known to be able to cause harm (monetarily or otherwise) when stolen, you are in some manner liable for the damages caused. Correct me if I am wrong, but if I ran a gun store and refused to lock the door when i left at night, despite being warned that kids were walking in and stealing the guns, I would be guiltily of manslaughter (at least) if one of those guns was used in a murder. Given that I premeditatedly chose to keep the store unlocked despite being advised of the risks, it might even be 1st degree murder (I'm not sure, IANAL as I already said).

      I am not an "expert" in the field of mailserver security either, but it is my opinion that this is a cut-and-dry case of negligence on Johns part, and I am disgusted that he would go so far as to try to abuse the first amendment in this manner.

      This security problem is so well known, and so well documented there's even an RFC on the matter, RFC 2505. And while this RFC is a description of current best practices, not a protocol requirements document, the list of recommendations under section 2 specifically states:

      1) MUST be able to restrict unauthorized use as Mail Relay.

      Don't believe me, go here:
      http://www.ietf.org/rfc/rfc2505.txt

      This implies to me that despite the existence of technical methods to solve this problem (SMTP authentication for one), and having been advised of the impact this is having on others, John Gilmore is bent on ignoring industry standard practices for properly securing a mailserver. Even Yahoo can figure out how to configure their SMTP server to use authentication, and the eudora mail client that Gilmore specifically mentions on his page is capable of using SMTP auth (I know, I use eudora and have a yahoo account).

      So how exactly is this a matter of free speech and not an attempt to contain the damage caused by a negligently configured mailserver operated by an administrator who is not ignorant to the industry standard methods of preventing the problem, and appears to be merely ignoring such standards for the sake of convenience? Sounds a lot like a "well, locking my store is a hassle because I have to remember to bring my keys with me when I go to work so I leave my gun store unlocked" argument. (admittedly the damage caused by this is much lower than a gun store, but it is fundamentally the same argument he's making)

      On his page Gilmore also makes the argument that the filter Verio has placed upon his internet connection is sufficient to stop the damage, this gives them no grounds to terminate him. What I believe that Gilmore is failing to realize is that he is placing the responsibility for correcting his own security problems on Verio. Now, due to the negligence of one of their customers, Vero has to maintain a filter to ensure that customer does no damage, and you could even make the argument that if the filter fails, now *they* are negligent and liable for the damage caused. If I ran and ISP I certainly would not want that liability.

      Now Verio is considering not disconnecting him because he's agreed to do some form of rate limiting? Sorry, this is not the proper solution to this simple problem.. it merely reduces the rate of damage caused to a less problematic level.

      (yeah, I'll secure the gun cases so you can only take one gun out every five minutes, which will prevent someone from coming in and taking more than one gun at a time, because I still don't want to put a lock on my door, even though the lock is free and I can install it myself.)

      I'm sorry Gilmore, you've been around the internet block several times more than I have, but I don't see how your arguments of free speech hold water. I'm also quite concerned that your actions are weakening the strength of the name of the EFF by associating them with a free speech argument which seems to consist of little more than baseless litigation. I expect legal cases with common-sense holes the size of Texas in them from the legal department of Amazon (patenting affiliation sales?) but I do not expect the name of the EFF to be associated with such frivolous matters.

      Censorship? Bah! Get off dead center and secure your systems properly.

      --
      -Matt
    17. Re:It's bad. by Grab · · Score: 3, Funny

      SlashDot Pedants' Dictionary: "postamster" not recognised. Suggested replacement: "post hamster".

      Grab.

    18. Re:It's bad. by ahde · · Score: 2

      but usually doesn't

      root@localhost

    19. Re:It's bad. by gorbachev · · Score: 1

      Gilmore knows. He's been ignoring advice and outright offers of help to make that SMTP server to use SMTP auth.

      Either he wants spam and other internet abuse flowing through that server or he's just not as bright as they say he is.

      I'd say he's a stubborn moron and an Internet abuser, no better than spammers.

      --
      In Soviet Russia, I ruled you
    20. Re:It's bad. by Anonymous Coward · · Score: 0

      Finally, someone figured it out! My god, people are idiots, huh?

    21. Re:It's bad. by ahde · · Score: 2

      does Verio have the right to cut him off? I'd say they do. It's their network

      That's the problem. Where is he supposed to go for an upstream provider? THere are only a few dozen major providers. And everyone, ISPs and all, have to go through them. I realize it's not popular to say so, but choice is essential for freedom. Remember when AT&T was broke up into 13 companies? There are 4 left. How's your phone service? How's your DSL? Congress just killed off all the CLECs and ISPs.

      I hope you trust Verizon, Cingular, and Qwest/Microsoft.

    22. Re:It's bad. by mech9t8 · · Score: 2

      Well, part of the problem is a matter of practicality. It is very easy to enable SMTP authentication. It is not very easy to have a system that checks to make sure every song that's transmitted is legal.

      One can close Open Relays without affecting their intended use (ie. With authentication, friends/client/whoever can still send e-mail). One cannot shut down sharing copyrighted files without shutting down ALL file sharing.

      --
      Convictions are more dangerous enemies of truth than lies.
      - Nietzsche
    23. Re:It's bad. by Anonymous Coward · · Score: 0

      I would say you are a paedophile. No better than child rapists.

    24. Re:It's bad. by Cinnibar+CP · · Score: 1

      BUT, the entire Internet community has said "Close your servers, they are being abused." The guy hasn't. It's being abused. Negligence? Aparently so. Conspiracy to spam? Maybe. The server's listed on blocklists. The guy hasn't fixed it yet. He's virtually required, or his ISP gets wind. His ISP is Verio. They've been sent notice. Neither he nor Verio has fixed the problem in a timely matter. The only recorse is to block all of Verio, because they're not playing nice.

      Whoa, hold on a second here! Gilmore's server is abused by spammers, so he's a victim, right? Why are we blaming the victim?

      All this blacklisting like saying we should weld car doors shut for people who have thier cars stolen. Gilmore's arguement is that SPAMMING is illegal, not the running of an open relay server, and he's entirely correct, IMHO.

      The whole concept of "enabling criminals" is patently false. Criminals commit crimes because there is inadequate deterrance, not because the tools are readily available. Hardware stores are not at fault for selling crowbars if criminals use them to break into our houses. Crowbars have MANY legitimate uses. Don't boycott a store that sells them, similarly, don't knee-jerk and blacklist this dude without hearing him out.

      The penalties for the crimes need to be applied to the criminals, not the people that are as much innocent victims as us.

    25. Re:It's bad. by alanwj · · Score: 1

      Even better yet, give them SSH access. Then they can port-forward to his mail server from the inside, where there are no open relay problems.

      Slightly off topic, but could you (or anyone else) explain how to do this?

      Currently, to send mail from my account at my university, I have to SSH in and use something like pine from the inside. I would much prefer to use my local mail client (KMail), even if I still have to establish an SSH connection first.

      Alan

    26. Re:It's bad. by poot_rootbeer · · Score: 2

      We should outlaw *specific purpose tools* -- programs which have only one or two functions which allow the user to break laws.

      You mean like DeCSS?

      You mean like Elcomsoft's eBook cracker?

    27. Re:It's bad. by ethereal · · Score: 1

      Those damn trolls - now they're filling up the RFCs with their page-widening tricks. The horror!

      The lameness filter wouldn't pass.

      --

      Your right to not believe: Americans United for Separation of Church and

    28. Re:It's bad. by Viking+Coder · · Score: 2

      It's not an either-or proposition. You go after both. People who facilitate breaking the law are also known as "accomplices".

      If it is within your power to prevent someone from breaking the law, and it poses no risk to you to do so, I would say that you are ethically obligated to do so. IANAL, so I don't know if you're legally obligated to do so.

      --
      Education is the silver bullet.
    29. Re:It's bad. by Surak · · Score: 1

      Near as I can tell, this looks like what he may have done.

      Here's the output from nmap:


      Starting nmap V. 2.53 by fyodor@insecure.org
      Host toad.com (140.174.2.1) appears to be up ... good.
      Initiating SYN half-open stealth scan against toad.com (140.174.2.1)
      ...
      Interesting ports on toad.com (140.174.2.1):
      (The 1507 ports scanned but not shown below are in state: closed)
      Port State Service
      13/tcp open daytime
      19/tcp open chargen
      21/tcp open ftp
      22/tcp open ssh
      25/tcp open smtp
      53/tcp open domain
      79/tcp open finger
      111/tcp open sunrpc
      515/tcp open printer
      540/tcp open uucp
      543/tcp open klogin
      544/tcp open kshell
      742/tcp open netrcs
      2000/tcp open callbook
      2105/tcp open eklogin
      6000/tcp open X11

      Nmap run completed -- 1 IP address (1 host up) scanned in 16 seconds


      Notice no smtp appears to be running, but ssh does appear to be running.

    30. Re:It's bad. by King+of+the+World · · Score: 0
      In common use of P2P for pr0n and warez an open handling of data is required.

      In common use of a mail relay to send messages to your friends being open is unneccessary. There are certainly steps to be taken here such as only allowing emails to be forwarded to his friends' addresses. If these international playboys change email address update the allow/blocklist.

      Now if you can think of a way in which de-centralised P2P can work without an open network please say. Otherwise the reality of the situation is far different.

    31. Re:It's bad. by Anonymous Coward · · Score: 0


      "and when Verio gets a clue, they may get their laywers in on the game and sue him."

      So we can sue other people for misconfigured
      servers now? Just yank his account, sheesh.

    32. Re:It's bad. by Precision · · Score: 1

      umm...

      25/tcp open smtp

      looks like a smtp server to me.

      --
      - U
    33. Re:It's bad. by xonker · · Score: 2, Interesting

      That's the problem. Where is he supposed to go for an upstream provider?

      That's his problem. Yes, there are plenty of potential problems with the lack of major providers and the consolidation of ISPs. But it's his fault he's been threatened with having his service terminated. He does not have to provide an open relay to run his business. If he cannot find an ISP that will tolerate an open relay, that should say something about how repugnant it is to run an open relay. It's not as if Verio is abusing their position as an upstream provider in this particular case.

      I realize it's not popular to say so, but choice is essential for freedom.

      I wasn't aware this was unpopular. The argument you seem to be making is that since there aren't very many major providers, they should have to tolerate customers who ultimately harm their other customers, refuse to follow their Terms of Service and cost the company untold amounts of money by wasting bandwidth and spreading virii. Remember, his open relay is probably spewing spam into hundreds or thousands of inboxes owned by other Verio customers -- chewing up bandwidth and other Verio resources and annoying their other customers -- not to mention giving Verio a reputation as a provider that tolerates open relays. (Someone else mentioned that Verio hosts other spammers. That doesn't mean that they shouldn't kick Gilmore, but they should also be getting rid of the other spammers as well.)

      Whether there are four major ISPs or four hundred, none of them should have to tolerate a customer like Gilmore. Endorsing their ability to kick a customer who runs an open relay is not an endorsement of any of their other business practices.

      If a smaller ISP hosted Gilmore, would it be okay for them to kick him? Should a mom and pop ISP have to host someone like Gilmore? If not, Verio should not be required to either.

    34. Re:It's bad. by Anonymous Coward · · Score: 0

      Ummm... You might want to read that list again. Look at port 25...

    35. Re:It's bad. by gimpboy · · Score: 2

      switch around the topics:

      its very easy to enable file sharing authentication (ftp without anonymouse access), its not very easy to configure sendmail so it checks to make sure each email message is not spam.

      one can close anonymous filesharing (with authentication). one cannot shutdown open email without taking away anonimity.

      this is alot of beating around the bush. very few people who use open realays do so to protect their anonymity. on the same note, very few people who use p2p networks do so to share files legally.

      --
      -- john
    36. Re:It's bad. by Cyberdyne · · Score: 1
      Notice no smtp appears to be running, but ssh does appear to be running.

      From the nmap output above:
      ...
      25/tcp open smtp

      Now, I think that looks a lot like an SMTP service running... just under the SSH service you commented on, in fact!

    37. Re:It's bad. by RollingThunder · · Score: 2

      Sure you can shut down open email without taking away anonymity.

      Just because the server verifies it's legit, does not mean it must pass that information on, or even log it!

      The server just needs to go "Ah, ok... this one's a good one", and queue it.

    38. Re:It's bad. by Matrim9 · · Score: 1

      That's fine, if the case if legal, but it's not. His ISP wants to give him the axe because he's causing them trouble, even if it's indirectly. If he can't get his act together, then why should his parent ISP have to suffer, too?

    39. Re:It's bad. by elmegil · · Score: 2

      Since about 1995 or 1996, nobody's paid any damn attention to the required mailbox names.

      --
      7 November 2006: The day Americans realized corruption and incompetence weren't addressing 11 September 2001
    40. Re:It's bad. by Anonymous Coward · · Score: 0

      Well, that machine looks like it has every possible port in the world open, someone should just root it and disable sendmail ;)

    41. Re:It's bad. by gimpboy · · Score: 2

      that would imply that the owner of the server gave the person an account--> the owner of the server knows the person with the account in some way. you could do the same with an ftp server and just not log file access and logins. i still think the argument goes both ways.

      --
      -- john
    42. Re:It's bad. by ahde · · Score: 2

      While you understand that he is is one of the outstanding members of the Internet Community, you should also understand that he isn't a DSL or Cable modem user serving MP3s over a poorly administered network. He pays for his bandwidth.

      What if he has a friend whose ISP is stupid (like most people), but that friend doesn't want to use hotmail or yahoo, so that friend can't send email when travelling unless they direct dial long distance to their ISP?

      Now that friend says, wait a minute, my friend John Gilmore has a mail server. I can point to his MX and send my email.

      Can you tell me another way to do this? Yes, if all his friends would get accounts on his server that would solve the problem. But, so would using hot mail. We're talking about people with existing accounts on other servers.

    43. Re:It's bad. by GreyPoopon · · Score: 2
      Gilmore's server is abused by spammers, so he's a victim, right?

      Oh, give me a break. He was a victim when it FIRST happened and he was notified. He stops being a victim when he doesn't implement any of the simple measures already mentioned.

      All this blacklisting like saying we should weld car doors shut for people who have thier cars stolen.

      No, it's more like saying we should take cars away from people who have them stolen over and over again and yet consistently leave them unlocked, park them in unguarded lots with a posted theft rate of over 50% and leave a big sign on the car that says "Steal me. I'm unlocked." I would wholeheartedly support preventing anybody like this from owning a car, as their negligence is only causing my insurance rates to go up. That's basically what a blacklist is doing for people who refuse to close their open relays.

      Hardware stores are not at fault for selling crowbars if criminals use them to break into our houses.

      This is hardly a valid comparison. In his case, the thief doesn't even need a crowbar. All they need is his address.

      Sorry. No matter how you slice it, he's not an innocent victim. Maybe if you put quotes around it....

      --

      GreyPoopon
      --
      Why is it I can write insightful comments but can't come up with a clever signature?

    44. Re:It's bad. by BroccoliGod · · Score: 1
      Fortunately, spammers are stupid (Rule #1) and spammers lie (Rule #3).

      I thought it was:
      #0- Spam is theft #1- Spammers are stoopid
      #2- Spammers lie
      #3- If a spammer seems to be telling the truth, see rule #2

      Back to nanae you go

    45. Re:It's bad. by orangesquid · · Score: 1

      I would say an open relay is a general purpose tool. They make it much easier to have hard-to-trace email (which has its advantages and disadvantages)

      However, on the subject of running an open relay...
      Everybody's suggesting that the guy force authentication of some sort.

      Authentication, IMHO, sucks.

      However, a friend of mine had an idea: Install spam filters on incoming mail whose origin is unverified... This would make it feasible to run an "open" relay and still give spammers a difficult time.

      --
      --TheOrangeSquid Is it any wonder things seem so awry? We swim in a sea of confusion and don't have to think to survive
    46. Re:It's bad. by operagost · · Score: 2, Funny

      Yeah, I think the original poster confused port 25 with port 110. Notice the other cool services running that should have been firewalled. I'm thinking about sending him some ASCII pr0n via 515.

      --

      Gamingmuseum.com: Give your 3D accelerator a rest.
    47. Re:It's bad. by prizog · · Score: 2

      They don't follow the GPL -- why should they follow the RFCs?

      Anyway, webmaster@ is one of the standards.

    48. Re:It's bad. by Anonymous Coward · · Score: 0

      hey, there's always a chance at some point one of their sysadmins decided to play by the rules...

    49. Re:It's bad. by ahde · · Score: 2

      The smaller ISP would be cut off by Verio. Which, by the way, he is.

      Just because you're ignorant doesn't mean you're right

    50. Re:It's bad. by Anonymous Coward · · Score: 0
      So basically, you're saying that instead of going after the people that are breaking the law, we should go after the people that are facilitating it?
      Have you ever tried to get the authorities to prosecute a minor crime with no headline value, especially one involving theft of service rather than the loss of tangible assets or bodily harm?

      Alternatively, are you willing to file a civil suit, knowing that your expenses will be 10-100 times what you have to spend? As things stand now, it is only practical to go after spammers in court if you are an ISP and have been repeatedly victimized. Even in states that have statutory penalties, you are looking at a long process with no guaranty that you will be able to collect on your judgement once you win it.

    51. Re:It's bad. by TheLinuxWarrior · · Score: 1
      In my opinion, it IS his fault. He is knowingly operating an open relay. Even if he didn't know, it is his responsibility to ensure that machines he runs are in compliance with rules the provider has in place. Ignorance is no excuse.

      If I were to do the same with my mail server, I would certainly expect my provider to cut my service.

    52. Re:It's bad. by Cinnibar+CP · · Score: 1

      No, it's more like saying we should take cars away from people who have them stolen over and over again and yet consistently leave them unlocked, park them in unguarded lots with a posted theft rate of over 50% and leave a big sign on the car that says "Steal me. I'm unlocked." I would wholeheartedly support preventing anybody like this from owning a car, as their negligence is only causing my insurance rates to go up. That's basically what a blacklist is doing for people who refuse to close their open relays.

      I guess the valid comparison would be that the RIAA is correct in it's harassment campaign to shutdown Napster and similar file-sharing services, as they(Napster, etc) leave the door unlocked to trading copyrighted software.

      It's NOT illegal to leave an open relay, not as far as I know.

      Portraying his open relay as a "Public Health Hazard" of the Internet is all fine and dandy if there are clear and precise regulations detailing what constitutes a hazard. Those restrictions/laws/regulations don't yet exist, people shouldn't be randomly forming organizations to "police" the internet using strongarm and blackmail tactics.

    53. Re:It's bad. by kelnos · · Score: 1
      Criminals commit crimes because there is inadequate deterrance, not because the tools are readily available.
      huh, funny. imho, not closing an open relay is inadequate deterrence.

      i really see no legitimate need for an open relay that can't be achieved by putting some controls on the server to prevent spam.
      --
      Xfce: Lighter than some, heavier than others. Just right.
    54. Re:It's bad. by Electrum · · Score: 2

      Slightly off topic, but could you (or anyone else) explain how to do this?

      Well, you could start by reading the manpage :) It's actually quite simple:

      $ ssh -L 2000:mail.example.com:25 user@host.example.com

      That will forward port 2000 on your machine to port 25 on mail.example.com, from host.example.com. It will stay in effect until you log out. If you just want to forward a port, then you can use the -f option. It still needs to execute a command, so give it something like sleep 900 (for 15 minutes). There might be a better way, but I don't know of one. Also check out stunnel. It might work with SSH.

      You could forward port 25 on your local machine, but then you would need to start SSH as root (so it can bind to the low numbered port).

    55. Re:It's bad. by Electrum · · Score: 2

      Can you tell me another way to do this? Yes, if all his friends would get accounts on his server that would solve the problem. But, so would using hot mail. We're talking about people with existing accounts on other servers.

      Give them shell accounts on the box, so that they can use either authenticated SMTP, or tunnel via SSH. Simple solution.
    56. Re:It's bad. by Anonymous Coward · · Score: 0

      I'm not sure those are equivalent. Anonymity is not a primary purpose of filesharing: you IP can always be traced. Similarly, SMTP open relays don't protect privacy as your IP will be revealed. So it seems weaker as an argument.

    57. Re:It's bad. by gimpboy · · Score: 1
      back up the thread some where someone basically said that people here had a double standard when it came to the two types of programs.

      the logic went something like this:

      statement 1:

      p2p network file sharing is ok it's just the users that abuse it so they should be sought after.
      seemingly contradictory statement 2:

      open mail relays are bad and the person with the mail relay should be held resposible.

      so what someone way up there in the thread was basically saying is if you agree with statement 1 and statement 2 simultaniously you're a hypocrite.

      i should also state that in my hypothetical world no logs would be kept to maintian anonymity.

      --
      -- john
    58. Re:It's bad. by mech9t8 · · Score: 2

      Point. Although I wouldn't consider "being able to send e-mail anonymously" to be a prime usage of e-mail, whereas "being able to obtain files shared by strangers" is a prime usage of file-sharing. In terms of actual privacy, neither means is effective, as both reveal your IP. If you want privacy, go to an Internet Cafe and set up an anonymous webmail account. (I don't think privacy is really a huge concern for file sharers: their use of file sharing is well known to their ISPs, and millions of neophytes who signed up with Napster used their real names for the signup forms.)

      Let's try another one...

      Shutting down Open Relays doesn't require the law to get involved: market forces will make sure that companies with Open Relays will be punished. Making sending spam harder benefits orders of magnitude more people/customers than it hurts. Companies that allow them will find themselves losing money. Customers that recieve spam, or can't send legitimate mail, will flock to other ISPs.

      Shutting down file sharing, OTOH, benefits a tiny minority (record companies) at the expense of millions of people/customers. Companies that shut them down will find themselves losing money as customers flock to ISPs that allow them.

      Thus, ISPs won't shut it down without The Law stepping in. And as soon as The Law steps in, things become a lot more complicated. There is no freedom to try another way; the right answer cannot evolve on its own. When The Law steps in, it's way things are, and there's nothing you can do about it.

      So an important difference is whether The Law controls what gets shut down, or whever it's simply a company's policy - which can be fought using the power of open markets.

      Of course, people will still complain if the major high-speed consumer ISPs shut down file sharing, but that's because the choices for high-speed consumer access are currently limited to two: The Cable Company and The Phone Company, both government-issued monopolies.

      And, of course, some people will bitch no matter what. ;)

      But the points are:
      - blocking open relaying benefits the many at the expense of the few
      - blocking file sharing benefits the few at the expense of the many
      - open relaying is shut down due to natural market forces
      - file sharing is shut down due to government interference in natural market forces

      That's in addition to...
      - blocking open relays doesn't affect (most) legitimate e-mail uses
      - blocking file sharing completely blocks legitimate, as well as illegitimate, file sharing.

      --
      Convictions are more dangerous enemies of truth than lies.
      - Nietzsche
    59. Re:It's bad. by DavidTC · · Score: 1
      No, that still won't always give you the correct address, even if they follow the RFC to the letter. If they are running a http server, webmaster should always be valid. But if they are running, say, only a ntp, or a gopher server, there are no names listed for those services.

      OTOH, if they aren't running an HTTP server, you couldn't run a harvester anyway. ;)

      I guess 'noc' might always supposed to be valid, but it's possible to argue a certain server doesn't have a network infrastructor. (And, in the real world, almost no one use noc anyway.)

      --
      If corporations are people, aren't stockholders guilty of slavery?
    60. Re:It's bad. by wunderhorn1 · · Score: 2
      The key term in the RFC is COMMON SERVICES. We could just require every open port to have its own email address, but that would be ridiculous to maintain. ("Hi, is your CHARGEN daemon running? Better go catch it!").

      And really, how many organizations do you know that run only NTP and no other services? ("Yup, we pay for a net connection just to keep our clocks synchronized!") I mean, gopher MAYBE, if were talking 1993 or something, but otherwise an organization is on the 'net it's bound to have http and email.

      Also, I think for a server to be useful, it ought to be connected to some sort of network infrastructure. Like, I dunno, a LAN cable.


      (OK I'mdone smartalecking for the day)

      --
      Karma: Bored. (Thinking about resurrecting the "Anyone else is an imposter" joke.)
    61. Re:It's bad. by khuber · · Score: 2
      The general population of Slashdot has very different views of P2P (go after the user!) vs open relays (shut it down!) even though at its heart they are the same issue

      I strongly disagree. P2P and email have different distribution architectures.

      Open relays allow you to distribute one thing to many people (one sending MTA to many receiving MTAs). P2P allows you to download one thing from one site (one P2P server to one P2P client).

      I don't think they are the same issue at all: email is a push technology (receiver has no choice), and Napster is a pull technology (only the receiver can choose).

      If P2P and email are equivalent, then downloading a web page and sending email are equivalent. They seem very different to me!

      -Kevin

    62. Re:It's bad. by DavidTC · · Score: 1
      No, Tier 1 NTP servers, like the one's run by the government, usually don't run anything else at all. Running HTTP just slows things down.

      That's my point, that no address at tier 1 NTP servers MUST be valid. Yes, there are hopefully other servers in said organization that will have contract information, but that doesn't change the fact there is no mandated contact address for that server.

      And 'noc' isn't for infrastructure problems with a server, it's for infrastructure problems with a network. Unless said server is a run by the people in charge of network infrastructure, it is not required to have a noc@ address.

      You know, all this is very simply proven by the fact no one is complaining about dialup users not having RFC mandated contact addresses. ;)

      --
      If corporations are people, aren't stockholders guilty of slavery?
    63. Re:It's bad. by autopr0n · · Score: 2

      It's a *general purpose tool*. It's like a car or a computer. That's ok, we shouldn't outlaw that. We should outlaw *specific purpose tools* -- programs which have only one or two functions which allow the user to break laws. Spamware falls under specific purpose tools.

      Uh huh. And I suppose you think we should outlaw DeCSS as well, right?

      Napster, Gnutella, et can be used for legit purposes, but in most cases isn't (porn is copyrighted to :P). DeCSS is even more dubious. If you define "general purpose" as having any non-illegal use, then all you have to say is that spamware can be used to send mailling lists

      --
      autopr0n is like, down and stuff.
    64. Re:It's bad. by wunderhorn1 · · Score: 2
      I realize single servers might run only one service, I was saying that within an organization there's bound to be a couple of the serivces running that require email addresses.

      I don't see why a single server has to have an email address. As long you can get an address within that organization's IT staff, ideally you should be able to get in contact with whoever you need (ditto for emailing noc@domain. hopefully the admin person you get isn't some BOFH type, but the original poster was talking about not being able to get ANY email contact. If it was an urgent issue, there are better means of communication than email anyway.)

      Dialup users aren't going to have their own SMTP servers to be contacted through (but their ISPs will.) You could say "every IP address must have an email address", but that wouldn't be too practical.

      You know, why not submit an RFC yourself? I'm not exactly sure how they handle addendums, but you're sure to get some interesting feedback, and if you make a good enough case maybe they'll add "time" (or "ntp") as one of the required addresses.

      --
      Karma: Bored. (Thinking about resurrecting the "Anyone else is an imposter" joke.)
    65. Re:It's bad. by Eric+Damron · · Score: 1

      "It's not his fault people are using his service illegally..."

      Well, when you knowingly do something that results in harm to other's you can be held accountable under United States laws.

      If I loan my car to a friend and he takes out a fence, I can be made to pay for it. I may not have been driving the car but I am responsible for seeing that the car is not used to do damage to other people's property. Same idea here.

      --
      The race isn't always to the swift... but that's the way to bet!
    66. Re:It's bad. by autopr0n · · Score: 2

      If he can't get his act together, then why should his parent ISP have to suffer, too?

      Because they agreed to certan terms when they merged with his company...

      --
      autopr0n is like, down and stuff.
    67. Re:It's bad. by Shimbo · · Score: 1

      Every site needs a post hamster; it's the little guy that chews up the unwanted mail.

    68. Re:It's bad. by Surak · · Score: 2

      Alright...so I was basically stoned off my ass when I posted that. What's your point? :-P

    69. Re:It's bad. by gorbachev · · Score: 1

      What a nice thing to say Mr. Anonymous Coward.

      You left out accusing me of being gay, an anti-commerce net terrorist, a net-nazi, a net cop, a spam cop, a bully.

      And you left out the obligatory threats of violence and Lawsuites (tm)

      HTH

      --
      In Soviet Russia, I ruled you
    70. Re:It's bad. by GreyPoopon · · Score: 1
      I guess the valid comparison would be that the RIAA is correct in it's harassment campaign to shutdown Napster and similar file-sharing services, as they(Napster, etc) leave the door unlocked to trading copyrighted software. Almost, but not quite. If RIAA had notified Napster that illegal trading of copyrighted works was happening, and then asked for either 1) their assistance in tracking down the abusers or 2) the lockout of abuser accounts, that would be the end of it. IIRC, they instead sued FIRST and then asked for cooperation later. Also, the RIAA never actually proved any damage from the illegal trading. Their sales records certainly don't show any. The damage from SPAM is pretty clear when you add up storage space, network bandwidth and personal time.

      It's NOT illegal to leave an open relay, not as far as I know.

      Agreed. If it were, he would have already been arrested. It's also not illegal to block or blacklist the ISP. Somebody carefully pointed this out to me when I was stupid enough to try to argue about it with no sleep for two days.

      Portraying his open relay as a "Public Health Hazard" of the Internet is all fine and dandy if there are clear and precise regulations detailing what constitutes a hazard.

      I don't think most people are portraying it as a public health hazard, although some certainly are. And I agree that they are going overboard. But the fact of the matter is that it costs people time and money. 95% of my e-mail is from SPAM. I have to spend time dealing with it.

      Those restrictions/laws/regulations don't yet exist, people shouldn't be randomly forming organizations to "police" the internet using strongarm and blackmail tactics.

      No, the regulations don't exist yet. And I don't think you want them to. Anytime a law is made to counter a problem, it almost certainly has negative impacts elsewhere. It is costly to enforce, and it must be enforced globally to be effective. It can also be warped and used in the future by particularly crafty people with their own agenda. The organizations that have chosen to fight SPAM are doing so because they have a common belief: they don't want somebody using their storage space, their time and their network resources to send out mass mailings to people, most of whom are irritated by it at best. Remember that the people who use a block list OWN their equipment. If they don't want certain people using them for certain purposes, it is within their rights to block that traffic. Without laws and regulations in place, it was inevitable that individuals and companies (even competitors) would get together to fight what they view as a common enemy.

      Every time the subject of SPAM comes up, there are arguments that we should target the SPAMMERS and not the owners of the relays they take advantage of. I would agree, except that in cyberspace it is very difficult to track down the source of the SPAM. If you manage to do so, the SPAMMER just moves on to other pastures. It's relatively simple to locate and shut down the resources they use. If closing up open relays actually had a significant impact on the legitimate use of SMTP servers, it would not be acceptable to demand that they be closed. However, as several other threads of this topic have discussed, there is no real harm to the operator in closing up that open relay. If he wants his friends to use the relay, there are several authorization methods that can be employed. Also bear in mind that for SPAMMERS, there is no real cost. It is the rest of us that bear that cost.

      --

      GreyPoopon
      --
      Why is it I can write insightful comments but can't come up with a clever signature?

  5. Free flow. by saintlupus · · Score: 5, Funny

    Is it a good thing because it promotes the free flow of information?

    Information wants to be free, but my mail client does not want to be chock-full of herbal pot alternative spam.

    If this were still the 'net of the pre-WWW days, I would see the point of running an open relay for friends. It's not, though. The vultures are here. And they really want to sell penis enlargers.

    --saint

    1. Re:Free flow. by Anonymous Coward · · Score: 0

      By cutting off people from using his email system, he's restricting freedom of speech. This would be like the RIAA shutting down Napster. Napster wasn't at fault for running the system, it's the users that should've used the system responsibly and not broken the law. It's the same case here. Information wants to be free!

    2. Re:Free flow. by DataPath · · Score: 4, Funny

      I have to ashk you about the penish mightier.

      Gushy it up however you like, trebek, the question is does it work?

      --
      Inconceivable!
    3. Re:Free flow. by Anonymous Coward · · Score: 0

      Information wants to be free, but my mail client does not want to be chock-full of herbal pot alternative spam.

      That's right, but we have to learn that trying to enlighten all people on this planet about how bad spam is is an exercise in futility, and so is trying to shut down all open relays, no matter if they are intentionally left open or by accident. What we need to do is develop ways to deal with anonymous communication by means of moderation or selection. Why does anyone accept anonymous or faked mail with the same priority as mail from well-identified sources? This is the weak edge of SPAM, not a more regulated infrastructure. Other problems like network attacks can be viewed upon from the same point of view.

    4. Re:Free flow. by royalblue_tom · · Score: 1

      There's no freedom of speech issue. He can close his server down tomorrow, and no one would have a go at him for not sending their e-mails. Nothing in the constitution forces him to publish what you say. Freedom of speech is about preventing the government from passing laws that prevent you from saying things.

      However, he's asking to be labelled as an "accessory to spamming" if he doesn't close that relay. And that may not be a crime in the real world, but would certainly lead to a lynching if the mob ruled.

      Napster was the equivalent of openly selling burgler's tools. I have no problem with a file sharing system that allows you to swap files with a friend (regardless of what the file is - that's the user's business). But when the only reason you know the "friend" is that they were advertised "by" Napster as having particular files.

      Information doesn't want anything. It's not sentient. What you're really saying is that you want the fruits of someone else's hard labour for free. There is no freedom of lunch.

    5. Re:Free flow. by CoolVibe · · Score: 3, Funny
      Saw this in someone's .sig:

      Steph: "Don't these people realize that if you outlaw SPAM, only CRIMINALS will have spam?"
      Piotr; "Sounds good to me...."
      Steph: "Okay wait, that didn't come out right..."

      :)

    6. Re:Free flow. by Flarenet · · Score: 3, Informative

      That signature is from a User Friendly strip. The characters were actually Stef and Greg. See the original comic strip.

    7. Re:Free flow. by MrFredBloggs · · Score: 1

      Yep, that sounds about right - contrived and unfunny as ever.

    8. Re:Free flow. by MrFredBloggs · · Score: 1

      "Napster was the equivalent of openly selling burgler's tools"

      Burglers tools are things like torches, crow-bars, small bits of metal etc.

      "But when the only reason you know the "friend" is that they were advertised "by" Napster as having particular files"

      Sort of like ebay, who are not responsible if you get in touch with someone for the purposes of buying stolen property.

    9. Re:Free flow. by jonnythan · · Score: 1

      Oh god, thank you for that.

      That made me laugh harder than anything else has in a while.

      (Someone else uses those phrases in everyday language! HA!)

    10. Re:Free flow. by Anonymous Coward · · Score: 0

      Uh, tell it to the judge that convicted Napster of contributory copyright infringement. It's not like anyone here can do anything about it.

    11. Re:Free flow. by DrSkwid · · Score: 2

      Sort of like ebay, who are not responsible if you get in touch with someone for the purposes of buying stolen property.

      funny you should use that as an example. Auctions in England were actually a way for stolen property to be legitimised.

      An auction house advertised that they are going to have an auction of goods (this is a legal requirement). The public comes to view them, if they can prove that the items belong to them they can claim them back before the auction starts.

      Once your stuff has been sold throug1060ction you cannot claim it back.

      M

      --
      There are places where the networks are not touching,and there are places where they are-Boeing's Lori Gunter
    12. Re:Free flow. by TekPolitik · · Score: 2
      Once your stuff has been sold through auction you cannot claim it back.

      But you can still take an action against the auctioneer for conversion and recover the value of the stuff (it's irrelevant that they didn't know the stuff was stolen).

    13. Re:Free flow. by TekPolitik · · Score: 3, Flamebait
      Information wants to be free, but my mail client does not want to be chock-full of herbal pot alternative spam.

      The problem with Gilmore (and the EFF, which is Gilmore's mouthpiece), is that he first got involved in lobbying to get copyright for software through (so people wouldn't copy his software), and since then he's basically opposed every single law relating to technology that has been proposed. It doesn't matter if the law is a good one, or if it's beneficial to the geek community - if it's a law relating to technology, he'll oppose it.

      Certainly there are some things that need to be opposed, but with the EFF there is no discretion - if it's a law that relates to technology, it must be bad. Except copyright law because it helped Gilmore make his millions.

      Gilmore and the EFF have long since ceased to represent the groups and interests they claim. They are utterly without relevance, although they seem to be able to con a few people to donate to them. Frankly, donating to the EFF is a bad idea - if Gilmore wants a personal mouthpiece for irrationally opposing all tech law, he can pay for it himself (and can afford to do so) without begging others to subsidise him.

    14. Re:Free flow. by saintlupus · · Score: 2

      The problem with Gilmore (and the EFF, which is Gilmore's mouthpiece), is that he first got involved in lobbying to get copyright for software through (so people wouldn't copy his software), and since then he's basically opposed every single law relating to technology that has been proposed. It doesn't matter if the law is a good one, or if it's beneficial to the geek community - if it's a law relating to technology, he'll oppose it.

      Are you sure you're not thinking of Mitch Kapor?

      --saint

    15. Re:Free flow. by Anonymous Coward · · Score: 0
      I believe that the words of the U.S. Supreme Court regarding junk mail in Rowan vs. USPS (397 U.S. 728, 1970) can apply equally well to email. Quote:
      In Martin v. City of Struthers, 319 U.S. 141 (1943), Mr. Justice Black, for the Court, while supporting the '(f)reedom to distribute information to every citizen,' id., at 146, acknowledged a limitation in terms of leaving 'with the homeowner himself' the power to decide 'whether distributors of literature may lawfully call at a home.' Id., at 148. Weighing the highly important right to communicate, but without trying to determine where it fits into constitutional imperatives, against the very basic right to be free from sights, sounds, and tangible matter we do not want, it seems to us that a mailer's [397 U.S. 728, 737] right to communicate must stop at the mailbox of an unreceptive addressee.
      ...
      To hold less would tend to license a form of trespass and would make hardly more sense than to say that a radio or television viewer may not twist the dial to cut off an offensive or boring communication and thus bar it entering his home. Nothing in the Constutition compels us to listen to or view any unwanted communication, whatever its merit; we see no basis for according the printed word or pictures a different or more preferred status because they are sent by mail. The ancient concept that 'a man's home is his castle' into which 'not even the king may enter' has lost none of its vitality, and none of the recognized exceptions includes any right to communicate offensively with another. See Camara v. Municipal Court, 398 U.S. 523 (1967).
  6. SMTP Authentication!!!! by spotter · · Score: 3, Informative

    If you want people to use you as a relay from where ever you are, use smtp authentication. it doesn't have to be a real account, and using things like cram-md5 the password isn't set in the clear (or one can use smtp-tls, but that's less supported)

    I do this with evolution, I know outlook and netscape support it.

    1. Re:SMTP Authentication!!!! by spotter · · Score: 2, Insightful

      A little bit more explanation.

      SMTP supports an authentication mechanism. Normally one would think you would want this hooked up to /etc/passwd (or shadow) but that would mean the passwords would have to be sent in the clear. So one would use smtp ssl (runs on different port) or smtp-tls (runs on port 25, and uses a start-tls command to start the encrypted session).

      One also can use a One Time Password (OTP) scheme. In this case, the password will be stored on the server in plaintext, and we use a challange/response system to authenticate. The server sends a challange, and then you do some cryptographic hash functions with the password and the challange to create a response, you then send the response back. The server can duplicate the steps, and if they match you are authenticated.

      This way, one can setup a "smtp account" with a name like relay (not a real unix account in /etc/passwd, but in something like /etc/poppasswd) and give it a password like "opensesame" and then tell anyone who needs to use this smtp server remotly the username and password. If this info ever gets compromised and used by spammers, just change it.

      I do this with qmail (with a patch for qmail-smtpd.c) and I use the same smtp server from my parents house, my apt in NYC and Columbia University (and multiple other places I have visited)

    2. Re:SMTP Authentication!!!! by Anonymous Coward · · Score: 1, Informative

      Vpopmail also supports pop-before-smtp auth very easily.

      just ./configure --enable-roaming-users=y and you're away.

  7. I see his point though... by Kintanon · · Score: 1, Troll

    My boss doesn't want to change his SMTP server every time he is connected to a different network (about 5 times per day) nor does he want to have to worry about having 5 different connections set up (one for each network even though he is using the same e-mail address for all of them) and he travels out of state and out of country a lot, which adds yet another set of random SMTP servers he would have to deal with.
    My problem is that SMTP has no authentication that I can find that would allow me to let him use our SMTP server from wherever he was, so I found a list of open relays and changed his SMTP server to use that. I wish there were a better technical solution, but I haven't been able to find one so far... If anyone has a suggestion I'd be happy to hear it, but until then Open Relays have a place in the world in my opinion.

    Kintanon

    --
    Check out JoshJitsu.info for Brazilian Ji
    1. Re:I see his point though... by igjeff · · Score: 2

      >My problem is that SMTP has no authentication that I can find that would allow me to let him use our SMTP server from wherever he was,

      SMTP Auth is exactly what you're asking for...most MTA and MUA's support it at this point.

      Jeff

    2. Re:I see his point though... by Kintanon · · Score: 2

      Oh and before people start telling me to use smtp-pop, it's an imap server and no one wants to change it to pop. And for some reason he doesn't want to use the web-based e-mail we set up...
      Bah nevermind.... >:)

      Kintanon

      --
      Check out JoshJitsu.info for Brazilian Ji
    3. Re:I see his point though... by b-side.org · · Score: 1

      get him an 800 number dialup, or a VPN client. this is all 90's technology, folks.

      --
      Indie rock lives! b-side!
    4. Re:I see his point though... by Gordonjcp · · Score: 3, Informative

      What's wrong with using POP-before-SMTP?

      Quite a few servers use it now. My favourite "toy" server, eXtremail, does this by default...

    5. Re:I see his point though... by Kintanon · · Score: 2

      Sigh, 800# dialup won't work, he's constantly connecting into other companies networks for things, so that's the connection he uses.
      I suppose I could do a VPN, but as far as I know that requires that I know what his IP addie will be, which we don't. Someone else recommended SMTP Auth, which is what I'm about to go look at.

      Kintanon

      --
      Check out JoshJitsu.info for Brazilian Ji
    6. Re:I see his point though... by Spock+the+Vulcan · · Score: 5, Informative
      My problem is that SMTP has no authentication that I can find that would allow me to let him use our SMTP server from wherever he was
      Yes it does. Read RFC2554, SMTP AUTH. To quote: "SMTP AUTH is " ..an SMTP service extension [ESMTP] whereby an SMTP client may indicate an authentication mechanism to the server, perform an authentication protocol exchange, and optionally negotiate a security layer for subsequent protocol interactions."
    7. Re:I see his point though... by Anonymous Coward · · Score: 1, Interesting

      Its called a vpn.
      Have your boss connect to your network remotely through a vpn and there should be no problem.
      either that or use a webmail client.

      not hard.

      AC

    8. Re:I see his point though... by Anonymous Coward · · Score: 0

      This is quite possibly the sanest idea I've seen on Slashdot in the past month. Pity that someone will have some lame excuse not to do it...

    9. Re:I see his point though... by mbyte · · Score: 2

      of course does SMTP have authentication ! see RFC 2554 ! it does solve your problem. really. use it. together with cram/digest-md5 auth.

      Even most modern MTAs do support it, sendmail since version 8.10, postfix for sure, exim probably, and there is probably one of the bazillion patches for qmail that will solve this problem ;)

    10. Re:I see his point though... by popular · · Score: 1

      VPN has always provided me with an IP within the LAN (therefore no extra config required), with its packets forwarded through the tunnel. I assume this is just how it works, although it's possible that this is just one of many ways to implement it.

    11. Re:I see his point though... by phaze3000 · · Score: 2
      You can set many mail servers up to only allow smtp relaying after auser has been authorised by checking POP3. Pretty much every email client supports this by default.

      A quick google found this for qmail, but there are plenty of similar solutions for other mail servers.

      --
      Blaming GW Bush for the Iraq war is like blaming Ronald McDonald for the poor quality of food.
    12. Re:I see his point though... by Kintanon · · Score: 2

      Welp, either way I've decided to go with SMTP Auth on Qmail here and that should fix it.

      Kintanon

      --
      Check out JoshJitsu.info for Brazilian Ji
    13. Re:I see his point though... by popular · · Score: 1

      Yeah, it's probably a tad easier to configure existing software than to install and get acquainted with something entirely different.

    14. Re:I see his point though... by Anonymous Coward · · Score: 0

      At least one pop-before-smtp daemon also supports IMAP, so your argument is bogus.

    15. Re:I see his point though... by eam · · Score: 1

      What about poprelayd? All he has to do is check his mail (pop or imap) and he is automatically authorized to use your SMTP server from that host for some (configurable) time period.

    16. Re:I see his point though... by schon · · Score: 2

      My boss doesn't want to change his SMTP server every time he is connected to a different network (about 5 times per day) nor does he want to have to worry about having 5 different connections set up

      He doesn't have to.

      Simplest solution: change his SMTP server from "mail.yourdomain.com" to "mail".

      Then, his computer will add the domain name of his local ISP to the DNS lookups, and he'll get the local mailserver.

      This will work for 99% of ISP's on the planet.

      If you use the 1% that doesn't have a DNS entry of "mail" pointing to their SMTP server, you can just use a VPN. It takes an hour to set up a VPN server, MS's PPTP client is free, and it's more secure (which should be enough to sell him on it all by itself.)

    17. Re:I see his point though... by sirsky · · Score: 1

      So do what I've done, and run your own local SMTP server. This is included with Windows 2000 (IIS5) and is VERY easy to install and secure. Just send your own mail! Plus, mail get delievered faster, most of the time.

    18. Re:I see his point though... by rahlquist · · Score: 1

      My server runs both pop and IMAP and uses SMTP auth. Its not that hard to setup. I only started learning linux in november and I can do it :)

      --
      Sick of stupidity? http://www.patentlystupid.com
    19. Re:I see his point though... by Anonymous Coward · · Score: 0

      Our mail server has ssl smtp, imap, imaps, pop3, pop3s, and if any authenticate via any of them you get relay rules added in order to relay, perhaps you should change email servers.

      -Myron

  8. secure by kritikal · · Score: 2, Interesting

    my school (wm.edu) had the same problem. aol (and some other isp's) blacklisted us last year for running an open relay. now, we switched over to secure login and everything is great! why doesn't he just use secure login? or what about running a secure proxy or even just let them use webmail?

    1. Re:secure by jalewis · · Score: 2, Informative

      Open relays are common for schools. I recently implemented some thing to reduce spam and all the schools that send us email were blocked, because they are on the list as being an open relay.

      Unfortunately, ALL of our business is school related. The open relay block came down. Sigh... I am still able to use the known spammer list, but it isn't as effective as the open relay.

      More info on setting this up for yourself can be found at http://www.spews.org . They are kind of a clearing house for all the spam blockers.

      I highly recommend using something. I use it personally and have seen a 80% drop in spam that gets through.

      jas

  9. Blame Microsoft by boltar · · Score: 0, Flamebait

    If it wasn't for the virus propagation tool known as Outlook this virus and its ilk wouldn't even
    exist. Sure this guys being an idiot but we should focus on the REAL source of this sort of
    these viruses, ie the idiot marketdroids at MS who thought being able to run executables in email
    would be "kool".
    I'll admit though its hard to even blame MS for non viral spam :)

  10. God forbid... by Ledge · · Score: 5, Insightful

    someone would use a little common sense. Perhaps his "friends" need to do what the rest of the world does and get a shell account or a webmail account. If the janitor of a school left the door unlocked so that his wife could come in after hours and drop off his dinner and a bunch of kids came in through the unlocked door and trashed the place, the kids would be at fault, but the janitor would be guilty of neglegence. If the janitor didn't lose his job, he probably would be smart enough to leave the door locked in the future.

    --
    If it ain't a Model M, it's a piece of crap.
    1. Re:God forbid... by (trb001) · · Score: 1

      I don't see the similarity in the arguments. I would liken it to leaving the keys in my car in my driveway and having kids come by, steal the car, and drive through my neighbors yards doing doughnuts. Sue me for negligence, it's MY car on MY property and THEY weren't invited in. Now, if part of the restriction of the neighborhood was 'Don't leave your keys in your car unattended', yeah, I'm guilty. But if Verio doesn't have that in their clause, I don't see a darn thing wrong with him leaving a relay open.

      Would you want someone telling you how to run your server?

      --trb

    2. Re:God forbid... by Stonehand · · Score: 2, Insightful

      Just a real-world bit -- if you have an unsecured swimming pool, and teens go trespassing and loudly playing in it at all hours, YOU can get nailed for having an "attractive nuisance", if memory serves.

      An open relay has similar properties, except that it's even easier to abuse since the abusers can be from all over the world.

      --
      Only the dead have seen the end of war.
    3. Re:God forbid... by exodus2 · · Score: 1

      where I live San Diego this is true. I bought a house with a swimming pool and wanted to change my fence. It truns out that I can lower my fnece but If someone kills themself or gets hurt and my external fence is less than 6 feet high then I am liable(sp?) for their death/injury. So I fence to a 4 foot rought iron So I could see my pool from the house and then I had to make my gate to the back yard 6 feet high. It was a real pain.

      --
      .sigs suck, thus nothing here.
    4. Re:God forbid... by Jon+Howard · · Score: 1

      One HUGE difference, of course, is that a Janitor is custodian to someone else's property, where the mailserver owner owns the mailserver.

      If I want to let random strangers do what they will with my property, it's my business.

    5. Re:God forbid... by maxpublic · · Score: 1

      And if I want to blacklist your fucking ass, that's my business. Screw you if you don't like it.

      Max

      --
      My god carries a hammer. Your god died nailed to a tree. Any questions?
  11. open relay bad by Anonymous Coward · · Score: 0

    open relays are bad.. Plain and simple.. this guy is just as bad as the people who spread the viruses and send spam.. It's kinda of like people who helped the nazi's but said hay i'm not a nazi so it's ok..

    1. Re:open relay bad by Anonymous Coward · · Score: 0

      Whoops.

      Hey Godwin, how's it going?

  12. slashdotting by MikeRepass · · Score: 1

    I have a feeling 300,000 slashdot readers will take care of Verio's traffic problem real quick.

  13. i guess it's open season on him now... by hyperstation · · Score: 2, Informative

    bash-2.05$ telnet toad.com 25
    Trying 140.174.2.1...
    Connected to toad.com.
    Escape character is '^]'.
    220 toad.com ESMTP Sendmail 8.7.5/8.7.3; Thu, 7 Mar 2002 09:11:09 -0800 (PST)
    helo toad.com
    250 toad.com Hello [12.32.42.180], pleased to meet you
    mail from:<asdfasdf@asdfasdf.com>
    250 <asdfasdf@asdfasdf.com>... Sender ok
    rcpt to:<dick@dick.com>
    250 Recipient ok
    data
    354 Enter mail, end with "." on a line by itself

    .
    250 JAA03142 Message accepted for delivery

    1. Re:i guess it's open season on him now... by JWSmythe · · Score: 1


      Hehe. His SMTP server has been slashdotted.. It's pathetically slow to accept the commands I typed to it.. My message will probably be queued for a few hours.. :)

      I wonder how long it'd take him to close his relay, when his machine is constantly relayed through..

      --
      Serious? Seriousness is well above my pay grade.
    2. Re:i guess it's open season on him now... by WetCat · · Score: 1

      Sorry, it's not proof of an open relay yet! Mail server can be configured to JUNK such mail after acceptance first time! So results of not getting "we do not relay MAIL REJECTED" in smtp session is not enough to presume that it's an open relay!

    3. Re:i guess it's open season on him now... by inkey+string · · Score: 1

      Yeah, except for the, um, fact that he says it's an open relay himself. Did you even read the article?

    4. Re:i guess it's open season on him now... by hyperstation · · Score: 1

      yes, but the fact that i receieved the email i sent through itdoes make it an open relay :)

      --
      Received: from toad.com (toad.com [140.174.2.1])
      by host17.hostingcheck.com (8.10.2/8.10.2) with ESMTP id g27HBuZ06266
      for ; Thu, 7 Mar 2002 12:11:56 -0500
      Received: from toad.com ([xx.xx.xx.xx]) by toad.com (8.7.5/8.7.3) with SMTP id JAA03142 for xxxx@xxxx.com; Thu, 7 Mar 2002 09:11:23 -0800 (PST)
      Date: Thu, 7 Mar 2002 09:11:23 -0800 (PST)
      From: asdfasdf@asdfasdf.com
      Message-Id:
      Status: R
      X-Status: N

  14. Invalid Justification by Dolph · · Score: 2, Insightful

    John Gilmore assertion that he wants his freinds to be able to send through the server are invalid, as he could always allow authenticated relaying instead of open relaying. This would allow authorized users to relay from anywhere without allowing abuse of the system.

    Of course, everyone knows that this isn't the reason for his running of the relay - it's simply an issue of free speech, as I understand.

    --
    --
    Beauty is in the eye of the beholder... Oh, no. It's just an eyelash.
  15. open relay not root cause of problem by Anonymous Coward · · Score: 0

    Having an open relay isn't intrinisically bad. 20 years ago it was common. What makes it bad today is Microsoft and it's lack of security, and the burgeoning of spam. If Microsoft products weren't so susceptible to worms and virii half the problem would be taken care of. Then work on shutting down the spammers. But the real fault should be placed a lack of OS security and spammers

  16. I wonder how long... by Technician · · Score: 3, Insightful

    I wonder how long it will take him to get a clue when his domain gets on all the major blacklists now it's well known. His view of the internet is going to get very small very fast. He needn't worry about being DOS'ed by angry netizens. Most of their packets will no longer be able to get through soon.

    --
    The truth shall set you free!
    1. Re:I wonder how long... by Anonymous Coward · · Score: 0

      It hasn't happened yet. I can still load his home page. It's 9:18 AM Pacific time. Post what time you can and can't load his page here and see how he falls off the net.

    2. Re:I wonder how long... by Anonymous Coward · · Score: 0

      It's perfectly okay for Gilmore to run an open relay.
      It's perfectly okay for me to drop his server in the deny list on mine.

      The only problem I have with the situation is that the relay blocking DNSBL's don't list him, because he blocks systems that have attempted relay tests on his machine, so to them, he appears closed. He should be listed as a test blocker and put on the open relay lists because of that so that I and others don't need to manually add him to our deny lists. From what I understand, if he finds that his machine has been used to spam, he drops the IP that was used to send the spam to his machine in his own deny list (which must be getting pretty sizeable by now). If one of his friends ends up later using one of those IP's, they won't be able to relay mail, which they would if he used SMTP AUTH and closed the relay.

      The volume throttle that Verio made him put on the machine is becoming obsolete. There is sophisticated spamware out there that specifically tries to avoid putting too much mail through any one open relay. This way, the relay doesn't get overloaded or crash, making it much less likely that the admin will fix the relay. A million run spam may use 1000 or more open relays in round robin fashion, which would mean that the spam his machine sees would be spread out over time, and possibly not caught by the rate limiting throttle.

      As long as he's listed in the major relay blocking lists, I don't care if he runs an open relay.

  17. The guy's an ass! by Anonymous Coward · · Score: 0

    I don't care who he is, but this is just wrong. If he insists on leaving it open for the world to access, then perhaps Verio should charge him for this excessive use of bandwidth.

  18. Not that easy by godot73 · · Score: 1

    Gilmore does nothing wrong himself, I think. Blame the people who send spam first - it's his choice how he wants to use his bandwidth. On the other hand he would certainly do a big favor to the community by using one of the many ways (SMTP auth, for example) of closing down his relay to spam without having to close the relay for friends.

    Your personal freedom ends where you harm another person's freedom by living it.

    1. Re:Not that easy by toast0 · · Score: 2

      i would agree he is not doing anything wrong

      however, by not doing something, he is in the wrong, by not doing anything to prevent spam going through his server, he is becoming a spam magnent

      he is being neglegent by not setting up some sot of authentication.

  19. Everyone's right! by Frater+219 · · Score: 5, Insightful
    John Gilmore has every right to run an open mail relay.

    Verio has every right not to sell Internet service to people who want to use it to run open mail relays. John Gilmore has no right to demand Internet service form Verio.

    MAPS, ORDB, ORBZ, and the other blackhole lists have every right to tell me that John Gilmore is running an open relay. John Gilmore has no right to gag the blackhole lists' truthful speech about him.

    I have every right to refuse to accept email from John Gilmore's open relay. I may do this on my own information, or on the advice of a blackhole list. John Gilmore has no right to force me to allow him or his traffic on my property.

    So everyone's right, as long as everyone stays within their rights.

    1. Re:Everyone's right! by romkey · · Score: 3, Informative

      Part of John's complaint was that Verio was filtering mail to their customers based on the RBL, and that John couldn't send mail to his own ISP because of this.

      I largely agree with what you said, but I think part of John's complaint which you missed is that Verio is making the decision for their customers as to whether or not to accept email from John's open relay, and not allowing their customers to make that decision themselves.

    2. Re:Everyone's right! by FreeUser · · Score: 3, Informative

      I largely agree with what you said, but I think part of John's complaint which you missed is that Verio is making the decision for their customers as to whether or not to accept email from John's open relay, and not allowing their customers to make that decision themselves.

      As long as Verio is being upfront and honest with their customers that they are using RBL, then their customers have made the choice, by choosing Verio. It would be nice if verio provided a facility for their customers to opt in or out of using the RBL list, but really that is just a convinience: their customers can easilly opt out of the RBL by choosing another ISP.

      As a previous post said, "everyone is right." John has the right to run an open relay, Verio has the right to sell him service (or not), and I (as well as Verio) have the right to filter his site because I don't like his actions. His rights stop at my home's router (whether I've chosen to block him of my own accord, or because of RBL's recommendation, or not at all, is my buisiness, not his).

      --
      The Future of Human Evolution: Autonomy
    3. Re:Everyone's right! by thczv · · Score: 2, Informative

      > Verio has every right not to sell Internet
      > service to people who want to use it to run
      > open mail relays. John Gilmore has no right to
      > demand Internet service form Verio.

      I think this is wrong. It sounds like the contract that governs Gilmore's internet service places NO content restrictions on his use of the service. That is what one of those links above says.

      thczv

    4. Re:Everyone's right! by dachshund · · Score: 2, Informative
      MAPS, ORDB, ORBZ, and the other blackhole lists have every right to tell me that John Gilmore is running an open relay. John Gilmore has no right to gag the blackhole lists' truthful speech about him.

      A lot of people would have made similar arguments for Napster. Turns out that there are a number of legal principles that override the "right to free speech" under various circumstances. I sincerely doubt that any of them come into play in this case, but don't imagine that the the 1st amendment provides MAPS or any other service with blanket protection.

    5. Re:Everyone's right! by Frater+219 · · Score: 4, Insightful
      Part of John's complaint was that Verio was filtering mail to their customers based on the RBL, and that John couldn't send mail to his own ISP because of this.

      So what? I'd say this might be a problem if he couldn't get in touch with Verio's administrators -- but he doesn't have any right to send email to Verio's other customers from his open relay. Even if he could not email Verio's administrators, I don't think that would be an issue of rights -- more an issue of Verio's competence or good sense. If he thinks they're incompetent, insensible, or malicious, he shouldn't keep sending them money.

      I largely agree with what you said, but I think part of John's complaint which you missed is that Verio is making the decision for their customers as to whether or not to accept email from John's open relay, and not allowing their customers to make that decision themselves.

      I don't think this changes the rights involved, although it may be a valid comment on Verio's desirability as one's ISP. (Spam filtering makes an ISP more desirable to me, but may make it less desirable to John Gilmore. Neither of us have the right, though, to impose our preference on any particular ISP.)

      In general, do customers of a business have the right to force that business to change the services it offers? No. I don't have the right to force McDonald's to serve me a charbroiled hamburger made from USDA Choice beef, when all they are selling is fried hamburgers made from inferior beef. In fact, I wouldn't even have that right if there were no high-quality burger joints in my town.

      McDonald's thinks it can do better by selling burgers I don't like. Good thing I don't have to eat them. Verio thinks it can do better by selling Internet service John Gilmore doesn't like. Good thing he doesn't have to use it. I think I can do better by not accepting mail from John Gilmore's open relay. Good thing I can choose to do so.

    6. Re:Everyone's right! by TotallyUseless · · Score: 2

      actually, the isp he originally got the service from, and cofounded, had no such use restrictions. that isp, TLG, was then bought by Best, which was bought by Hiway, which was bought by Verio. Verio's Use Policy states: "Spamming -- Sending unsolicited bulk and/or commercial messages over the Internet (known as "spamming"). It is not only harmful because of its negative impact on consumer attitudes toward NTT/VERIO, but also because it can overload NTT/VERIO's network and disrupt service to NTT/VERIO subscribers. Also, maintaining an open SMTP relay is prohibited. ..."

      I understand those arent the terms he agreed to, but they are the ones he has to obey now if he wants to keep the service. I can understand where he is coming from to a certain extent. Nobody likes to sign up for a service and then have features you use taken away from you. But the truth is I bet Verio could give a rat's ass who this guy is, and what he did for the internet. It could probably be Tim Berners-Lee in his place, and the response would be the same. I think Verio thinks of him as a disposable customer, regardless of who he is, and that if he wants to run his relay, she should try finding an isp that will let him do it. Dont sit around waiting to see if Verio will really cut off service on April 4th. Thats like standing on a traintrack and waiting to see if the train really will hit you.

      --

      Time for some tasty Shiner Bock!
    7. Re:Everyone's right! by Anonymous Coward · · Score: 0

      I'm pretty sure, based on the lack of spam in my inbox, that my ISP (earthlink) is blacklisting spammers. However, I have never been notified of that fact. If they offer to sell me a service (an email address) and then block access to that address without informing me, it seems they've violated the terms of service.

      The real solution to this problem is a per-transmission fee for sending email. As all the anti-spammers say, bandwidth isn't free. I don't see why I should be paying more because someone subscribes to the Risks.list when they could subscribe to Risks-Digest. I see no reason why granny who gets three emails a week from her children should pay as much for her access as someone who subscribes to the Linux Kernel developer's list. The invisible subsidy of listservs (which is one of the hidden costs of 'free software') in the form of flat-fee email should go away.

      It's NOT too cheap to meter. That was true 20 years ago when CPU time was expensive.

    8. Re:Everyone's right! by Frater+219 · · Score: 2
      A lot of people would have made similar arguments for Napster. Turns out that there are a number of legal principles that override the "right to free speech" under various circumstances.

      Yes, there are. Let's say I'm an officer of a bank. It's illegal for me to answer truthfully if someone comes up to me and says, "I want to rob your bank. What's the combination to the vault?" Or let's say I'm your next door neighbor. It's illegal for me to answer truthfully if someone comes up to me and says, "I want to frame dachshund for drug possession by dumping a bunch of crack vials in his/her house. What times is s/he away from home?"

      What do these cases have in common? These are cases in which my speech would contribute materially to the commission of a crime. The argument you refer to regarding Napster is analogous: the crime is copyright infringement, and the allegation is that Napster is contributing to this crime by telling people how to find people willing to make illegal copies. (As it happens, I don't agree with this allegation, but that is not relevant here.)

      However, it is not a crime for me to refuse to accept email from an open mail relay. My mail server is my property, and I may allow or refuse people access to it. By telling me which IP addresses harbor open mail relays, MAPS et al. are therefore not contributing to a crime, but rather helping me out with a perfectly legal act on my own property.

      So no, an analogy between Napster and MAPS does not hold water.

    9. Re:Everyone's right! by MrFredBloggs · · Score: 1

      "Verio is making the decision for their customers as to whether or not to accept email from John's open relay"

      Seems fair enough. Who do you think are the best people to decide what Verio does with its hardware, time and money?

    10. Re:Everyone's right! by dachshund · · Score: 1
      However, it is not a crime for me to refuse to accept email from an open mail relay. My mail server is my property, and I may allow or refuse people access to it. By telling me which IP addresses harbor open mail relays, MAPS et al. are therefore not contributing to a crime, but rather helping me out with a perfectly legal act on my own property.

      Incidentally, one of the people below pointed out that it's the ISP that's implementing the blocks, not you. Which might limit their ability to defend themselves against lawsuits dealing with what goes over their network.

      IANAL. Obviously. (And even if I said I was, why in god's name would you believe me?)

      I have no reason to believe that any of these lists are doing anything illegal, so all of this is just hypothetical. What I'm pointing out is that the 1st amendment does not provide absolute protection-- if you were accused of violating a law (of which there are many), you could find that your "speech rights" aren't as absolute as you might think. The courts might determine that you're partly responsible for the functional aspect of your speech (getting sites blocked), instead of supporting your analogy ("it's just a list that I'm publishing, and should therefore be protected.") This is partly because 1st amendment protections appear to be weaker when there's a functional component to your speech, as is the case in an RBL list.

    11. Re:Everyone's right! by dozing · · Score: 2

      Everyone's right. But, that doesn't make everyone smart. His excuse of wanting to provide a mail server for all his friends is just stupid. I provide a mail server for all my friends too, but I use smtp authentication to do it. When it turned out the ISP of one of my friends didn't allow outbound traffic on port 25 I set up ssh tunneling so he could use it. You can provide access to your friends and still keep the "bad guys" from hijacking your server.

      --
      Dozings.com -- Its kinda funny... If you're as crazy as me.
    12. Re:Everyone's right! by Anonymous Coward · · Score: 0
      The real solution to this problem is a per-transmission fee for sending email.
      No.
      1. That would penalize the legitimate mailing lists.
      2. It wouldn't work, because the spammers use large distribution lists in each transmission. You would need to charge per addressee, or addressees*size.
      3. There's no guaranty that you would be able to collect.
      4. It doesn't address the issues of invasion of privacy, theft of service (on the receiver's end) and trespass to chattel
    13. Re:Everyone's right! by Anonymous Coward · · Score: 0

      > John Gilmore has every right to run an open mail relay.
      > Verio has every right not to sell Internet service to people who want to use it to run open mail relays. John Gilmore has no right to demand Internet service form Verio.

      But that's precisely what he did do.

      Verio served notice upon Gilmore that he was violating their AUP and that they would no be renewing his account.

      He responded with a volley of legal threats using EFF lawyers and threats to take things as far as he could using puiblicity against Verio on a frea speach ticket.

      He also did the same against the DNSbls who listed his servers - although he also tried to play IP renumbering games with them too.

      Note the title page of the original link - "Verio is censoring John Gilmore"

      It is not censorshop to say to a problem customer "we do not want your business anymore". Verio is not a monopoly player, so arguments about quasi-governmental bodies don't apply either (eg, mall owners in the mall area).

      Gilmore is severely misusing EFF funds and resources simply by threatening to sue Verio for their termination notice.

      If he was to be consistent, he'd also have to weigh in with full support of Monsterhut in their case against Patec and in favour of Cyberpromo in the AOL and Compueserve cases.

      The fact that he didn't in any of these shows he's a hyprocrite who should be removed from any role publically associated with EFF - and drummed out of EFF for using their lawyers in what is a personal dispute.

    14. Re:Everyone's right! by autopr0n · · Score: 2

      Verio has every right not to sell Internet service to people who want to use it to run open mail relays. John Gilmore has no right to demand Internet service form Verio.

      Verio merged with Gilmore's company. So they probably are required to allow gilmore's server.

      --
      autopr0n is like, down and stuff.
    15. Re:Everyone's right! by cube_mudd · · Score: 1

      Well spoken. It's good to know that there are still a few people with the ability perform critical thinking. I'm glad you're one of them and I'm glad you decided to share your thoughts with /. You should probably also send them to John Gilmore. I normally find myself in agreement with John, but this is one instance where I vehemently disagree with him.

      Oh, and it's a good thing McDonald's hasn't yet bought up all the good burger joints and put them out of business.

      -Cube

  20. It's his right to run an open relay by jonbrewer · · Score: 2, Insightful

    It really is.

    It's also your right as an end user or mail server administrator to block traffic from his server / network.

    A common carrier, however, does not have the right to block his traffic because they want to stop spam.

    This is really clear-cut.

    1. Re:It's his right to run an open relay by aug24 · · Score: 1

      A common carrier has the right to block whatever the hell they like, so long as it's in their terms and conditions - and I bet it is.

      You choose the carrier, you accept the Ts&Cs.

      Me? I'd want the one blocking this dick, who should argue his points in journals or websites like all the rest, rather than making a nuisance.

      --
      You're only jealous cos the little penguins are talking to me.
    2. Re:It's his right to run an open relay by fcanedo · · Score: 1

      A common carrier, however, does not have the right to block his traffic because they want to stop spam.

      If they don't, they should. If he causes enough traffic it could cause big problems for his carrier. Probably it would cost them some money, but in the worst case scenario, it could push them to a chapter 11

      This guy is just abusing the system. It's no problem to adjust his server so that it's not an open mail relay and his friends can still use it to send mail.

      --
      alt.binaries.erotica.hamster.ducktape ;-)
    3. Re:It's his right to run an open relay by spikedvodka · · Score: 1

      Taken from the verio AUP: http://verio.net/company/policies/aup.cfm

      Spamming -- Sending unsolicited bulk and/or commercial messages over the Internet (known as "spamming"). It is not only harmful because of its negative impact on consumer attitudes toward NTT/VERIO, but also because it can overload NTT/VERIO's network and disrupt service to NTT/VERIO subscribers. Also, maintaining an open SMTP relay is prohibited. When a complaint is received, NTT/VERIO has the discretion to determine from all of the evidence whether the email recipients were from an "opt-in" email list.

      emphasis mine. as far as I can see from that, case closed, internet access revoked, end of story.

      --
      I will not give in to the terrorists. I will not become fearful.
    4. Re:It's his right to run an open relay by BasharTeg · · Score: 1
      A common carrier, however, does not have the right to block his traffic because they want to stop spam.

      Yeah, and my phone company doesn't have a right to cut my phone line if I use it to abuse other peoples' phones right ? Common carriers apparently have no right to protect the world from their customers' abuse, nor to enforce their terms of service.

      I hate when ignorant people use terms like common carrier, with little or no understanding of the law that accompanies that term, and then tries to make a statement with the implication that the legal definition of a common carrier backs up their statement.

      What's clear cut is that you, and many other Slashdot posters, are talking out their asses with pseudo-legal knowledge that wouldn't stand up in an IRC arguement. I'm not saying that's anything new; nerds with pseudo-legal knowledge spouting BS is actually quite common, especially on Slashdot.

    5. Re:It's his right to run an open relay by DavidTC · · Score: 1
      Here is a fun experiment to decide whether or not common carriers have the right to decide what devices are hooked up to their network.

      Take a standard computer power cable. Slice it open, figure out which is the ground, and ignore it. Go outside out house, or in your backroom, whereever the phone junction box is located. Open it. Plug the cable in, being careful not to short the ends. Now, touch one of the non-ground ends to the red and the other to the green plug. (You probably want to unhook all the phones in your house first.)

      And see how goddamn fast the phone company cuts off your service. In fact, they will not only disconnect your service, they will physically cut your wires. And I bet they don't even have a 'wiring the power grid into the phone line' termination clause, unlike most ISPs, which do have 'hooking an open relay up to your connection' termination clause.

      Common carriers cannot ban content. They can certainly decide you can't send 120 volts though their phone lines, or send unsolicted bulk email (or allow other people to send UBE, which is what he's doing), or hook up a train car that's seventy-five feet tall to the common carrier railroads, etc, as none of those are bans on content, just networking standards.

      --
      If corporations are people, aren't stockholders guilty of slavery?
    6. Re:It's his right to run an open relay by jonbrewer · · Score: 2

      Consider first the fact that I was working for an ISP when you were still in Jr. High School.

      Next, consider that Common Carrier status is first defined in US Code Title 46, Sec. 1702, but is now defined quite differently due to sixty years of legislation and court cases.

      Finally, consider fucking yourself.

      Thank You.

  21. This is good by Anonymous Coward · · Score: 0

    Because it highlights the failing of the whole existing mail trasfer system. Currently, free speech and spam reduction are in some ways diametrically opposed aims.

    Not that I know what would be better, but it's about time there was a rethink.

  22. ideals and technology by romkey · · Score: 2, Interesting

    I've argued with John about this.

    On the one hand, I believe he's saying that the ISP should not make the choice for its customers as to what mail it accepts and what mail it doesn't accept. I have to agree with this, it's a slippery slope and easily abused. However I believe a lot of customers are happy to have their ISP try to reduce the amount of spam they receive.

    Also, I believe John's attitude is that any spam-prevention mechanisms should not block valid mail from getting through. I have to agree with this.

    And, having been (incorrectly) attacked by anti-spammers a few times I have to say that often the anti-spammers are worse than the spammers.

    On the other hand, I think John's insistence on running open relays is just plain a bad idea, and that using technological means such as SMTP Authentication could completely remove the need for having open relays.

    1. Re:ideals and technology by jadbalja · · Score: 1

      Amen to the point about anti-spammers. I work for the company that was providing the DMA (Direct Marketing Association) with the website for people to opt out of all DMA members mailing lists (www.e-mps.org). A number of spammers started adding a link to www.e-mps.org at the bottom of their messages, which caused SpamCop and other anti-spam organizations to start accussing us of being part of the spamming and sending complaints to our NAP, who several times threatened to cut off the e-mps site (thus cutting off people's chance to opt out of DMA mailing lists). Ironic and stupid all at the same time....

    2. Re:ideals and technology by Zocalo · · Score: 2
      I have to say that often the anti-spammers are worse than the spammers.

      As an "anti-spammer" myself, I have to agree that there are indeed some anti-spammers that look upon their role as some kind of holy writ and are as overzealous as that implies. And there are also some that genuinely try to do their best to fight spam (hopefully I'm in this camp). Yes, I do submit to SpamCop, I even have my own internal RBL server at work (an ISP) because it's more convenient than updating the banned IPs on all our servers one by one. On the otherhand, I'll only shitlist someone who refuses to take action against a spammer, or gets abusive (it happens), or is clearly a spammer themselves. However, I tag each entry with the date it was added and why, and expire as appropriate. It's this expiry phase that some "anti-spammers" seem to forget - shitlisting a spamming IP is all very well, but at somepoint a new user is going to be on that IP who doesn't deserve the entry.

      Of course, the flipside is that while some spammers are outright criminals, there are some spammers that are genuinely trying to target their email to generate leads and act responsibly. The problem is that the criminal element has ruined it for the latter group, because almost noone trusts "Sorry - go here to opt-out of further emails" any more.

      --
      UNIX? They're not even circumcised! Savages!
    3. Re:ideals and technology by Zocalo · · Score: 2
      I trust you took advantage of the facility that SpamCop has about "ISP does not wish to receive complaints about ..." to resolve this? Lot's of spammers cite that crap spam legislation and include a URL to some US Government site as well. I don't recall ever getting an option to send a spam report to the .gov site. If your NAP and the anti-spam organizations concerned have a clue then it should have been easy to convince them that the DMA was trying to be responsible.

      Drifting off topic a bit, but an idea just occured to me regarding the lack of trust people have towards opt-out lists. If a "responsible spammer" (for want of a better term) could prove they honoured their opt-outs to SpamCop, say, then a link to a secure page at SpamCop to confirm that fact might go a long way, particularly in the DMA's case.

      --
      UNIX? They're not even circumcised! Savages!
    4. Re:ideals and technology by catfood · · Score: 1
      Of course, the flipside is that while some spammers are outright criminals, there are some spammers that are genuinely trying to target their email to generate leads and act responsibly. The problem is that the criminal element has ruined it for the latter group, because almost noone trusts "Sorry - go here to opt-out of further emails" any more.

      Bah. Opt-out is still spam, and it still sucks. Being slightly less grievous than the stuff you can't opt out of doesn't make it okay.

      I can't opt out of the 100-plus spams I get every day even if the spammers weren't lying. It's just far too much work to bother with, and it's a hell of an imposition considering who benefits from the spam in the first place. (Hint: not me.)

      There is no such thing as responsible spamming!

    5. Re:ideals and technology by Shimbo · · Score: 1
      On the one hand, I believe he's saying that the ISP should not make the choice for its customers as to what mail it accepts and what mail it doesn't accept. I have to agree with this, it's a slippery slope and easily abused. However I believe a lot of customers are happy to have their ISP try to reduce the amount of spam they receive.


      Yes. I don't know of anyone offering unfiltered mail as an added value service.

  23. Let him be free. by www.sorehands.com · · Score: 5, Interesting
    Allow him to keep an open relay. But also require that he would be liable responsible for ALL spam that passes through his server.


    That means that he would have to be paying out large amounts of money to anyone who is a victim of spam through his server.

    It is interesting to know that a while back, Verio was scraping the register.com database to spam people who had registered with register.com

    1. Re:Let him be free. by Anonymous Coward · · Score: 0

      This would be a pretty dangerous precident to set - It could quite easily be extended to ISPs, and would
      quite likely give them the legal responsibility to monitor and report all kinds of traffic going through their servers.

    2. Re:Let him be free. by sporty · · Score: 2

      There's a funnier solution. Everyone who use SMTP in their mail client to send mail, point it to his open relay. Then he'll really regret "free information flow". Yeah the information wants to be free.. it just feels like costing him thousands of dollars :))

      --

      -
      ping -f 255.255.255.255 # if only

    3. Re:Let him be free. by Anonymous Coward · · Score: 0

      They were quite possibly using software from that wonderful Dmitry at ElcomSoft to 'scrape' theregister.com's database. Elcomsoft makes a commercial product for 'harvesting email addresses' from public forums and websites.

      Why do we all fight so hard for ElcomSoft's rights? They've sold out to the spammers bigtime, certainly more than this Gilmore fellow.

    4. Re:Let him be free. by www.sorehands.com · · Score: 1
      Would that be such a bad thing? If the ISPs that support spammers are held responsible for spamming?


      Should one not be responsible for refusing to take basic security that causes harm? If leave your car and keys at a pay parking lot with an attendant, but the attendant leave the keys in the car and not watches it or take any security measure, is not the lot responsible? Or the bartender loans his SUV to the guy who he just gave 8 shots of wiskey to?


      I'm not saying that the spammer is not responsible, but saying that the person who invites the spammer to use their system to spam is also responsible.

    5. Re:Let him be free. by jc42 · · Score: 1

      It's time to point out again that there's a perfect solution to all this at:
      http://www.snark.com/e-mail/

      With this approach, Mr. Gilmore could keep his spam relay open and MAKE MONEY FAST! from it. His ISP would charge him more, but he'd probably be happy to pay a fraction of his profits to them.

      ;-)

      (Be sure to check out the "simple explanation" page, too. It's all quite well done.)

      --
      Those who do study history are doomed to stand helplessly by while everyone else repeats it.
    6. Re:Let him be free. by geekoid · · Score: 2

      except that would make anyone who has a machine the spam passes through liable for the content of the spam.

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    7. Re:Let him be free. by HiThere · · Score: 2

      Why do we all fight so hard for ElcomSoft's rights?

      Consider that it is a part of the fight for our rights.
      .

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    8. Re:Let him be free. by Fjord · · Score: 1

      Why do we all fight so hard for ElcomSoft's rights?

      To stregnthen the previous responder: the way the U.S. justice system work is that when a right is lost for one person, it is lost for everybody.

      --
      -no broken link
    9. Re:Let him be free. by josepha48 · · Score: 2
      "But also require that he would be liable responsible for ALL spam that passes through his server."

      Does this now mean I should hold the US post office liable for ALL anthrax scares? How about holding them liable for al junk mail that I get too.

      How come I can't put filters on my snail mail?

      I don't like spam, so I filter based on headers. Gee if you have netscape you can use javascript to filter out email. Edit your preferences.js to point to it. I am not sure about how to do it, but know it can be done. I read about this last week. I'll be working on this tonight I hope.....

      --

      Only 'flamers' flame!

  24. Missing the Point by the-banker · · Score: 1

    People are missing the point. The fact there are other ways to authenticate SMTP is moot. The question is whether or not free speech and expression can be limited because of inconveniences it causes. For example, in the US you cannot yell, 'Fire' in a crowded movie theater - it has been decided by the court system that the public interests outweigh the individual right.

    So does the same thing apply here?

    Analogy: I build a subway, and charge no admission. Penniless vagrants board the subway and ride to Wealthyville and rob a house. Am I to blame because had I charged a subway fare they would not have been able to get to Wealthyville?

    Comes down to his Terms of Service with Verio. If he agreed not to run an oen relay, then he shouldn't. If Verio did not prohibit it, then he can. In general, long term Bad Things(c) happen when practicality trumps freedom.

    1. Re:Missing the Point by Anonymous Coward · · Score: 0

      Freedom of speech != open relay. Or, more importantly, freedom of speech != freedom of every possible means of speech. Mr. Gilmore's friends' freedom of speech would not in any way be hindered by the use of an authentication scheme, as they would still be able to send whatever e-mails they wished.

      If it can be demonstrated that there are no reasonable counterparts to an open relay, and that closing the relay would truly prevent their speech, then Mr. Gilmore's argument is sound. For example, if his friends are all blind, and the only mail software they could use did not support SMTP authentication, then there would be a free-speech angle here.

    2. Re:Missing the Point by schon · · Score: 1

      Sorry, spam has NOTHING to do with free speech.

      Free speech is about your freedom to express views and opinions without government interference.

      Spam is about harassment and theft.

      "Free speech" does not guarantee you the right to force people to listen to you.

      If Mr Gilmore went to his local TV station, and demanded that they broadcast (for free) videotapes of him masturbating, and they refused, would be be crying about how they're limiting his free speech?

  25. Great example by JordoCrouse · · Score: 4, Insightful

    This is a perfect example of why ethical issues like freedom of speech, fair use, and the right to carry a gun are not as cut and dried as we would like them to be.

    It all boils down to this: While 99% of any given set of a population may be honest, ethical or safe, there is always that 1% that will take advantage of that very fact. In this case, Gilmore wants the freedom to do what he wishes with his mail server, and though most people respect that, a malious few have used that trust to damage others.

    You can extend this to any argument: While most of us respect fair-use laws, there are those that take advantage of those laws and pirate music and movies. While most people with concealed gun permits have honorable intentions, there is always a small contingent that does not.

    I always say, you have the right to [ speak freely, copy music, carry a gun ] until it infringes on my rights. The problem is, determining who's rights are being infringed on.

    This episode is a great reminder that the issue is much more complicated that most people are willing to admit.

    --
    Do you have Linux and a DotPal? Click here now!
    1. Re:Great example by aug24 · · Score: 1

      This was the premise behind the European Convention on Human Rights:

      You have the right for free speech
      You have the right not to be bothered by others

      etc
      etc

      Each of them has a check against it in the form of another human right. So, he has the right to free speech, and you should have the right to refuse to listen to him.

      Ooh look! You do. You can do it yourself, if you have ipchains or whatever, or your ISP can do it for you.

      Justin

      --
      You're only jealous cos the little penguins are talking to me.
    2. Re:Great example by fishebulb · · Score: 2

      they do not have any right of free speech inside your home. once an email enters my computer, it is my home, they have lost all rights to free speech.

    3. Re:Great example by Arandir · · Score: 2

      While 99% of any given set of a population may be honest, ethical or safe, there is always that 1% that will take advantage of that very fact.

      As always, those 99% can always sue the 1% for damages, without having to resort to a law oppressing the 100%. In the case of Gilmore it's quite simple, sue him for any spam you receive coming through his open relay.

      you have the right to [ speak freely, copy music, carry a gun ] until it infringes on my rights.

      Firing that gun may infringe your rights, but I don't see how carrying it ever could.

      --
      A Government Is a Body of People, Usually Notably Ungoverned
    4. Re:Great example by Anonymous Coward · · Score: 0

      And how did that email enter your computer?

      You configured your mail client to request it from another machine, knowing that it was configured to accept email from other machines according to a public protocol, which allows open relays, which you choose to use despite the undesirable qualities.

  26. What about POP-Before-SMTP Auth moron. by Anonymous Coward · · Score: 1, Interesting

    if he'd used his brain for 10 seconds then a websearcher for maybe 20 he would have found the solution before all this shit.

    I found this out from scratch a few years back so surely he could have worked out that it's possible to validate users from the pop daemon then use that to give them relay permission to use the smtp server.

    FFS half the smtp servers you get these days have pop-auth built in to them, qmail/vpopmail just needs an extra option to ./configure that is talked about in the README to set this up, theres a really handy popauthd.pl script for sendmail to do this...I'm sure exim/postfix can both do this aswell.

    the best bit was the title: "Verio is censoring John Gilmore's email under pressure from anti-spammers".

    Wheres my fucking clue-by-four. *SLAP*

    Theres one born every minute.

    pkm

  27. Change your ISP. by sulli · · Score: 3, Informative

    My ISP (Verio, it turns out) lets me send email via my own domain, from any IP address. I just need to get email first, so the server knows I'm a legitimate user. This rule makes sense for spam prevention - and it also means that I don't need to change smtp settings when switching from DSL to dial-up to private network behind a firewall. If your ISP doesn't do this, it should.

    --

    sulli
    RTFJ.
  28. it's still open by Anonymous Coward · · Score: 1, Interesting

    blah:~$ telnet toad.com 25
    Trying 140.174.2.1...
    Connected to toad.com.
    Escape character is '^]'.
    EHLO hehehe
    220 toad.com ESMTP Sendmail 8.7.5/8.7.3; Thu, 7 Mar 2002 09:18:22 -0800 (PST)
    250-toad.com Hello blah.blah.foo [1.2.3.4], pleased to meet you
    250-EXPN
    250-8BITMIME
    250-SIZE
    250-DSN
    25 0-VERB
    250-ONEX
    250 HELP
    MAIL FROM: blah@blah.foo
    RC250 blah@blah.foo... Sender ok
    RCPT TO: blah@blah.foo
    250 Recipient ok
    DATA
    354 Enter mail, end with "." on a line by itself
    hahahaha..
    .
    250 JAA03950 Message accepted for delivery

  29. Freedom to shit in your neighbour's garden by nagora · · Score: 2, Insightful
    Isn't really a freedom worth fighting for. Just switch the damn thing off and stop being a dick.

    At least it's well known so it's easy to add to the spam blockers. Hope he didn't have anything he wanted to send me in an email.

    TWW

    --
    "Encyclopedia" is to "Wikipedia" what "Library" is to "Some people at a bus stop"
    1. Re:Freedom to shit in your neighbour's garden by guiding_knight · · Score: 1

      The problem with this analogy is he's not doing the shitting. To continue your analogy, if I tell some random person that they can shit in your garden, I am not necessarily responsible for you walking outside one morning and finding it. Just because I informed them of the opportunity does not mean I am responsible, after all I personally did not place warm fecal matter upon your beloved plants.

      However, my (adapted) analogy is also flawed. He is not only providing the opportunity, he is providing the means. If I give someone a slingshot and tell them that they are free to shoot shit into your garden, am I responsible because I provided the delivery means? It is somewhat like the debate over whether guns kill people or people kill people. Guns prvide the delivery system, but can the maker of the gun be held responsible for homicide?

      --
      LOTR: Elijah Wood is a munchkin asshat. Yes, asshat. LOL.
  30. Free Speech My Ass! by Spencerian · · Score: 1

    Even free speech under the Constitution is restricted under specific, remarkably stupid applications. These would include:

    --Standing up in a crowd with the intent to incite a riot

    I would think that his free speech notion is invalid because it endangers an actual process with possibility of harm. In this case:

    --Internet mail servers
    --Operating systems (Windows primarily--hah!)
    --Our common fscking sensibilities

    --
    Vos teneo officium eram periculosus ut vos recipero is.
  31. SMTP AUTH.... by DanEsparza · · Score: 1

    Apparently, you aren't using Sendmail, or don't know anything about SMTP AUTH.

    1. Re:SMTP AUTH.... by Kintanon · · Score: 2

      NOT using Sendmail.
      Using Qmail, and I just found the SMTP Auth patch for Qmail. Now I just have to get that installed...

      Kintanon

      --
      Check out JoshJitsu.info for Brazilian Ji
  32. What to do about it. by Anonymous Coward · · Score: 1, Funny

    What to do about it

    Write, email, fax, or phone to Darren Grabowski of "Verio Security". Tell him that punishing innocents if you can't find the guilty is not the right way to run a network. Please send me a copy at , and also send a copy to EFF at .

    So should I use my real email address...no I think I'll use bill@microsoft.com and relay 100000 copies through your open mailserver. Cool huh!

  33. if his issue is free expression.... by toast0 · · Score: 3, Insightful

    then use of email through his gateway is free expression. however, people blacklisting his box is also free expression.

    additionally, i gather he has an account with verio, which has certain provisions you must agree with to have an account, one of which i imagine compells him to avoid running an open relay. If he has a problem with these provisions, he needs to find a new provider, and if he can't find a provider w/out those provisions, he needs to suck it up and realize that in the civilized world, open relays are bad.

    Yelling anything during a movie is expression, but unless you're at Rocky Horror, it just isn't appropriate, and could get you kicked out of the theatre. If you take passing spam as yelling, and the internet as the theatre, it makes a decent analogy.

  34. Hosting Companies by Anonymous Coward · · Score: 0

    He does have a point. I run a free webhosting company and have had my service (along with my 100,000 users) cut off by AT&T because one of my users spamvertised his URL. He didn't use my mail server, he just used my service to create an otherwise legitamate site. After arguing with the AT&T legal department, I got them to reinstate my service. Does anyone have advice on how I can protect myself from this?

  35. Maybe I'm missing something... by SpookComix · · Score: 5, Interesting
    ...by my mail server is not and open relay, effectively blocks Spam, and requires authentication to send through, but I can send email from anywhere I get an Internet connection. I just have to provide my username and password.

    Is that too much of him to ask of his users? Or is he just unaware of how and what to do?

    Clue me in, folks.

    --SC

    --
    You read fiction? I write it! Lemme know what you th
    1. Re:Maybe I'm missing something... by Anonymous Coward · · Score: 0

      Can you provide us with more information about your mail server? I'd just like to know where to sniff to receive those plaintext username/password combinations you're required to provide.

    2. Re:Maybe I'm missing something... by Anonymous Coward · · Score: 0

      Dumbass... it's the same method used for POP.

    3. Re:Maybe I'm missing something... by Midnight+Thunder · · Score: 1

      You can also add the use of SSL to avoid this problem.

      --
      Jumpstart the tartan drive.
    4. Re:Maybe I'm missing something... by Anonymous Coward · · Score: 0

      Heard of SPOP or IMAP over SSL you stupid fuck?

    5. Re:Maybe I'm missing something... by Anonymous Coward · · Score: 0

      The original comment never said anything about a username/password in the clear. The AC comment under that made it seem like it was and made it seem like a huge deal. Hell, every major ISP uses POP with the username/password sent in the clear. Only a select few give the option to use SPOP or IMAP over SSL.

      In short... you're a tool...

  36. stupid friends by fcanedo · · Score: 1

    John,

    I've got this to say to you:

    It's nice that you want the internet to be totally free, but what good is a free internet that's not usable because of stupid pricks trying to sell anything to every second dumbass out there.

    If you can't setup your server to authenticate your friends, then ask somebody for help. Or you could setup accounts for them, so that they can log in remotely and use pine or elm or yadda yadda yadda.

    If your friends are to dumb to remember passwords, then maybe they're to dumb to use e-mail. You should give them pre-adressed and stamped enveloppes so that they can communicate with other people whilst on their trip.
    Or maybe they'd get confused trying to figure out what stamps to use in which country!

    Open mail relays are not free speech! I hope you get shut down real soon.

    --
    alt.binaries.erotica.hamster.ducktape ;-)
    1. Re:stupid friends by Anonymous Coward · · Score: 0

      It's a 'tragedy of the commons' situation. The perpetrators are both the people provoking the thugs (anti-spammers) to tromp over the grass, and the thugs (anti-spammers) themselves.

      It's just what happens when a consensus-based system is adopted globally. It's never gonna work, and let's face it, as things stand the reality is it allows anybody who wants to call themselves a 'sysadmin' the right to act like a little thug.

      It's gonna change. Change is inevitable. The change I would like to see is full authentication of all traffic. No more aonymnity. Boo fucking hoo.

    2. Re:stupid friends by jhantin · · Score: 1
      No more aonymnity. Boo fucking hoo.

      Ironic that you should say that, AC. I suggest you log in before you post next time.

      --
      ...when you're writing a game...tweak the difficulty of "Easy" to something [your mother] can cope with. -- onion2k
  37. open relay == P2P by Anonymous Coward · · Score: 1, Insightful

    Everybody's pissed that this guy is somehow contributing to spam, but the reality is that all this guy's providing is a tool - an email server. What people do with the server is up to them. It's the same as all these P2P networks like Napster and Gnutella. It's a tool. It doesn't mean that if you use it you're necessarily using it to steal music. Everybody's quick to defend the P2P networks but quick to condemn this guy. What if P2P networks became sources of worms and spam? Then will we side with the RIAA to shut them down?

    1. Re:open relay == P2P by Anonymous Coward · · Score: 0

      Not quite, because the P2P networks are designed to allow you to pull content, whereas spam lands in your lap whether you requested it or not.
      If I go to limewire and search for, for example, bon jovi, I may get results indicating an old man boning a jovial old woman, but I'll probably also get some results of a more musical nature.
      Guess which ones I'll download?
      In the end, out of 600 results, I may have one more song on my hard drive. Out of the last 600 emails I got, about 500 were spam that I had to delete. Someone who is (especially knowingly) providing an avenue for those spam to reach me has earned my contempt.

    2. Re:open relay == P2P by Anonymous Coward · · Score: 0

      Pulling content is only a small part of the equation. You're actually acting as a relay while pulling specific content to your machine on a P2P network. The stuff you download is only a small portion of what flows through your machine. If someone finds an exploit in the division of what's to end at your machine and what's to be passed on, that would be a pretty bad worm. Additionally, I wouldn't think it would be that hard to target specific nodes in a DOS attack.

  38. Re:I thought that was the USAs lifestyle... by toast0 · · Score: 2

    [feeds trolls]
    usually you have to buy the weapon unloaded and then buy bullets and then load the weapon

  39. SMTP Authentication by MicroBerto · · Score: 1, Troll

    Yeah, I guess having his friends and server use some form of SMTP authentication from anywhere would be too hard. What a dipshit.

    --
    Berto
  40. Bandwidth conservation by cluge · · Score: 5, Insightful

    The gentleman in question has a home page here He also has an e-mail address of gnu@toad.com and gnu@eff.org so you can e-mail him here and here

    May I suggest instead of bitching on slashdot you take a second and send an e-mail to the John and let him know how you feel. Practice your first amendment rights. Visit his web page as well. Perhaps the "slashdot affect" can do some good. Take a second and stop being so apathetic and send John Gilmore an e-mail.

    --
    "Science is about ego as much as it is about discovery and truth " - I said it, so sue me.
    1. Re:Bandwidth conservation by Paul+Neubauer · · Score: 1

      Note also that his own site ( http://www.toad.com/gnu/verio-censorship.html ) suggests who to contact at Verio. Maybe Verio could use a few supportive emails about this matter to encourage them to whiten their hat.

      --
      I don't subscribe to RMS's GNUtopian vision.
    2. Re:Bandwidth conservation by JohnnyX · · Score: 1

      May I suggest instead of bitching on slashdot you take a second and send an e-mail to the John and let him know how you feel. Practice your first amendment rights. Visit his web page as well. Perhaps the "slashdot affect" can do some good. Take a second and stop being so apathetic and send John Gilmore an e-mail.

      Please note that you very well may not get an email back from him, since his server "toad.com" has been blacklisted by a number of ISPs. Hell, he may not even receive your mail in the first place.

      I think that's one of the issues he's pissed about. Not to say whether it's right or wrong, but if you look at his site, he does point out that problem as being one of his main beefs with Verio.

      Yours truly,
      Mr. X

      ...just the facts, ma'am...

    3. Re:Bandwidth conservation by Rogerborg · · Score: 3, Interesting
      • The gentleman in question has a home page here

      Please mod the parent up. You have to read some of Gilmore's own words to believe how aggressively and unreasonably stubborn he is on this issue. Gilmore has done some wonderful things, but he flat out refuses to ignore the changing realities of living on the 'net, calling anti-spammers "extortionists", "thugs", "blackmailers", and asserting that this is an "antitrust" issue. Regarding spam itself, Gilmore says: "I don't even want a "tyranny of the majority", if the majority happens to prefer to smash spammers (and suspected spam-sympathizers). I don't want a rerun of Joe McCarthy's witch- hunt, with spammers in place of Communists. I want to have everyone's right to communicate with each other protected, whether or not they disagree with the majority."

      Which is all well and good. Gilmore argues that any censorship is reprehensible. OK, then why did Gilmore voluntarily censor mail passing through his gateway in a token attempt to appease Verio? He argues on a point of principle, then breaks that principle quite cynically so as to create an appearance of having offered a reasonable compromise (when the real solution is much simpler: authorisation). He is a very jolly, persuasive and genial old hypocrite. Harsh comment, but judge him by his actions, not his protestations.

      Gilmore is an extremely confused man, well intentioned, but in severe denial that the world has changed around him. He has found a cause to fight (using EFF lawyers) and is enjoying playing hardball on an issue of principle (while breaking that principle himself) when there's good grounds for believing that the real issue is that he's just pissed at Verio for buying up the ISP he founded and imposing terms of usage on him. Any terms. Gilmore is pro-free speech in the shouting-fire-in-a-crowded-theatre-is-OK way. Information doesn't just want to be free, it wants to be thrown out of the door and helped along with a cattle prod. While he's done a lot of good in his life, I believe that this extremist stance actually damages the EFF and the free-speech lobby.

      Before you judge him, go and read his specific thoughts on this issue, and decide for yourself whether he deserves contempt or pity. I'm rather leaning towards the latter.

      --
      If you were blocking sigs, you wouldn't have to read this.
    4. Re:Bandwidth conservation by Zocalo · · Score: 2
      I thought of that. I got as far as "Securing the Internet. As I said above, my FreeS/WAN project is to secure Internet traffic against wiretapping." before I snorted my coffee out of my nose.

      So: "Wiretapping = Bad", but "Spam = OK" then, John?

      --
      UNIX? They're not even circumcised! Savages!
    5. Re:Bandwidth conservation by SpaceLifeForm · · Score: 1

      Besides giving him a clue via the /. effect and filling his mailbox, perhaps Verio could allow him his freedom to run a open relay but still control the problem from their perspective. Charge him for excessive bandwidth consumption. Bet he closes it up REAL fast.

      --
      You are being MICROattacked, from various angles, in a SOFT manner.
    6. Re:Bandwidth conservation by augustz · · Score: 2

      EFF Member...

      Casting this as censhorship damages the credibility of those truly fighting for free speech. Write verio, the eff, and John and let's see if power to the people can get this guy off the net.

    7. Re:Bandwidth conservation by Anonymous Coward · · Score: 0
      On his homepage he says these things should be allowed: "hiring a housekeeper and not paying social security" as well as "paying below government-guaranteed wages"

      I guess he just *forgot* putting "owning a slave" there.

      What a disgusting piece of shit this person must be. I hope he dies.

    8. Re:Bandwidth conservation by Anonymous Coward · · Score: 0

      > Gilmore [...] refuses to ignore the
      > changing realities of living on the net,
      > calling anti-spammers "extortionists",
      > "thugs", "blackmailers" [...]
      .
      And how is he wrong in this regard? When CompuServe refused access to certain newsgroups *coming in over their network and resources* everybody whinced about censorship. Why? It's the end-user, that's supposed to make the decision and not a/many middlema/en, correct?
      Now why not the same approach here? It's not the Verio's and/or Gilmore's (nevermind machines) that you should be concerning yourself with, is it?! You would not want to hand off the decision over what you get to see to somebody else, would you? After all, you're a grown-up now and can read things like man procmail and man iptables.
      But then, it is far more convenient to let others make the decisions for you, such as MAPS/RBL (and please don't tell me about the freedom of not opting-in. Since the Net these days is not an equally distributed spider-like network but a hirarchical chain of bandwith providers/deny'ers, if the censoring is done upstream from you, there's nothing you can do about it and yes, thus infringes on your freedoms, incl. speech.)
      The man we're talking about here coined the phrase of "routing around damage". This can only work in a network of peer machines of *equal* attributes, such as bandwidth (incoming and outgoing), openess and accessability of relay-services (proxie's for http, mail relays etc.) and the general equality of being a fully functioning node as part of the whole (net). MAPS and any other blackholing DESTROYS THIS ENTIRELY and has the potential of doing more damage (this time without around-routability) than any other scheme even the most nefarious of entities (such as TLA's and .gov's) could ever devise. Nevermind the hijacking of even the existing "beneficial" scheme by various people with various agenda's.
      Go, John Gilmore! There's nothing wrong with being a relay. Perhaps one day you'll be remembered as the last one before the Net ceased to be and became just another one-way street of what others wanted us to see. For those that are oh so upset about it see above man pages and please, STFU, until you have done so.

  41. sheesh... by mikeee · · Score: 2

    He should just hack his relay so that it's extreeeemly slow; nobody will much care if they're using it on the road, but this will make it next to useless for spammers.

    There is a fine line between exercising your rihts and being an asshole; right now he's straddling it.

    1. Re:sheesh... by Turing+Machine · · Score: 1

      He should just hack his relay so that it's extreeeemly slow;

      That's an interesting idea, actually. Since the bulk of the open relays out there are open because of clueless sysadmins (rather than from genuine spam-friendliness), how about making SMTP default to only accepting, say, 20 emails per hour from a particular IP address? (just a ballpark figure, the actual number would need to be tuned) There'd be a config setting to raise it if necessary, but raising it would require that the sysadmin actually read the docs to learn how.

    2. Re:sheesh... by ethereal · · Score: 1

      Better yet (and this isn't my idea, but I like it): hack it so that the delay starts small but then increases exponentially for every subsequent mail from a particular IP address within a set time period. So his friends can just send one or two emails quickly, but spammers will find that by email #20 it takes a minute or two to complete the send process.

      --

      Your right to not believe: Americans United for Separation of Church and

    3. Re:sheesh... by realdpk · · Score: 2

      Or he could just use the built-in features of his mail program to do authentication, no hacking necessary.

    4. Re:sheesh... by kaiidth · · Score: 1

      From the article linked: According to Gilmore's Web site, Verio agreed last August not to terminate his service if he modified his mailer software to avoid forwarding large quantities of e-mail from single addresses over short periods of time.

      I don't know whether they're referring to addresses or email addresses there, however. But the attitude most people seem to have (he hasn't done ANYTHING! Why not!) suggests that most people didn't actually read the article ;-)

  42. not about censorship by djweitzner · · Score: 2, Interesting

    This is a hard problem, but it's not about censorship. Censorship is what *governments* do when they are either trying to shut down political debate (a.k.a. totalitarianism) or subject minorities to the cultural values of the majority (repression),or both. Verio is not the government nor should it be treated like one, lest we get into a whole bunch of real censorship problems (like forced use of porn/content filters by ISPs).

    This problem is about messed-up technology (as others have pointed out) and the difficulty of dealing with anti-social behavior (from spammers, not Gilmore). Since it appears that John can close his relay without interrupting his traveling friends, I hope he will do so. This is about cooperating with the relatively harmless means that the community has evolved (without recourse to legal repression) to help curb spam.

  43. Verio doesn't honor its agreements by Anonymous Coward · · Score: 2, Insightful

    Frater wrote:

    Verio has every right not to sell Internet service to people who want to use it to run open mail relays.

    No, actually, Verio doesn't. It's bound by the terms under which it (indirectly) acquired The Little Garden (tlg.net), which very clearly specified that there was to be no blocking of service on grounds of content.

    Remember this, if you're ever tempted to business with Verio: It breaks its commitments. Accordingly, you can't believe a word it says.

    1. Re:Verio doesn't honor its agreements by gwernol · · Score: 2

      No, actually, Verio doesn't. It's bound by the terms under which it (indirectly) acquired The Little Garden (tlg.net), which very clearly specified [toad.com] that there was to be no blocking of service on grounds of content.

      I'm not party to the acquisition agreement that TLG signed when it was bought by Verio. However it is very common for Terms of Service of the acquired entity (TLG) to be replaced by the Terms of Service of the acquirer (Verio).

      Basically Verio bought the TLG business under a contract. If that contract says words to the effect: "Verio pays the owners of TLG x dollars and agrees to be bound by the TLG terms of service" then you are right. However I suspect it says something more like: "Verio pays the owners of TLG x dollars and has the right to alter the Terms of Service to the standard Verio ToS". I doubt any business would acquire another and bind itself to keep the previous business' terms forever.

      If John Gilmore doesn't like Verio's terms of service he should find an ISP that will let him do what he wants. He doesn't have some magic right to do whatever he likes. Verio are quite within their rights to impose terms of service that disallows running an open mail relay.

      --
      Sailing over the event horizon
    2. Re:Verio doesn't honor its agreements by Frater+219 · · Score: 5, Insightful
      No, actually, Verio doesn't. It's bound by the terms under which it (indirectly) acquired The Little Garden (tlg.net), which very clearly specified [toad.com] that there was to be no blocking of service on grounds of content.

      Refusing to provide Internet service to an open mail relay is not "blocking of service on grounds of content." The attribute of being an open mail relay is a formal property of a mail server. It is defined without reference to the content of the messages transmitted or rejected by that mail server.

      If Verio were blocking every message that contained the word "spam", then they would be blocking on the basis of content. If they were refusing service to John Gilmore because of the political views he expresses using that service, they would be blocking on the basis of (intended or past) content. They aren't doing that. They aren't inspecting the content of the messages at all -- just the formal (and thus content-neutral) attributes of the transmitting host.


      Let's say Verio goes into the bookselling business, and promises to sell any book regardless of its content. I publish pornographic novels, and you publish travel books. One month, we both decide to publish books of our respective genres which weigh one ton apiece and are the size of a small car. Verio chooses not to sell these particular books, on the grounds that they will not fit on its shelves and will cause damage to its facilities due to their weight.

      I then complain that Verio lied, and is not selling my pornographic book because of its content. Is my complaint valid? No, it is not. The decision wasn't on the basis of the content of the book, but its form. Verio chooses not to sell books which weigh a ton, regardless of their content, be they travel books or porn.

    3. Re:Verio doesn't honor its agreements by Anonymous Coward · · Score: 0

      Where can I get a copy of the Ton 'O Porn??

    4. Re:Verio doesn't honor its agreements by Arandir · · Score: 1

      However it is very common for Terms of Service of the acquired entity (TLG) to be replaced by the Terms of Service of the acquirer (Verio).

      It may be common, but it's still illegal. On the other hand, Verio is not obligated to continue service indefinitely to every TLG account.

      --
      A Government Is a Body of People, Usually Notably Ungoverned
    5. Re:Verio doesn't honor its agreements by Frater+219 · · Score: 2
      Where can I get a copy of the Ton 'O Porn??

      You don't want to. It's just a couple of megs' worth of alt.binaries.* spam images printed on big sheets of lead. It's entirely unremarkable for its content -- it's the form which is exceptional and causes bookstores problems. (That, and the bookstores don't know how to deal with metals commodity traders who want to buy it to melt it down -- they don't like to sell to book-burners.)

      Yeah, the quoted post was a troll. It gets my point across, though.

    6. Re:Verio doesn't honor its agreements by jareds · · Score: 1

      No, actually, Verio doesn't. It's bound by the terms under which it (indirectly) acquired The Little Garden (tlg.net), which very clearly specified that there was to be no blocking of service on grounds of content.

      Remember this, if you're ever tempted to business with Verio: It breaks its commitments. Accordingly, you can't believe a word it says.

      Yes, TLG's contracts with its customers eventually became contracts between Verio and its new customers. However, the original contract, which you linked to, states that the terms can be changed with 60 days notice. I find it implausible that in that string of three buyouts, nobody sent the customers new terms of service. In any case, if that wasn't done, that is a technical problem that Verio can surely remedy.

    7. Re:Verio doesn't honor its agreements by geekoid · · Score: 2

      actually, they're blocking it based on what the content might be. there saying ALL content will be blocked becasue SOME content might be spam or a virus.

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    8. Re:Verio doesn't honor its agreements by terrymr · · Score: 1

      No that would be a breach of contract - verio can't legally impose new terms on customers who signed up under different terms. Unless TLG's terms specifically provided for unilateral modifications of terms.

    9. Re:Verio doesn't honor its agreements by Anonymous Coward · · Score: 0

      The quoted post was not a troll of any sort! It's really sad how modern slashdot users have completely lost track of what really constitutes a troll. This partially explains the failure of moderation.

      The post you quoted was a joke. It was offtopic at worst. A post calling someone else an asshole is a flame, not a troll (although the closest thing /. has to marking something as a flaim is "flaimbait") The confusion between flaimbait and troll (which partially overlap) also is a problem for /. moderation. A troll is a person who posts, pretending to be earnest, a message calculated to produce protracted discussion of irrelevant minutia.

      There are very few genuine /. trolls. Most of the self-appointed "troll community" are just crapflooders. A good troll is a work of performance literature. Crapflooding is the intellectual equivalent of a 2nd-grader smearing poop on the walls.

    10. Re:Verio doesn't honor its agreements by Anonymous Coward · · Score: 0
      Refusing to provide Internet service to an open mail relay is not "blocking of service on grounds of content." The attribute of being an open mail relay is a formal property of a mail server. It is defined without reference to the content of the messages transmitted or rejected by that mail server.

      Whoa, be careful there! The identity of the sender and/or recipient of an SMTP message is arguably "content", and any restrictions on a message, or on a server which sends messages where the sender and recipient of the message bear some particular relationship to one another (e.g. third-party relaying), can be plausibly viewed as a "content-based" restriction.


      As for your "one-ton book" example, that's beside the point unless anyone can prove that the spam relayed through Gilmore's server (if any) has caused damage comparable to the damage that a one-ton book would cause to booksellers and/or distributors.

  44. long term outlook not good... by Hooya · · Score: 2
    Although I am against open relays, it does pose and interesting question. As of late, I've been pondering the fate of the internet as I see firewalls and especially proxy servers cropping up all over the place.

    I work for a company that provides a web based application to our clients. Increasingly I'm having to answer questions as to why some guys browser has nothing in it when he goes to the url that we provided them to access this web-based app. So far it has been because of their proxy servers restricting them. It looks like even though the internet is all inter-connected there are lots and lots of checkpoints that restricts movement. I'm sure Berlin-wall had roads connecting either sides. Except most people couldn't use those roads. Now our company wants to somehow restrict access to even the general/informational/marketing company web-site based on IP addresses or some such. I found that so against the 'internet' idealogy that I voluenteered (sp?) myself out of that project. I mean, we do have passwords to protect client data and what not but why restrict information that you would otherwise put on a newspaper-ad?

    On the flip side, our clients usually have proxy servers and what not and at the beginning of these projects I usually have to talk to their sys-admins and ask them to open-up our web-site to their users. When everyone and their brother installs proxy-servers and firewalls the only thing we'll be sharing is the connection. What will we use that connection for? I mean, large companies already restrict your access to the local lan only + a few other 'approved' sites. So you can't do jack with the connection at work. You come home, and well your ISP thought it would protect you from the monstrosities on the internet too and has now created this little sandbox that you can access.

    The internet is going down the drain. It came too quick too soon with no good business model that people could think of. Now everyone is trying to 'restrict' access and hope to make money by doing that since that's the only business model we know of. In the meantime, restricting access is killing the internet. At least the idealogy of sharing information. Pretty soon we're going to have all these nodes refusing access to each other.

    1. Re:long term outlook not good... by Anonymous Coward · · Score: 0

      The consensus model doesn't scale well. The Internet was established as a place for cooperative work with people who had common goals. The WWW was set up with that intent as well.

      It doesn't work globally. It can't work, and it was utopian to think it would work.

      Things change. Oh well.

  45. Why doesn't Gilmore? by Hieronymus+Howard · · Score: 5, Informative

    My provider allows anyone to use SMTP, provided that they have first made a successful POP connection. Once the POP connection is made and the user authenticated, then their IP address is added to the relay, for a period of time (a few hours, I think).

    Why doesn't Gilmore implement something like this? Then his friends could still use his relay from anywhere in the world, but spammers wouldn't be able to.

    I'm inclined to agree with the comment in the article at Gilmore is "being a stubborn old fool for leaving his mail systems as open relays"

    HH

    1. Re:Why doesn't Gilmore? by wholesomegrits · · Score: 2, Insightful

      Because, if you read the history of it, Gilmore has this fucked up, romantic view of the Internet that worked in 1990, but fails in 2002. He's an arrogant romantic who cannot be convinced that his failure to take even the most mundane, non-intrusive steps to secure his open mail server can and did cause harm to many people.

      I didn't have any sympathy last year, and I have even less now. Just because one is an 'Internet pioneer' does that abdicate him of *any* responsibity for being a poor sys-admin?

      What verio wanted was symple. He just wanted some publicity and attention.

      --
      No sig is worth reading.
    2. Re:Why doesn't Gilmore? by Anonymous Coward · · Score: 0

      Good god, I cannot spell. That ought to be simple.

  46. Gilmore's a twit by Anonymous Coward · · Score: 0

    I think he's a senile fart who gets his kicks "fighting the man" and the "system". His rather juvenile view of the legalities of drug possession, sale and abuse (see his homepage) only serve to demonstrate that he's a sod. ;)

    1. Re:Gilmore's a twit by Anonymous Coward · · Score: 0

      He's just a regular libbertardian sort.

      There's no reason to name call.

  47. I'm not an SMTP Expert, and I did this: by OS24Ever · · Score: 2

    I need to be able to send/receive email while I travel. So what did I do to allow this?

    Simple. I turned on SMTP AUTH.

    It was hard. I was using an Exchange server. I had to click two checkboxes. One on the Exchange Admin tool and one in Outlook Express.

    --

    As a rock-in-roll Physicist once said, No matter where you go, there you are.

  48. Re: "Is it a good thing..." by DarkRyder · · Score: 1

    This kind of question is coming up more and more these days. Is anti-piracy a good thing? Is anti-spam a good thing? Or is pro-freedom and pro-communication more important?

    Ask yourself this - Why do *I* use the Internet? Why do *I* use computers at all? Is it really to altrustically promote communication and the exchange of ideas, or are those simply side effects of wanting to make your life easier? Personally, I feel that well over 90% of the internet-using world tends toward the latter, and perhaps those people responsible for making the internet work (you know, us :) should consider that more carefully when acting on, and reacting to, the actions of others.

    So is John Gilmore trying to promote communication? Maybe. Is he trying to make his life easier? I certainly don't know. But maybe those who do can take that into consideration before labelling him as Part Of The Problem or Part Of The Solution.

    (Oh, and in case it wasn't clear - I don't have an actual opinion on the Gilmore issue, I just wanted to respond to the editorial musings accompanying it.)

    --
    Unless, of course, scissors can't cut rock...
  49. Use webmail instead by macemoneta · · Score: 2

    It would be easier for his friends to use web based email instead. He could install SquirrelMail with SSL authentication instead, for example. His friends would be happier, and he wouldn't be causing a problem for others. He also wouldn't be running his mail server and bandwidth flat out processing spam. No infringment on his rights, and he's not being used as the tool to infinge on the rights of others. Win-win.

    --

    Can You Say Linux? I Knew That You Could.

  50. It's all about... by cornice · · Score: 1

    Your need for information, your threshold for pain and the signal to noise ratio. Unfortunately an open relay today has a very poor signal to noise ratio. Yes, I am in favor of free and open communication but this is like using a bull horn to call my neighbor. It might work but it causes too much pain for anyone else - and there are better alternatives.

  51. Summary by h4x0r-3l337 · · Score: 2

    The guy should know better (smtp auth, pop-before-smtp).
    The guy seems as fanatic and rooted firmly outside of reality as RMS. I wonder if all bearded men over fifty that are into free software will eventually develop this mental illness...

  52. Hey, it's his stuff... by hanenkamp · · Score: 1

    He can do whatever he likes with his machines and I can do whatever I likes with mine. So, if he leaves his wide open, he shouldn't be surprised if he finds that I've added a REJECT next to his host on mine--if he doesn't get added to an RBL first.

  53. New Career by tadas · · Score: 1

    Is Gilmore now in the Korean middle school business?

    --
    This page accidentally left blank
  54. Woman by Anonymous Coward · · Score: 0

    This guy is probably a woman... just a woman could be that ingenuous...
    Or maybe he is a Microsoft Certified...

  55. POP to relay by jjeffries · · Score: 2

    There are mail systems that can open up a relay for a specific IP after a successful POP login from said machine. It stays open for a little while, and then closes.

    A quick Google search for "pop temporary relay" finds us this page which will make sendmail work this way.

    Problem solved? I doubt it.

    1. Re:POP to relay by ThesQuid · · Score: 2

      I believe CommuniGate Pro, from Stalker Software does this.
      It's a neat software package available for almost any operating system or flavor of *nix.

  56. What's that sound? by Hard_Code · · Score: 5, Funny

    A herd of anonymous cowards and email harvesters whooshing to the open relay...

    --

    It's 10 PM. Do you know if you're un-American?
  57. Missing point... by Fnkmaster · · Score: 5, Insightful
    Lots of people seem to be missing the point. This guy isn't ignorant of SMTP AUTH or other possibilities and doesn't think they'd be too hard to implement. He is trying to make a political statement against MAPS, ORBZ, etc. The problem is that Gilmore is wrong.


    ISPs are out there to make a living, like the rest of us. The reality is that spammers are people who don't care about inflicting what we call a "negative externality" on everybody else. That means they are inflicting a cost on those who have to read through spam, or figure out how to block/filter it, and the ISPs who have to carry large volumes of unsolicited commercial email. While ORBZ, MAPS, etc. may be annoying, these organizations do serve a function. Gilmore is free to run his open relay on his T1, but it's akin to parking your Ferrari in the middle of Harlem, with the keys in the car, and the driver's side door open. Technically, you may not be legally responsible, but ethically, if somebody walks into that car and goes joy riding and gets into a crash killing/maiming others, well, what the hell did you expect?


    Society does get to set rules about permissible behavior, and we do get to enforce them by exclusion. Hell, if 40% of ISPs (by volume, or by number, I don't know) use MAPS, ORBZ, by their own choice it's probably for a reason. And frankly, I'd rather use an ISP that does, because I don't want to be on the receiving end of any more spam than I already get.


    Gilmore may be right that RBLs are not the correct long term solution. I've heard it said before, so I won't take credit for it - the correct solution is a change in Internet standards - make it more "costly" in some way (bandwidth or other) to send bulk emails. This would bring the economic cost back to the spammer and remove or reduce the negative externality. Make it so it doesn't pay to spam. And no, I don't have the solution to this problem, but I could imagine alternatives to SMTP/mail routing procedures that address the problem. Of course somebody might argue that this just reduces the utility of email. Ah well. Until then, for god sakes, close your open relays.

    1. Re:Missing point... by Anonymous Coward · · Score: 0

      Every solution anybody can offer to the problem reduces the 'utility of email.'

      Who should pay for email? Personally, I think everybody should pay for each message they send.

      This will get certain people running frantic, namely people who subscribe to a lot of mailing lists.

      But why should a light mail user bear the same cost as someone who subscribes to a lot of mailing lists?

  58. Y'know... by wedg · · Score: 1

    If he really wanted to let his friends use his mail, he'd setup SSH instead of an open relay, so they could SSH into his boxen, then mail from there.

    Security is a 'good thing'. We don't need more virii being propagated, thanks.

    --
    Jake
    Dating: while( 1 ){ call_girl(); get_rejected(); drink_40(); } return 0;
  59. What 'bout webmail? by ryochiji · · Score: 1

    If you want friends to be able to send mail from wherever, how about giving them an IMAP account on the server and setting up a webmail interface?
    This will allow "free flow" of information without "free flow" of spam and virii.

  60. Irresponsible and Uneducated. by ThePixel · · Score: 1

    It's both irresponsible and uneducated. If he wants people to be able to get to the server from anywher, that's fine. leave off the IP filtering. But turn on Authentication for all uses of the mail server. DUH.

    --
    People see the world as they are, not as it is.
  61. Ethics (Re:Hey, it's his stuff...) by PigleT · · Score: 2

    ...and as soon as his stuff starts connecting to mine, expect to be well & truly blacklisted as well.

    As for ethics:

    if you run a mail relay you can do so for a few IP#s and domains,for all IPs and domains, or just for your own local stuff that you own. Accordingly you get varying potential for valid use or misuse.
    Amongst these options tailoring his relay to just those IP#s and/or domains for which his "friends" want to relay, no more no less, would've resulted in an optimum amount of relaying, no more no less.

    Hence he is not doing the best he could.

    Not to mention, whatever happened to SMTPAUTH? Why doesn't he at least have the common courtesy to run an SSL-wrapped authenticating SMTP server if he wants to provide a relay?

    The FSF have a similar attitude to relays - all this cuddly "free speech" stuff really strikes me as so much horse-excrement when it's *me* that has to process the spam - and yes, I've seen stuff relayed through the fsf's open relay before now. I would've thought that such an organisation would have far more sense of the *responsibility* that goes with Free Speech than to abuse it in such an unthinking childish manner.

    --
    ~Tim
    --
    .|` Clouds cross the black moonlight,
    Rushing on down to the circle of the turn
  62. RMS and system security, once upon a time? by Lumpish+Scholar · · Score: 3, Interesting

    I vaguely remember that at one point, Richard Stallman didn't want to use any Unix machine that didn't support guest accounts (user: "guest"; password: ""), because he thought that was a violation of freedom. For a while, that meant he didn't use any system hooked up to the Internet.

    It's not that he didn't understand the security implications; it's that he thought they were less important than what he considered the moral implications.

    Can anyone back this up?

    --
    Stupid job ads, weird spam, occasional insight at
    1. Re:RMS and system security, once upon a time? by ethereal · · Score: 1

      For a while his desktop didn't have any passwords on it, or at least that's the legend. Again, this was supposedly based on a moral understanding of the 'net as a cooperative network of individuals that were similarly high-minded and would treat your stuff as they treated their own.

      Also, it probably helped that the early 'net community was so small that there wasn't a lot of anonymity. It's easier to trust "the world" when you have a good chance of finding anyone in "the world".

      --

      Your right to not believe: Americans United for Separation of Church and

    2. Re:RMS and system security, once upon a time? by Lumpish+Scholar · · Score: 3, Informative
      For a while his [Stallman's] desktop didn't have any passwords on it, or at least that's the legend.
      Thanks; that's enough to help me find the story:

      http://www.kde.org/food/rms.html
      HY: In a lecture, you mentioned that you didn't use passwords, and had no
      security for your computer.

      RMS: Uh-huh. Security might make sense with banks and military facilities,
      but in a computer lab, that is a sign of a social breakdown.

      HY: (!!!) Social Breakdown?!?!!

      RMS: Yes. It's like curing the symptom and worsening the disease. The
      disease here are the young people who are cut off from warmth and anything
      really worthwhile, who have nothing on their hands that to rebel and get
      attention by sneaking into other peoples system. But then the attention
      that they get from this is one of total hate and hostility. Security sends
      out that message of hostility, and I don't want to be on either side of it.

      HY: So, you still don't have security?

      RMS: I regret to say that we had to. There was this one person who
      repeatedly erased our files and there was no choice. So we made a gateway,
      a login server. But since I thought that this was such a sad thing, I
      thought I should suffer more from it so I can't log in on that server.

      HY: But on the other hand, FSF supports some encryption scheme, doesn't it?

      RMS: Well, that's an interesting point. I don't like people who keeps
      secret from their neighbors, but you should be able to protect yourself
      from the government. That's where encryption comes in.

      HY: But governments are, in a sense, an expanded form of a neighborhood,
      aren't they?

      RMS: Um, no, I don't think of the United States government in that way. No.
      --
      Stupid job ads, weird spam, occasional insight at
  63. A Sample E-mail that I sent by cluge · · Score: 3, Insightful

    The following text of the e-mail that I sent

    To: gnu@toad.org
    Cc: gnu@eff.org, drg@verio.net
    Subject: RE: Your fight with Verio

    Dear Sir,

    I find myself in an unusual position, agreeing with Verio. They (Verio) isn't trying to censor your mail, it is trying to prevent your mail server from being used by people to spread SPAM, viruses and other vermin of the e-mail world. It has nothing to do with trying to censor your free speech, or your opinions.

    Allow me to provide a parallel this for you. Say you maintain a building on public property with a printing press. You leave the building unlocked so that your neighbor can use it as well. You do this because making a key for your friend is "just too much trouble". The building starts being used by violent gangs and an anarchist who builds his bombs there. The public ask you nicely to lock the building so that this activity will stop. You refuse saying that they are trying to censor you because you have a printing press in the building. That is patently untrue you are in affect aiding and abetting criminals by your negligence.

    As an administrator that has to defend against SPAM attacks, sometimes coming by the hundreds and thousands for small domain that has at most 10 mailboxes I have no sympathy for you. This is not about free speech, this is about theft, denial of service and common sense.

    aaron@NoitalianSpam-carsPlease.com

    --
    "Science is about ego as much as it is about discovery and truth " - I said it, so sue me.
    1. Re:A Sample E-mail that I sent by Anonymous Coward · · Score: 0

      aaron@italian-cars.com

      djdjdjrheuwqer9 djd sjd ajd djjs

      aaron@italian-cars.com

      reri idid dididid as

      aaron@italian-cars.com

      dkdd eee9fdd asks s oeoe sowoeigfht

      aaron@italian-cars.com

      no spam indeed. yep

      aaron@italian-cars.com

      hee

    2. Re:A Sample E-mail that I sent by cluge · · Score: 2

      procmail is my friend and your enemy.

      Anonymous cowards are such pussies.

      --
      "Science is about ego as much as it is about discovery and truth " - I said it, so sue me.
  64. Not quite.. by Anonymous Coward · · Score: 1, Insightful

    What makes it bad today is Microsoft and it's lack of security, and the burgeoning of spam.

    OK, while I loathe MS, and will dis them every chance I get, I gotta say that they're not at fault here.

    Spam is the only reason that open relays are bad. MS's security isn't. Worms or virii, while disturbingly common in MS-land, have no bearing on open SMTP servers at all - they use the victim's SMTP server to spread.

    1. Re:Not quite.. by sqlrob · · Score: 2, Informative
      Spam is the only reason that open relays are bad. MS's security isn't.

      Try reading the article. A Windows trojan has this particular relay hard coded into it and uses it to send.

    2. Re:Not quite.. by Anonymous Coward · · Score: 0

      I did read the article. And my comment stands.

      MS could make the most secure programs on the planet, and spam through open relays would still be a problem.

      OR, we could close every open relay on the planet, and viruses would still exist for MS programs.

      Just because ONE virus makes use of open relays DOES NOT mean that there is a correlation between open relays and MS security.

    3. Re:Not quite.. by sqlrob · · Score: 1
      Just because ONE virus makes use of open relays DOES NOT mean that there is a correlation between open relays and MS security.

      Yes, it does. There is no causation there is correlation. It basically comes down to the following set of questions:

      Is spam the only reason open relays are bad?
      No.

      Is spam the major reason open relays are bad?
      Yes.

      This single virus (even if it is the only one) disproves the statement that the only problem from open relays.

  65. We can prevent this! by Anonymous Coward · · Score: 0

    Very easy. We must have licensing to allow anyone who wants to do such a thing. That license should cost, oh, $5000 per year. Then we need to make sure that the person holding the license also has _insurance_ from an approved underwriter to cover these kinds of things. Yup, we need to tighten this internet thing up so this kind of crap can't happen!

  66. NOW Verio wants to crack down on open relay?!?! by 19Buck · · Score: 1

    I worked for Verio As a TS Rep for about 1 yr as a Telephone rep for both the Shared Web Hosting platform, but Primarily to support the FreeBSD Based Best Internet Communications Shell server platform. Best was a fairly large ISP/Web Host that conducted business in the bay area before Verio Bought them out. The Best SMTP was listed on both MAPS and ORBS as an "open relay" (it wasn't open, but there was an exploit loophole that couldn't be closed, for reasons that would take too long to explain here.). the Best SA worked with MAPS to take care of that issue, but ORBS, as everyone probably knows, is full of self righteous crackheads that wouldn't even return the SA's calls Verio didn't give a flying crap about that either. As far as it was concerned, the Best Inc server farm was a bastard child that it didn't pay attention to, and just wanted it to go away for good (they closed the doors early this year, anyone wanting to maintain a shell account had to move to the massively overpriced iserver service. In so far as internal support went, it was unheard of. If a customer didn't complain, then a problem didn't exist. But the second some outside force opened it's yap, the President's office would jump to attention and start cracking the whips. Let's be realistic, this dude is running a private STMP, ok, he's got that right, but running it as an open relay is just stupid. Hell, it's his bandwidth bill right? He wants to be a tunnel for crap mail, let him foot the bill for it. a quick examination of the header will reveal him as the culprit. Of course he could simply enable an SMTP auth requirement to restrict access to only the users of his choice....

  67. Community Obligations by arfore · · Score: 1

    It is interseting the everyone feels that Gilmore has the obligation to close his relay..

    While security wise this is a nice thing to do, he is by no means obligated to do so. The only obligation he has is to live up to the terms of service and acceptable use policies of Verio. The acceptable use policy (http://www.verio.com/company/policies/aup.cfm) does specifically state that running an open relay is prohibited.

    But besides the load on the network(s) and various servers, what is the real problem?

    Most if not all email programs have the ability to filter email. And most sysadmins maintain a "blacklist" of domains that they routinely block at the gateway.

    This is the same problem that Windows users face when confronted with a security hole in MS Outlook or Windows. Is it Microsoft's responsibility that damage has ocurred on a company's network because Outlook has a hole? What if the patch was made available and the user/techie failed to apply it? Is it still Microsoft's problem?

    Some posters have said that having an open relay offends the "community sensibility." Well so does not bathing regularly, but it's not against the law. And most places won't deny you service on this fact alone.

    Just my 2 coppers.

  68. Who's fighting who? by AnotherBlackHat · · Score: 2

    Sorry, but I just don't buy that the villain here is Gilmore or Verio.

    This is a war between spammers and the spam vigilantes. The spammers want to send their spam, and vigilantes want them not to send their spam. And like all wars, the people hurt the
    most aren't the combatants, but the poor sods caught in the crossfire.

    Standard vigilante tactics are to threaten people for running open relays, because it makes it easier for the spammers to send spam. Since that doesn't always work, they turn to threatening the people who host the people who run the open relays. Verio isn't a third party - it's a fourth party in this dispute.

    Even if I thought the ends justify the means, I don't believe closing open relays would achieve the vigilante's ends. Before we force Verio to force others to close their open relays, How about some evidence that closing open relays helps stop spam. ORBs has been around for a long time, but I still get spam.

    -- Spam Wolf, the best spam blocking vaporware yet!

    1. Re:Who's fighting who? by Frater+219 · · Score: 2
      Standard vigilante tactics are to threaten people for running open relays, because it makes it easier for the spammers to send spam.

      You've got it backwards. It's spammers who threaten anti-spam sysadmins and ISPs: sometimes with frivolous lawsuits, but sometimes even with death threats. Just take a look around news.admin.net-abuse.email.

      All the anti-spam ISPs do is operate mail servers that refuse mail from spammers and those who host them. That's not "threatening"; it's just perfectly reasonable stewardship of their property. If every time I let you in my store you knock my stock off the shelves and crap on my floor, I'm going to pretty soon decide you don't get to do business with me any more.

      Before we force Verio to force others to close their open relays, How about some evidence that closing open relays helps stop spam.

      Take a look at the spam you receive. Where's it from? Most of the spam I get is from China and Korea. How come? Thanks to the anti-spam movement, the majority of domestic ISPs have shut down open relays and implemented anti-spam policies. The spammers have to go to places where the anti-spam movement hasn't reached in order to send their spam.

      One of those places, evidently, is toad.com. No anti-spam ISP is going to "threaten" John Gilmore about that. They're just going to refuse to accept mail from him.

      (The volume of spam is increasing for the same reason as the volume of email is increasing: there are more people online. Cities of one million people average more murders than villages of two hundred, too. That's why murder stats are reported per unit population.)

    2. Re:Who's fighting who? by Anonymous Coward · · Score: 0

      shelves and crap on my floor

      Please, the preferred term is 'poo'.

    3. Re:Who's fighting who? by AnotherBlackHat · · Score: 2
      You've got it backwards. It's spammers who threaten anti-spam sysadmins and ISPs: sometimes with frivolous lawsuits, but sometimes even with death threats. Just take a look around news.admin.net-abuse.email [google.com].

      All the anti-spam ISPs do is operate mail servers that refuse mail from spammers and those who host them. That's not "threatening"; it's just perfectly reasonable stewardship of their property. If every time I let you in my store you knock my stock off the shelves and crap on my floor, I'm going to pretty soon decide you don't get to do business with me any more.

      Before we force Verio to force others to close their open relays, How about some evidence that closing open relays helps stop spam.


      Take a look at the spam you receive. Where's it from? Most of the spam I get is from China and Korea. How come? Thanks to the anti-spam movement, the majority of domestic ISPs have shut down open relays and implemented anti-spam policies. The spammers have to go to places where the anti-spam movement hasn't reached in order to send their spam.

      One of those places, evidently, is toad.com. No anti-spam ISP is going to "threaten" John Gilmore about that. They're just going to refuse to accept mail from him.

      (The volume of spam is increasing for the same reason as the volume of email is increasing: there are more people online. Cities of one million people average more murders than villages of two hundred, too. That's why murder stats are reported per unit population.)


      No, I haven't got it backwards.
      Just because spammers fight dirty, it doesn't mean the vigilantes don't too.
      Spammers are probably a lot worse individually, but there are a lot more vigilantes.

      The anti-spam people do a lot more than just block email from spammers.
      The most obvious example is that they also block email from ISPs that host
      web pages which spam points to. But they have their share of death threats,
      frivolous lawsuits, hacking attacks, denial of service attacks, boycotts, libel,
      slander, and cussedness too. You probably don't do any of these things,
      but as I said, there are a lot more vigilantes than spammers.

      Most of the spam I receive is emailed to me directly from address blocks
      which resolve to US hosts. Less than 10% goes through a relay.
      And a larger percentage of spam is "personalized" with an ID word this
      year compared with last.
      But don't take my word for it - after all I don't take yours.
      Check your headers, see for yourself.

      I don't believe that blocking open relays will reduce spam even 10%,
      nor do I believe that stopping 10% of the spam in the world is
      worth sacrificing a tiny bit of network connectivity.

      -- Spam Wolf, the best spam blocking vaporware yet!
  69. Worm's IPs by TheSHAD0W · · Score: 2

    What are the IPs in the worm's database? It'd be a good idea to ban the whole list.

  70. Not quite like leaving your home unlocked... by rsidd · · Score: 2

    More like leaving your pharmaceutical factory unlocked and unprotected, for any criminal in the world to use, on the ground that your friends leave the medicines too. That is, it doesn't just hurt you: it hurts others.

  71. Now that I've spent my moderation points by ahde · · Score: 3, Insightful

    and waited a bit for them to have their effect, I'd like to make a couple points.

    One, John Gilmore is not some dipshit with DSL. Take a look at <a href="http://www.toad.com/gnu/">his webpage</a>. He is one of the founding members of the EFF. He knows what he's doing-- technically, morally, and legally.

    Two, he's not sending spam. He's not enabling it, or allowing it. This "virus" doesn't exploit his computers, it exploits other dipshits, and then sends mail through his relay. But Spammers could send their mail through any other open mail relay (there are plenty0) -- but plenty don't. There are other ways to send spam. The virus could be written to use any open relay, why does it target his?

    Maybe his definition of "friends" include people he wouldn't necessarily trust with personal accounts on his service. Maybe they include people he hasn't met personally. Would you deny strong encryption to people in countries whose government would supress their opinions, if expressed openly? No, but you would deny them the ability to send email?

    This is a ridiculous scenario. No one in China or Iraq is going to use John Gilmore's mail server. But he's making a point. And the point isn't just about radicals in bad bad countries. Wouldn't it be nice if there were phones on every block and they were free to use? If everyone who could chipped in a little, the cost of sending email would drop sufficiently. Not to mention the increase in efficiency. Why should the email I send to my neighbor have to go to MAE-WEST and back? Do I really want every piece of mail I send to be routed through Verio or UUNet once they've got carnivores in place. The FBI can't put one in every geek's basement, but they can place them at strategic upstream locations and catch a huge majority the way we're currently set up.

    The problem is spam, not open relays. Don't ban guns, or cars, or forks because people may do bad things. Spam will still come, in larger amounts than ever, even if all open relays are closed.

    You wouldn't accept a company that has multiple expliots in their product to just advice all their customers to just disable the service that has the most frequently used exploit. Should we ban all webservers because Code Red took advantage of a vulnerability in IIS? Browsers because of bubble boy (an Active X exploit)?

    This is a flawed analogy because there are other products that do not suffer from these exploits, and because these were coding flaws by one company. But other implementations could potentially be dangerous. Netscapes brown alert?

    What about porn -- should we let net filters block anything that may be considered inappropriate for children?

    Let's treat the problem, not one of the symptoms. Open relays enable spam. So does DSL. So does weak passwords. So does Hotmail. Is there any question where more spam comes from, toad.com or hotmail.com?

    Wouldn't it be nice to live in a would where spam is not sent? You won't get there by ignoring the problem. Blackhole lists are like burying your head in the sand. They don't even save much on bandwidth. And they're getting further behind in the battle against spammers.

    1. Re:Now that I've spent my moderation points by Anonymous Coward · · Score: 0

      John Gilmore is not some dipshit with DSL.

      Right. He's a dipshit with a T1. Just because he's done "gold" things in the past does not mean that everything he does is "gold".

      he's not sending spam. He's not enabling it, or allowing it.

      He's not sending it, but he is enabling it, AND allowing it, by running an open relay.

      The virus is irrelevant to me. The fact that someone might use his system to harrass me is the problem. And yet when someone blocks his relay, he accuses them of being "thugs".

      He is someone who seriously needs to retire.

    2. Re:Now that I've spent my moderation points by maxpublic · · Score: 2

      Gilmore is free to have an open relay...and I'm free to blacklist him. Freedom all around! How much more American can you possibly get?

      Max

      --
      My god carries a hammer. Your god died nailed to a tree. Any questions?
  72. What happened to free speech? by ruckc · · Score: 1

    Alright people you are all such hypocrites, you call for free speech, you want your free software. But you slam someone who just wants to run an open relay, just because people use it illegally without his consent, you slam him. Me, i run an open relay on my home server because I never know where i will be when i want to send an email, does that make me a bad person that I help the spammers send you guys spam? Maybe so but that is what junk mail fiters are for, thats why 90% of the email i receive daily is automatically deleted. You call for free speech but you slam people who encourage it.

    1. Re:What happened to free speech? by CJ+Hooknose · · Score: 3, Informative
      Me, i run an open relay on my home server because I never know where i will be when i want to send an email, does that make me a bad person that I help the spammers send you guys spam?

      The 1st Amendment doesn't apply to this. You're attempting to raise emotions instead of solving a problem, makes me think you're trolling, but oh well.

      Yes, running an open SMTP relay is bad. Best analogy is leaving your house unlocked, and leaving the liquor cabinet unlocked as well. If you did that, and some 16-year-old got into your whiskey and then behind the wheel of a car, you'd be in trouble... but it's totally legal to leave your house and liquor cabinet unlocked.

      You personally may not be a bad person, but you are certainly lazy, sloppy, and remiss in your duties, since there are a number of ways you can set your machine up to relay mail from legitimate users without running a wide-open relay:

      • POP/IMAP-before-SMTP (easy to do, works with all clients)
      • SMTP Authentication (slightly harder but more secure, some clients may not function properly)
      • Turn relaying off, SSH to your machine and use a local client (very secure, but inconvenient)
      • Set up a web-mail client, access your machine from any browser.
      An SMTP relay is similar to an "attractive nuisance" like a swimming pool in a residential neighborhood. Best course of action is to put a fence up, so people don't piss in your SMTP server, or fall in and sue you.
      --
      Give a monkey a brain and he'll swear he's the center of the universe.
  73. IANAL but........ by cluge · · Score: 2

    I think Verio has a case that Herr Gilmore's server is a nuisance. By definition a nuisance is ".... is something that annoys -- a wearing on the nerves by a persistent unpleasantness. It can evoke anger and interfere with comfort and peace of mind." A server used to spread virii and SPAM would certainly meet that definition.

    In several legal texts I see the following when reffering to nuisances and grounds for legal action
    Nuisance
    attractive nuisance
    forseeability of danger
    negligence
    liability

    I would think that this server can be shown to fit almost all of the above terms. Does anyone know if civil suits can be used to help stop SPAM? Is there a lawyer willing to take up the cause?

    . Can /.er's find a fit for this example? Is it a good option?

    --
    "Science is about ego as much as it is about discovery and truth " - I said it, so sue me.
  74. Relay still open? by Helevius · · Score: 1

    Is this still an issue?

    ---

    host -t mx toad.com
    toad.com mail is handled (pri=100) by old.toad.com
    toad.com mail is handled (pri=200) by ecotone.toad.com

    nc -v -v old.toad.com 25
    DNS fwd/rev mismatch: old.toad.com != toad.com
    old.toad.com [140.174.2.1] 25 (smtp) : Connection refused
    sent 0, rcvd 0

    nc -v -v ecotone.toad.com 25
    ecotone.toad.com [216.240.42.33] 25 (smtp) open
    220 ecotone.toad.com ESMTP Sendmail 8.8.7/8.8.7; Thu, 7 Mar 2002 10:09:26 -0800
    HELO test
    250 ecotone.toad.com Hello xx-myhostname-xx [xx-myipaddress-xx], pleased to meet you
    MAIL FROM:test@test.com
    250 test@test.com... Sender ok
    RCPT TO:test@test.org
    551 test@test.org... we do not relay
    quit
    221 ecotone.toad.com closing connection
    sent 61, rcvd 283

    ---

    So, is the relay closed?

    Helevius

    1. Re:Relay still open? by bruns · · Score: 2, Informative

      [bruns@summit bruns]$ rlytest 140.174.2.1
      Connecting to 140.174.2.1 ...
      220 toad.com ESMTP Sendmail 8.7.5/8.7.3; Thu, 7 Mar 2002 10:52:02 -0800 (PST)
      HELO mail.2mbit.com
      250 toad.com Hello bruns@summit.magenet.net [216.152.230.50], pleased to meet you
      MAIL FROM:nobody@[140.174.2.1]
      250 nobody@[140.174.2.1]... Sender ok
      RCPT TO:bruns@mail.2mbit.com
      250 Recipient ok
      DATA
      354 Enter mail, end with "." on a line by itself
      (message body)
      250 KAA10196 Message accepted for delivery
      QUIT
      221 toad.com closing connection
      rlytest: relay accepted - final response code 221

      Still wide open.

      --
      Brielle
    2. Re:Relay still open? by Helevius · · Score: 1

      Got it -- toad.com is 140.174.2.1, although I tested ecotone.toad.com.

      Helevius

  75. Who is John Gilmore? by SiliconEntity · · Score: 5, Informative
    Readers should be aware that John Gilmore is not just a clueless know-nothing who refuses to close his mail server out of ignorance.

    Gilmore is a true Internet pioneer and activist, a dedicated supporter of free speech. A short list of his accomplishments is available here, including being one of the first employees at Sun and helping found the EFF. In addition he was an early activist in getting the Usenet alt. groups going as an alternative to the rest of the hierarchy where tight controls were in place. He has been active in supporting free access to cryptography, helping found the Cypherpunks and participating in a number of law suits and FOIA actions to get the government to reduce restrictions on crypto. He has funded the FreeSwan effort to build transparent point to point crypto into the Linux kernel.

    He also founded Cygnus Support, probably the first company to prove that you could make money off of open source software. The company was sold to Red Hat in 1999 for $674 million.

    John Gilmore was fighting for free speech and the right to communicate before most of us had ever heard of the Internet. If his actions seem out of step with an increasingly paranoid and closed Internet community, I suggest that we not be so quick to assume that everyone else is right and Gilmore is wrong. History has shown him to be a far sighted thinker who has been on the right side of virtually every issue.

    1. Re:Who is John Gilmore? by Electrum · · Score: 2

      Then why isn't he smart enough to setup his mail server to use authentication? The web hosting company I work for (ITmom.com) allows its customers to send mail using our SMTP server, and we're not an open relay. We use POP-before-SMTP, so only IP's that have recently successfully authenticated via POP3 can send mail. There's also SMTP authentication, SSH tunneling, and probably some other available methods.

      The spam problem isn't going to go away. Refusing to close relays just makes it worse.
    2. Re:Who is John Gilmore? by Anonymous Coward · · Score: 0

      Right. ...

      And Timothy Leary was once a well respected academic. ... What's yer point?

  76. Open relay in the US? by LadyLucky · · Score: 2

    Oh my, oh my. I thought they only came from Asia. Oh well, time to block all emails from America...

    --
    dominionrd.blogspot.com - Restaurants on
  77. Auth or Go Away by theirpuppet · · Score: 1
    If you can't implement some authentication mechanism for your SMTP server, then you shouldn't be running a server. If your server is used to propagate spam, or a virus, or anything that can be construed as damaging, then you should be held liable.


    Frankly it doesn't matter who you are, it's all about responsibility. If you don't have it, then you shouldn't be responsible for anything, except your actions (in a court of law).


    I admit that there are privacy issues that aren't resolved by the above. If you want a privacy protected, anonymous system then it needs to be better planned out to protect against abuse. Maybe this guy, with his influence, could get something going.

  78. Let me get this right? by Anonymous Coward · · Score: 0

    His machine is being used by a (windows) virus to spread it self. This sounds to me like a noble deed this man is doing.

    Keep up the great work ...

  79. AUP by NateDawg · · Score: 1

    Nobody is obligated to provide this guy with internet service. And those who do provide it are entitled to limit the terms in any way they please.

    Having been in the ISP business and the hosting business for quite some time, I can attest to the fact that it's wise to take a very strict approach to spam/spammers. If Verio doesn't cut this guy off, the black hole lists may decide that entire blocks of their IP's should be listed. How would you respond to being blacklisted because your "IP neighbor" thinks he should be allowed to maintain an open relay simply for the sake of the convenience. Verio would loose customers if they didn't act.

    According to Verio's AUP (last modified March 9, 2000):

    Spamming -- Sending unsolicited bulk and/or commercial messages over the Internet (known as "spamming"). It is not only harmful because of its negative impact on consumer attitudes toward NTT/VERIO, but also because it can overload NTT/VERIO's network and disrupt service to NTT/VERIO subscribers. Also, maintaining an open SMTP relay is prohibited. When a complaint is received, NTT/VERIO has the discretion to determine from all of the evidence whether the email recipients were from an "opt-in" email list.

  80. Re: DDOS through toad.com, that's what it'll take by gorbachev · · Score: 1

    There's no law in any country in the world that would hold an owner of an open relay liable for the spam sent through it.

    The situation is even more complex, when you consider that his open relay appears to be only used to relay spam to Italian Internet users.

    What needs to happen is that some script kiddie needs to initiate a DDOS attack using toad.com shutting down a few high volume online stores, like Amazon or eBay. John Gilmore can not possibly claim ignorance, when Amazon and eBay will sue him for damages.

    Of course they won't sue anybody, because they'd rather pass on the costs to their users as part of the operating costs of an Internet business. That's the typical response from credit card companies, Internet businesses, ISPs and the law enforcement agencies regarding online security issues.

    --
    In Soviet Russia, I ruled you
  81. Useless by FireStorm69 · · Score: 1

    All this blacklisting going on today is useless in my opinion. So an open relay gets blacklisted, whoopee, the spammer just moves to a new one.. They are very good about finding and utilizing open relays. It's annoying and time consuming to try to stop them and the spam they send.. We try to do as much as we can, but the spam is still getting through.. I have not yet found a 100% guarenteed way of stopping spam without limiting the capabilities of our honest clients. Maybe I am missing something, I am, after all, still in newbie land.

  82. SPAM from toad.com by Anonymous Coward · · Score: 0

    It would appear that gilmore's domain, toad.com (whois -h whois.geektools.com toad.com) is listed by a number of the DNSbls (see: http://relays.osirusoft.com/cgi-bin/rbcheck.cgi ).

    Personally, I think this is a good, if not great, idea. Open relays suck. They are the "attractive nusiance" of the internet.

    This is not a free speach issue. This is a good net citizenship issue. Plainly, Gilmore is being a bad net citizen and is being shuned by a number of other net citizens. Gilmore's right to "free speach" ends at the entry to my mail server. My property, my rules.

    I suppose it is no coincidence that he chose Verio as a hosting company. Verio are reputed to be very spam-friendly (see: http://groups.google.com/groups?as_q=verio%20spam& as_ugroup=news.admin.net-abuse.*&hl=en ).

    Verio's netblock 140.174.0.0/16 is already shunned by many MTAs, including mine, for its spam support. I encourage you to do the same.

  83. Verio's generosity by pinkUZI · · Score: 1

    After some interaction among me, Verio, and lawyers from Stanford Law School's Internet and Society law clinic, Verio agreed to not immediately terminate my service if I modified my mailer software to avoid forwarding large quantities of email from single addresses over short periods of time.

    Seems rather generous of Verio to me, it is after all their equipment to control the way that they want.

    --
    You are receiving this message because your browser supports Slashdot Sigs and you have Slashdot Sigs enabled.
  84. The worst victims of open relays are its operators by DocSnyder · · Score: 3, Interesting

    I wonder if John Gilmore administrates his mail server and reads Postmaster mails on his own. If he did, he would spend the whole day on cleaning it up.

    A bit more than a year ago I worked at a company which was running an open relay to allow their customers sending mails through it. It has been blacklisted everywhere, no one has ever read Postmaster, they just reinstalled the mail server (out-of-the-box system, which they are developing) or removed the entire mail spool if it got too bad.

    Yet they had of course plenty of problems with sending their own mail - so had their customers who used the relay, too. Being blacklisted on RSS, ORBS and dozens of other DNS-based lists causes quite some mails to be rejected - the percentage is certainly too high to ignore.

    To make it short, it took several weeks to persuade each customer to change his mail server's configuration into using the ISP's mail relay instead of ours. Meanwhile the company moved its former 64k Internet connection to a 2Mbit/s line, which made relayed spam spread as fire.

    Within the few weeks between the new line went up and we were finally able to replace the old mail server with a new system running Postfix, the mail relay was almost unusable for us - it took about a minute to even have a TCP connection of any type accepted, the system load was always between 10 and 20, and the ISP bill was _really_ high.

    After putting Postfix into work, it was my job to keep the mail system running. As it ran on the same IP address as the old server, the spammers didn't stop trying to relay their trash through it. AFAICT almost no spam flood mailer checks SMTP return codes, and if it does, it tries to connect to the secondary MX. As a consequence the syslog has been filled with thousands of "Relaying denied" messages, SMTP sessions have been kept up for hours, and as they discovered after some time that this relay has been closed, they scanned our networks for some more open SMTP servers - not only - they scanned almost everything, so as if they can't relay spam through us, they at least want to look for an open FTP or HTTP server to share pr0n and w4r3z. It didn't take them too long to find an open proxy, and they caused 80 GB (the ISP bill was 6000 € that month) of bandwidth until we discovered it. They found an open FTP server, too, and uploaded about 5 GB of m0v13z until the partition went full what made us notice it.

    What is more, the mail server has been fixed, but the IP address has still been blacklisted. After two weeks of notifying blacklist operators and having our mail server tested as secure, it has been unlisted from most services. Spam continued, of course, Postmaster notifications due to recipients who blacklisted our mail server manually continued to occur, and some customers who forgot to change their mail relay or were unable to do so (it's an easily-installable out-of-the-box system which they bought from us, so they just lacked basic knowledge to run a mail server). It has been a mess even months after we closed the mail relay.

    So my advice for John Gilmore and anyone else who operates an open relay, intentionally or not: Close it! You are having the worst problems of all involved parties! If possible, move to a different IP network or you won't get any rest in the near future.

  85. Gilmore is right, MAPS, SBL, and Spews are wrong. by arcade · · Score: 3, Interesting

    OKay. now, why do I argue that Gilmore is right? Well its quite simple. You see, if we want to get rid of the chickenboners, we have to:

    a) Get rid of all open relays (impossible!)

    b) Get rid of all socksproxys (Do we want to get rid of this great way of staying anonymous?)

    c) Get rid of all open squid-servers (Do we want to get rid of this great way of staying semi-anonymous?)

    d) Get rid of all other ways you can use/abuse all sorts of relays.

    The problem is that the fight against spam hurts not only email administrators anymore, but hostmasters, webmasters, people that want to run anonymous proxies of any sort, and so forth. If one wins the fight against anonymous relaying, one removes the option of staying completely (or semi-completely) anonymous in many cases.

    Do you think the "antispammers" like anonymous remailers? Nope, not unless you're the customer of one, or that there are ways they may limit/stop the spamflow.

    I hate the spam as much as anyone, but I really don't think the solution is to block every possibility of staying anonymous. The solution is to rewrite the fucking mail protocol, not to let _everything_ suffer because of spam beeing intolerable.

    end of rant.

    --
    "Rune Kristian Viken" - http://www.nwo.no - arca
  86. Email Vulnerability by jes5199 · · Score: 1

    Email has an inherent security flaw that we would never accept in any other standard... we essentially give everyone in the world write access to our Inbox.
    We need to make a new standard, that makes it impossible for someone to send you a message without some sort of cryptographic authentication. Perhaps with third party servers that can authenticate "yes, this is a real person", plus any automated service that you gave a PGP signed certificate.
    Forever and ever, world without Spam. Amen.

    --
    monkeys.
  87. Libertarianism by jjohnson · · Score: 1

    How can a libertarian cry "censorship!" when it's a private corporation making rules about its own terms of service? If he doesn't like it, he can find another ISP.

    --
    Anyone who loves or hates any language, platform, or manufacturer, doesn't know what they're talking about.
  88. responsibility by 47PHA60 · · Score: 1

    If he wants his friends to be able to use his mail server, his responsibility is to set up some kind of authentication and account management. Simple as that.

    If I were his ISP I would cut off all access until he proved to me that he had secured this hole. After all, it's his machine, but it's his ISP's network.

  89. Mod the parent up by Russ+Nelson · · Score: 2

    Somebody please moderate the parent up. John Romkey is one of the co-founders of TLG, from whom John Gilmore purchased his T-1 from. TLG ended up getting bought by Verio.
    -russ

    --
    Don't piss off The Angry Economist
  90. Thats not how RBL's work by cluge · · Score: 2

    The way RBL works is that your INCOMING mail is blacklisted. When a machine makes a connection to your ISP's SMTP port it checks it against the RBL. If that machine is NOT in the RBL then the machine continues with the trasaction. The SMTP server does not perform this same lookup when DELIVERING mail.

    If and ISP blackholed his IP then you would have a problem. Verio apparently had filtered port 25 (they later took it off), which would prevent e-mail from getting to him. This is why I sent my mail to both his publically listed addresses. EFF.org isn't in any RBL that I know of (except china's)

    --
    "Science is about ego as much as it is about discovery and truth " - I said it, so sue me.
    1. Re: Thats not how RBL's work by Anonymous Coward · · Score: 0
      The way RBL works is that your INCOMING mail is blacklisted. When a machine makes a connection to your ISP's SMTP port it checks it against the RBL. If that machine is NOT in the RBL then the machine continues with the trasaction. The SMTP server does not perform this same lookup when DELIVERING mail.

      If you're using the MAPS RBL [sm] in BGP mode, any IP in the RBL gets routed to the bit bucket. No contact, ever, in or out. I fixed his little open relay problem locally by dropping all packets to his machines at the border router. Funny, I can't seem to resolve toad.com any more. (If you're interested in blocking his insecure spam spewers, be sure to block 140.174.2.1 as well as 216.240.42.33 -- ecotone.toad.com is his other mail server. You might want to block all of 216.240.42.0/24.

      As far as I'm concerned, Gilmore and his machines can rot in net.hell forever. He's a dinosaur, and perhaps this will help to hurry his extinction. And wasn't toad.com used by Mitnick to stage an attack against Shimomura's machines? Hey, John, gimme root, I promise I won't abuse it.

  91. how effective by Anonymous Coward · · Score: 0

    a design do you think it is, that requires proper configuration of all the various systems involved
    to avoid collapse?

    as an aside i think john is trying to make a point,
    not just about retaining his ability to do whatever
    he wants with his internet connection, but a more
    subtle one about privacy.

    who is it that gets to decide how information
    flows, how it must be addressed and delivered?

    i dont remember voting for them

  92. This reminds me of the same shit in HAM Radio... by Wanderer1 · · Score: 2, Interesting

    Recently I've been reading about how an amateur radio based network involving wireless packet data fell apart because a few stations did not organize in the same way as the rest of the network. This isn't the sole reason it fell apart, much of its demise seems to be from apathy.

    Understand that amateur radio in the US and in most countries, consists of free (as in beer) but regulated swaths of the electromagnetic spectrum. This spectrum is shared by all amateur radio operators to communicate on using voice, morse code, video, data or some combination. Not unlike the Internet collective of networks, it is a shared resource of interconnected points.

    The network in question used a specific frequency to communicate inbetween BBS nodes, and another frequency to communicate between BBSes and end-users. A loosely organized group provided a set of working rules to ensure the network could function efficiently. If BBS to BBS traffic and end-user traffic were shared on the same frequency, the network would bog down in short order (packet switched radio is slow at 1200-9600 bps plus overhead). Splitting the types of traffic up helped to ensure things kept moving.

    For whatever reason, a few nodes decided to pass BBS to BBS traffic on the end-user frequency. The constant chatter between these unruly BBSes made it very difficult for end-users to operate making the network nearly unusable. No one was really in the wrong from a legal or regulatory stance, but they were obviously disrupting the function of a "system" and causing headaches for other users of the shared medium.

    In US HAM radio, the FCC leaves problems in the hands of the amateurs to sort out. First come, first serve on the frequency. It is illegal to wilfully interfere with stations who are carrying on an active conversation. Written early under the assumption that two people could not possibly talk all day and all night long, the regulation did not account for repeaters. Repeaters are always-on radios mounted in geographically advantageous places to amplify weak radio signals extending their range. Who "owns" the frequency occupied by a repeater? No one. The FCC left it to Hams to coordinate the frequency assignments for a repeater. There is language in the regulations affording precedence when interference occurs with a repeater involving the Ham-run coordination. The problem was handled in the community and repeaters thrive today.

    But back to the packet network - while HAMs have shown to be very cooperative folks (albeit ornery) with repeaters, this cooperation did not extend to the packet network. I'm told some terrific arguments used to break out at the meetings of the network group. Compromise, it seemed, was not an option.

    Finally, rather than improve the software and hardware to deal with interference, things died down. The network still exists as only a shadow of its former glory - and without advancement.

    The Internet infrastructure consists of privately owned equipment, and each owner can choose whether or not they'll cope with something they don't like. But the collective "Internet" that exists only when these networks work together is much like that shared spectrum HAMs use. It only works when the people who own the infrastructure agree to equal access for all traffic and issues should be settled in accordance with the understanding that the Internet is a commons. Anything less is not the "Internet."

    Moral Beating:
    If you don't like SPAM, then adjust your receiver to ignore it. The end-2-end principle should apply. Only the edge device should carry the ability to decide if information is of value or not. IF the SMTP protocol is too open for your tastes, then revise it to become more intelligent.
    There is nothing wrong with subscribing to blacklists for your own mailbox, but to do so in a manner that blocks mail for those who have no choice in the matter violates the spirit of the end-2-end concept and the spirit of freedom that many in the earlier days of the Internet thought could change society for the better.

    Quit bitching, apply your filters and focus on things that really matter.

    -b-

  93. The point is my choice. by Derek+Pomery · · Score: 2

    "The problem is spam, not open relays. Don't ban guns, or cars, or forks because people may do bad things. Spam will still come, in larger amount than ever, even if all open relays are closed."

    The reason open relays are used is because spammers frequently get blocked. I do that myself. I want to have the choice to block spammers. I also *don't* want to have to add Mr. Gilmore to my list of spam servers, since he has legitimate users.

    That's why I urge him to close down his relay, or require authentication.
    I fail to see your point about mail having to go through the large ISPs. My mail goes straight from my machine to whomeever I am trying to deliver it to. Yes, those packets pass through the large ISPs, but then, so do Mr. Gilmore's (and frequently my traffic is encrypted anyway, so good luck to them)
    If you want privacy, use PGP.

    And I fail to see a phone on every corner as helpful. It would force me to unlist my cell and block all public phones so I wouldn't get called 3000 times a day.

    I'm all for anonymizers, encryption, and internet privacy, but let's all use a little common sense so I don't have to block the interesting things Mr. Gilmore might have to say due to his offers of penis enlargement.

    --
    -- perl -e'print pack"H*","6e656d6f406d38792e6f7267"' /. ate my old sig. Bastards.
  94. Re: Ok - so he's trying to make a point..... by King_TJ · · Score: 2

    I think it's rather clear that Gilmore isn't really running an open relay because he truly has concerns that some of his "friends" (who he doesn't trust enough to give accounts to on his system) might not be able to send out email.

    He's merely trying to start trouble, for the sake of raising awareness that open-relay blocking won't eliminate spam.

    I say fine, point taken - but you're still not part of the solution. Instead of bickering with an ISP over their rights to kick you off for breaking your terms of service agreement, why not help develop new tools to better filter out spam? That would do everyone much more good!

  95. My letter to Verio and Mr. Gilmore by mikl · · Score: 3, Interesting

    From: Michael Merritt
    To: drg@verio.net
    Cc: gnu@toad.com
    Date: Thu, 7 Mar 2002 12:47:17 -0600

    Mr. Darren Grabowski
    Verio Security

    Mr. Grabowski,

    I write to you in response to the web page located at
    http://www.toad.com/gnu/verio-censorship.html

    I encourage you to continue your actions against Mr. Gilmore in response to
    his refusal to comply with the terms of your company's AUP.

    Let me state that I firmly uphold Mr. Gilmore's RIGHTS to run an open mail
    relay as "free speech". Yet, I also firmly uphold your company's ("Verio")
    RIGHTS to deny him service if he does not adhere to the terms of the service
    contract which you offer him. Mr. Gilmore's continual payment of the service
    charge for his T1 connection is acceptance of the terms of Verio's service
    contract.

    Furthermore, I firmly support the RIGHTS of Internet users, system and
    network administrators, and blacklists to REFUSE to accept mail from Mr.
    Gilmore's server/connection/domain.

    I am exercising my RIGHTS to freedom of speech and expression in this
    message, as any American citizen is permitted. I also respect the fact that
    you have a RIGHT to disregard, ignore, or otherwise disagree with my views,
    beliefs, and practices.

    If Mr. Gilmore is truly concerned about everyone having the freedom to
    exercise their RIGHTS, he will accept the fact that Verio has the RIGHT to
    deny him a connection, and he has the RIGHT to seek a connection to the
    Internet elsewhere. I do not find a law or governing statute anywhere that
    declares every free man has a RIGHT to access the Internet.

    Thank you for your time and consideration of this matter,

    --
    Michael Merritt
    SPAM filtering by SubLimeMail -- http://www.sublimemail.com/
    (remainder of signature snipped for /. "junk filter")

    1. Re:My letter to Verio and Mr. Gilmore by Anonymous Coward · · Score: 0

      To: Michael Merritt ( michael@miklm.com )

      You should make it easier fo someone to contact you by email. I had to go to your site and find your email addess there before I could post it in this message.

      Signed,
      A concerned netizen.

    2. Re:My letter to Verio and Mr. Gilmore by mikl · · Score: 1

      Dear Nameless Coward,

      In fact I'm not at all ashamed or embarrassed to put my name and email address beside what I posted/wrote. I know it isn't hard to find my email address and even my telephone number (it is on the site as well). Furthermore, my uid is based on a phonetic spelling of my name. Very clever of me to try so hard to stay an "Anonymous Coward", isn't it?

      I initially posted the message verbatim which included my e-mail signature, which contains my web site, email address, phone number, and AIM/MSN screen names. However, the Slashdot Junk Buster rejected it due to two lines of '---' characters. I'm not afraid of being "found out" like it appears you and so many other blathering idiots on the Internet are.

      Thank you for making it easier for others to contact me. I hope you will devote the same energy into writing Verio or Mr. Gilmore, and sent me a copy of it, even if you don't agree.

      -Michael

  96. John Gilmore is lying by hoggoth · · Score: 5, Interesting

    Come on people! John Gilmore is going on and on about his freedom of speech and how he is running a mail relay for his friends.

    He is lying.

    If he really wanted to run a mail relay for his friends you could authenicate them on a properly administered CLOSED mail relay. Here are a few ways to do this:
    POP before SMTP authentication
    SMTP authentication
    SSH accounts for his friends
    Webmail accounts

    And John Gilmore certainly knows these and other methods of properly administering his mail server.
    I doubt he is running a spam relay for profit, I think he is just trying to stubbornly make some minor point of personal philosophy, and hiding it with his words.

    --
    - For the complete works of Shakespeare: cat /dev/random (may take some time)
    1. Re:John Gilmore is lying by mikl · · Score: 1

      > I think he is just trying to stubbornly make some
      > minor point of personal philosophy, and hiding it
      > with his words.

      That is almost exactly the case, except he isn't even hiding it with his words. If you find time to read the entire page, I think he makes it pretty clear that he's making himself a "martyr" of sorts (by having his machines killed from the Internet at large) to make his point.

      While I respect what the man has done in the past, I think he is indeed a stubborn old fool in a lot of his latest undertakings.

  97. Open Relays don't cause spam ... by Jumperalex · · Score: 2, Interesting

    Spammers cause spam.

    Sounds like a statement I very much believe in about guns. Yet for some reason I feel it isn't quite as simple. I liken the scenario (closing a relay) to putting a lock on a gun to prevent a child from getting their little hands on it and shooting someone/themselves. So too is closing a relay.

    But then again the difference is that an open relay does have legitimate non-spamming uses. Again sorta sounds like an argument often made for mp3, napster etc. Things which I also feel should not be shut down.

    I don't think there is a 100% correct answer but I will defend my position that open relays should be closed by saying: closing open relays has the potential to signifigantly prevent bad things from happening (spam and virii) while ultimatly not preventing much of anything legitamate from being done. Much like a lock on the aforementioned gun doesn't prevent you from hunting or self-defense. so IMO relays should be closed. Of course we all know what my opinion is worth :)

    --
    If you can't be good, be good at it!
  98. SMTP AUTH by Anonymous Coward · · Score: 0

    ITS CALLED SMTP AUTH, why doesnt he use it? What a goof.

  99. heheh by Anonymous Coward · · Score: 0

    thanks, that made my afternoon

  100. You misdefined censorship. by Anonymous Coward · · Score: 0
    Censorship is not soley a government function. Censorship is an -authority- function. And entity with the ability to control speech, publishing, etc has the ability to censor.



    Hell, -I- could censor -you- given enough money and possibly a gun to your head. And I'm just an underpaid private citizen with credit card debt. Quit trying to confuse the issue.

  101. Bad analogy by scarhill · · Score: 1

    Don't ban guns, or cars, or forks because people may do bad things.

    I agree with the sentiment, but it totally misses the point in this case. If SMTP servers are like guns then authentication is like trigger locks.

    Suppose I left a gun in an unlocked shed "so my friends can use it". If kids were stopping by and firing bullets around the neighborhood, my neighbors might be pretty upset. If I self-righteously protested that neither I nor any of my friends had fired those bullets, they probably wouldn't be mollified. If I refused to lock up the gun, they might go to my landlord and try to get me evicted.

    According to the article, Gilmore is a libertarian. So he should applaud people finding private solutions to the problem his open relay is creating.

    1. Re:Bad analogy by ahde · · Score: 2

      If someone breaks into your shed and steals your gun and shoots themselves with it, I'm sure you'll be full of tears for them because your padlock was screwed onto the door with ordinary phillips head screws.

  102. There's no excuse for an Open Relay! by OneFix · · Score: 1

    I think we discussed this enough in the prior story Are SPAM Blacklists Unreasonable?

    But, some information just bears repeating. First, there is a very good test system put in place by The Open Relay Database. Anyone running a mail server on their system should use this service (I do).

    There is also a very good site that runs down how to close holes in different servers at mail-abuse.org.

    Regardless of why this system is being exploited, it is certainly the system administrators fault...

  103. Big difference by HiThere · · Score: 2

    If the government makes a rule, they threaten you with force.
    If people decide to block you, they just stop listening to you.

    The first is quite a dubious activity. Sometimes necessary (almost certainly), but always deserving of a great deal of hesitation.

    The second is the individual decision of people. And if people are too draconian, then they will start being ignored. But if they decide that you aren't worth listening to, then it is their clear right not to listen.

    That said, blocking lists is certainly a tremendous bother at times. "(Mail relay prevented by default)" can severly reduce the value of a mailing list, as well as enhancing it. It blocks spam from a site, and also blocks all other communications from those using the same ISP. But it's their right.
    .

    --

    I think we've pushed this "anyone can grow up to be president" thing too far.
  104. Harms the EFF? by Anonymous Coward · · Score: 0

    You raise an interesting question. Does this harm the (presumably) good name of the EFF? Generally, the EFF is on the Side of Clue and Good Network Health as well as the side of Freedom.

    I have seen comments on here about people not donating to the EFF so as not to support their somewhat weird spam statements.

    1. Re:Harms the EFF? by gorbachev · · Score: 1

      Yes, it harms the EFF.

      John Gilmore is/was using EFF lawyers to fight Verio. Your EFF contributions are in part going to John Gilmore's personal use.

      I would say that's harming the EFF's reputation.

      --
      In Soviet Russia, I ruled you
  105. info? Is Verio a local monopoly? by HiThere · · Score: 2

    These arguments seem air-tight unless Verio is a local monopoly. If it is, then perhaps they need to have two classes of membership, one of which is unfiltered.

    --

    I think we've pushed this "anyone can grow up to be president" thing too far.
  106. A good argument by randombit · · Score: 3, Informative

    I went and saw a talk this afternoon, given by John Peter Barlow (another co-found of EFF) at my school. Someone asked about this, and he had a very good response, one which makes me side with Gilmore on this:

    The whole point of the internet is dumb network, smart nodes. If the end nodes aren't smart enough to deal with spam (99.9% is quite easy to identify) and viruses (hello MS, I'm talking to you), then that is the problem of the end nodes, not the network.

    <possible flamebait>
    If I take a bus to downtown and proceed to throw a brick through a store window, is that the fault of the city, for running the bus service? (I know this isn't a particularly good analogy, but it's the best I can come up with on short notice)
    </possible flamebait>

    Posting at +2 on purpose. Moderate as you like.

    1. Re:A good argument by haral · · Score: 1
      The whole point of the internet is dumb network, smart nodes. If the end nodes aren't smart enough to deal with spam (99.9% is quite easy to identify) and viruses (hello MS, I'm talking to you), then that is the problem of the end nodes, not the network.

      And if someone uses compromised computers on the net to DDOS your server, it is your problem. After all, your end node should be smart enough to deal with it, right?

      Wrong! I think that the administrators of the compromised servers carry part of the blame. The same goes for the administrators for the open-relay servers.

      --alex

    2. Re:A good argument by Bartmoss · · Score: 2

      IN your example, the gilmore person would be the rock thrower, and the T1 would be the bus service. The T1 is not to blame, but the person running the open relay. There is NO justification for open relays. None. Zero. Nada. Keine. Null. He can use SMTP Authentication or have his relay taken down. Everything else is just sick.

    3. Re:A good argument by randombit · · Score: 2

      And if someone uses compromised computers on the net to DDOS your server, it is your problem. After all, your end node should be smart enough to deal with it, right?

      That isn't a problem smarts can deal with (well, at least in a reasonable sense). Anyway, if those zombie boxen had any smarts to start with, they wouldn't be wasting their bandwidth DDOSing some random server.

  107. I wonder if anyone will.... by elgee · · Score: 1

    I wonder if anyone will mailbomb him using his mail server? I think that would be delicious irony to fill up his mailbox several times a day with junk. Just a thought.

  108. Welcome to Internet Top 10 Virus! by ch-chuck · · Score: 2

    Since its discovery around Valentine's Day, Yaha, also known as "Valscr," has wormed its way past Nimda, Hybris and Funlove to the number eight position on the current list of virus threats tracked by managed e-mail provider MessageLabs.

    This almost sounds like a Casey Kasem American top 40 show... Wow great, now virus writers have a feedback mechanism to rate their performance and a target to shoot for: NUMBER 1 on the list.

    CK: Now, here's VdUB with his latest hit, 'Don't open this fking Email!!!'. Tell us, VdUB, to what do you attribut your recent success as #1 email virus writer for 3 weeks in a row?

    V: Well, I, uh, wud like to thank most of all, the Microsoft Outlook development team for making this all possible, special greetz to 4TerTz, and all the gang at the 7oyz2bad gang for the stealthSMTP script and killer relays...

    --
    try { do() || do_not(); } catch (JediException err) { yoda(err); }
  109. Kevin Mitnick by Anonymous Coward · · Score: 0

    Kevin Mitnick, the guy who spent several years in jail for hacking, actually hacked several of John Gilmore's computers. I wonder how he did it? ;)

    John Gilmore's a nice guy, but he's a wealthy eccentric who doesn't take advice from others. He's a lot like Bill Gates, except he's a hippie GNU/Linux nut. He was one of the first employees at Sun Microsystems.

    You can read all about his Libertarian attitude and lifestyle in the book Takedown.

  110. Regarding China' s complaint by kindbud · · Score: 2

    If Gilmore is responsible for the spam sent through his open relay, then MAPS and Spews and Osirisoft and all the other DNSBL will be responsible when China begins imprisoning admins for leaving relays open.

    The argument against Gilmore seems to be that when you know your actions will enable or make possible actions taken by others, and you take that action anyway, you are responsible for the actions of those other parties.

    If that is so, then all ther DNSBL operators will be responsible if China starts locking up admins who neglect to close their relays. It is as simple as that. One follows from the other.

    I am with Gilmore - spam is the problem, not open relays.

    Now here comes the flames...

    --
    Edith Keeler Must Die
    1. Re:Regarding China' s complaint by Anonymous Coward · · Score: 0

      I would welcome any policy China might institute against admins who don't secure their relays. I would especially welcome a policy against spammers. I think death would be a bit extreme, but I did have to think about it for a second. :)

      Why? Because, in any job you have reasonable rules you must follow. Usually, those rules are created to enforce responsible behavior. Armored car drivers lock the doors when they leave the truck. Would you hold it against their employer for enforcing that behavior? I wouldn't. I would expect them to fire their employees who don't lock the vehicle. You can't expect the bad guys to respect that the money in the vehicle isn't theirs, nor can you expect law enforcement to ensure that the bad guys won't open the door and take the money bags. There are a million such examples in life.

      If, though negligence, someone indirectly allows harm to come to others, they can be held responsible. If an admin is too fucking lazy to lock down his mail server (takes about 2 seconds with most mail server apps I know), and his server is used to propagate large amounts of spam to unwilling recipients, then he is responsible for it and should be punished.

  111. Free Speech or Free Noise? by madhakr · · Score: 3, Insightful
    When did Free Speech become about allowing more bits to be pushed around in the network? Raw data can't be speech; information has to be meaningful and understandable, and understood, to be speech. Running an open mail relay, especially one which is known to be relaying spam, viruses, etc, actually hampers the flow of free speech, since it makes valuable information more difficult to find amid the junk.

    If you want to apply the usual ethics about freedom of speech, you ought to require him to use some form of authentication for his friends, to ensure that their speech is accessable (since he won't be blacklisted) and free of excessive noise (spam, viruses). VPN tunneling, IMAP, shell accounts, webmail, authenticated POP, and POP over SSH come to mind.

    Of course, I'm assuming that spam and viruses are not valuable examples of free speech in action, a view that may be difficult to justify. I consider them to not be speech for the same reason that I don't think the signals generated by a garage door opener are speech--they are signals, possibly meaningful in some context, whose intended purpose as used is to cause some event to occur. The spammer says, "I push this button, and our monthly page views go up!"; the virus distributor says, "I push this button, and 3y3 0wnz j00!"; I say, "I push this button, and my garage opens!" In none of these cases is the button pusher trying to convey any information to another person. If the signal (virus, merchandise, scam) is itself an object of conversation, I can see it being speech, but that context isn't relevant to open mail relays.

  112. Not a jackass. A cypherpunk. by Chasing+Amy · · Score: 5, Insightful

    Isn't it obvious that the reason he wants to keep his relay open is so that his cypherpunk friends can send less-traceable e-mails? A noble goal, even though it has unfortunate side-effects regarding spam and this new virus.

    In this day and age of government snooping, Carnivore, shutting down anti-globalization websites, justifying mass surveillance of all citizens under the rubric of anti-terrorism, and the other atrocities reported every damn day on /., surely the hypocrites here can retract their heads from their asses long enough to see the adantages of a static open relay for helping to safeguard the privacy of e-mails. Does it have unwanted side effects? Yeah. Freedom always does.

    Look, let's be frank here: spammers will always find open relays in Asia. Always. China's recent baby steps forward notwithstanding, you know that this is true. This is part of the spammer's job. If spammers couldn't find open relays, they'd just purchase ISP accounts, start flooding out of their own servers, and move on when they get cut off. They sometimes do it now, even though open relays aren't hard to find.

    Toad, on the other hand, is just a way for the privacy conscious to have a little conrol over how their e-mail gets routed without having to work like a spammer to keep up-to-date lists of Asian relays. It's just an added layer of obfuscation. Shutting it down won't curb spam or viruses, it'll just take away a privacy tool.

    --

    Chasing Amy
    (We all chase Amy...)
    "The more corrupt the state, the more numerous the laws"-Tacitus
  113. It is a general purpose tool by John+Macdonald · · Score: 1

    You miss an important point. He provides a tool to facilitate anonymous posting.

    - Spammers can misuse this to send spam.

    - Whistleblowers and humans rights activists and oppressed people can use this to pass out information without getting shot or identified. There are parts of the world where complaining about your situation is a capital offence. Even is the "free" world, complaining about mistakes in a company can cost a job and your livelihood. (It is not "his friends" that he provides this facility for - so a large number of other people have also missed the point.)

    Napster/Gnutella provide a tool to facilitate copying files.

    - Some people can misuse them to bypass copyright restrictions.

    - Other people can use them to copy files for legitimate purposes.

    How is a general purpose tool that can allow publishing information about attrocities less worthy of your acceptance than a general purpose tool for file copying?

    1. Re:It is a general purpose tool by NDPTAL85 · · Score: 1

      "- Whistleblowers and humans rights activists and oppressed people can use this to pass out information without getting shot or identified. There are parts of the world where complaining about your situation is a capital offence. Even is the "free" world, complaining about mistakes in a company can cost a job and your livelihood. (It is not "his friends" that he provides this facility for - so a large number of other people have also missed the point.)"

      If these people are breaking the laws of te nations they reside in then I have no sympathies for their needs. Spam sucks and must be stopped at all costs.

      --
      Mac OS X and Windows XP working side by side to fight back the night.
    2. Re:It is a general purpose tool by DEBEDb · · Score: 1


      If these people are breaking the laws of te nations they reside in


      When will people like you croak already?

      --

      Considered harmful.
    3. Re:It is a general purpose tool by NDPTAL85 · · Score: 1

      Why should we and not you?

      --
      Mac OS X and Windows XP working side by side to fight back the night.
  114. this is disgusting by sister_snape · · Score: 1

    You guys are having a feeding frenzy against a person who has done more for open source and online rights than many. I would think that he is at least owed enough respect to start an online dialog giving a chance for response to balance the mud-slinging. This sort of one-sided attack does not belong here and I am utterly disgusted to see it.

  115. I am sure someone else has pointed this out but... by Anonymous Coward · · Score: 0

    use SMTP auth, or pop before SMTP.

    Open relays are no longer acceptable, because it enables spammers to abuse your connection to make money.

    And everyone else has to pay for it....

  116. Rights versus competence by Anonymous Coward · · Score: 0

    I've seen various postings debating rights -- whether Gilmore has the right to demand service from Verio, whether he has the right to keep his relays open, &c. This is a red herring. It all boils down to his incompetence as an administrator. Anyone worth his salt knows that there are far easier, more expedient and more secure ways to accomplish his goal than keeping SMTP relays open. For God's sake, John! Create some frigging accounts and force your buddies to log in! Or set up VPN access!

  117. That's the irony. by Wntrmute · · Score: 2

    Gilmore, a life member of the Libertarian party, has accused Verio of censorship and said he configured the mail server to accept and forward e-mail from anyone in part so that friends could use it while traveling around the world.

    Gilmore isn't as much of a Libertarian as he thinks. After all, Verio owns the network, a good Libertarian would say that they have the right to refuse service from anyone, and that it's not censorship since they are a private entity. Sounds to me like Gilmore is trying to "coerce" Verio into providing him service. Not very Libertarian at all.

  118. Re:Not a jackass. A cypherpunk. by Anonymous Coward · · Score: 0

    The next moderator that comes through (and isn't an asshole) ought to mod this up.

    (Regardless of whether it's right or accurate, it's still "+1 Interesting")

  119. Seems like a possible terminology confusion ... by Anonymous Coward · · Score: 0
    Terminology problem ?

    Are we talking about the "third-party relay"
    and not any "open relay" ?

    see http://mail-abuse.org/rbl/relay.html for details

  120. My email to Darren Grabowski of Verio by alexburke · · Score: 4, Interesting

    To: drg@NOSPAMverio.net
    Cc: gnu@NOSPAMtoad.com, gnu@NOSPAMeff.org, nospam@NOSPAMeff.org

    Darren:

    Further to my phone call of a few minutes ago, here's a followup email of which I'm also sending copies to John Gilmore and the EFF.

    Having just learned of this whole saga (http://slashdot.org/article.pl?sid=02/03/07/16232 13&mode=nested&tid=153), here are my thoughts.

    I find Mr. Gilmore's behaviour and attitude absolutely abhorrent. He apparently thinks that he has the moral right to run an open relay, and that noone should stop him.

    Has he never heard of SMTP authentication (http://www.imc.org/rfc2554)? This would allow his mail server to accept socket connections from anyone, yet only allow his authorized users to send mail through his relay. Most modern MUAs support this.

    Now, supposedly, a virus is (or has been) using his relay to propagate. (http://securityresponse.symantec.com/avcenter/ven c/data/w32.yaha@mm.html) This in and of itself should be grounds for immediate termination of Gilmore's T1, or at least an ACL entry on your router serving his connection to block all outbound port 25 traffic, until he straightens this mess out by implementing some sort of security on his relay. I understand this is already the case. If not, perhaps it should be?

    If this were 1992, one could see how beneficial an open relay might be on the Internet. Unfortunately, this is no longer the case under any circumstances.

    Being a paying member of the EFF ([My EFF-registered email address went here]), I am sincerely disappointed that the EFF is taking such an anti-Internet stance as to support the maintenance of an open relay which has, without any doubt, been abused in the past (and will no doubt continue to be). This makes me sincerely rethink my desire to continue to be a paying member, as well as my advice to friends and relatives to make donations to the EFF in lieu of giving me gifts at the holidays.

    I find it amusing that Mr. Gilmore himself asks (http://www.toad.com/gnu/verio-censorship.html) for a copy of any correspondence regarding this matter be sent to nospam@eff.org -- how ironic.

    Thanks in advance for helping to keep the Internet free from spam and virii, Darren. Knowledgeable Internet users everywhere thank you.

    [My sig went here.]

  121. Good plan by horza · · Score: 2

    There have been a number of times when I could have done with an open relay. Times when POP was ok on an account but SMTP had problems. I think having well publicised open relays is good for the community... if we can keep bulk emails off.

    Hence restricting volume, as suggested above, is a good idea. If he isn't just too lazy to do POP before SMTP authenticate and it's a freedom of speech thing then he should hack the relay to allow 100 emails/day from one IP. That's an awful lot of speech to have free and should help those being held hostage by their email providers problems whilst stopping spam.

    Phillip.

  122. Want to install SMTP-Auth? by Havokmon · · Score: 2
    Go here for a nifty little toaster, or skip on over to www.vfemail.net, and create your own account!

    --
    "I can't give you a brain, so I'll give you a diploma" - The Great Oz (blatently stolen sig)
    1. Re:Want to install SMTP-Auth? by Anonymous Coward · · Score: 0

      Go here to deliver your spam.

  123. Nope still a jackass by NDPTAL85 · · Score: 1

    Well if he wasn't such a paranoid fuck it wouldn't be a problem. I'm well aware of Carnivore and all that crap but since I'm not breaking the fucking law I don't have much of a problem with it.

    Sometimes people have such a inflated sense of self worth that they consider themselves worthy of government attention when the government doesn't have a reason to be paying your boring ass any mind to begin with.

    Oh well to each his or her paranoid own.

    --
    Mac OS X and Windows XP working side by side to fight back the night.
    1. Re:Nope still a jackass by Anonymous Coward · · Score: 0

      "since I'm not breaking the fucking law"

      Well, one day there might be a law against using the word 'fuck' - I thought it's a bit like that already in some states?

      Even so, this 'not breaking the law' argument falls a bit short. Nevertheless there are probably lot's of things you wouldn't want everybody to know. Psychologists create all kind s of weird profiles. Who knows why you'll be rejected in your next job application? (Perhaps because the company did a web search on your name and found that you have a tendency to use fool language?) Not to mention becoming a target of custom spam.

    2. Re:Nope still a jackass by NDPTAL85 · · Score: 1

      Wouldn't I have to be using my full name instead of the nick NDPTAL85 in order for that to be a concern? Do you think I apply for jobs as NDPTAL85? And althought my full name can be found if one were to ego surf my nick the likelyhood of that happening in the real world for 99.99999999% of jobs is extremely low. Hell not even the CIA would do it.

      --
      Mac OS X and Windows XP working side by side to fight back the night.
    3. Re:Nope still a jackass by Anonymous Coward · · Score: 0

      It took me about 5 minutes to find out you:

      - are called Troy Lewis
      - own WinXP, Mac OS/X, FreeBSD and Mandrake boxen
      - chat about lesbian orgies on IRC
      - have processed 507 SETI@home units, with your last results sent on Feb 18th
      - use Earthlink as your ISP

      Then I got bored. It would be possible to get a lot more, given half an hour or so.

      I do this for everyone I hire (and I don't work for the CIA). Everyone I know who is in a position to offer jobs to techies does this as well. It's much more reliable than interviewing :-)

      HAND.

    4. Re:Nope still a jackass by NDPTAL85 · · Score: 1

      Yes I know but that doesn't go over my earlier statement as to how many employers do this. I don't even work in a techie job. How is this information being public or collected by any one agency harmful to the average citizen? You see none of what you've reported is illegal. And if I did do something illegal, I don't really have a right to hide it now do I?

      --
      Mac OS X and Windows XP working side by side to fight back the night.
  124. I've said this before by tuxlove · · Score: 3, Insightful

    I've posted numerous times here about Gilmore's open relay. Each time I think it will be the last time this silly topic arises, and each time I'm wrong. Here I am posting again.

    Many others here have reiterated the things I've been saying all along, that there's no excuse for his open relay and that there are numerous solutions he could easily employ to stop spammers from using his mail server, so I won't belabor those points.

    There is one point that still needs to be made, though. Despite his past record as champion of the Internet oppressed, John Gilmore is a danger to the rights of anyone who gets in his way, be they oppressed or oppressor. He is *filthy* rich from his days at Sun (and perhaps other things), and is apparently willing to throw his weight around with no regard for legal costs if he feels like making some sort of point. The problem is, he's a cantankerous, arrogant person with often strange views on right and wrong. There is a seeming randomness to the causes he takes on these days, and in cases like this, where the entity he opposes is clearly in the right, he does nothing but hurt the Internet community at large. Not only is his relay a spam engine, causing immediate but somewhat localized harm, his fight with Verio threatens to undermine an ISPs ability to enforce reasonable acceptable use policies. This latter point has broad implications for the entire Internet.

    I see him as a sort of "legal terrorist". His cause is on the side of a very small faction (spammers, lazy admins, and himself - though he might also fall into one of the preceding categories), he has an undue amount of firepower (vast quantities of money to pay lawyers) and has a fanatic will to use that firepower. He is known for taking on causes, sometimes without due research, simply because it offends his often skewed viewpoint. And with the EFF behind him, with its history of legal success against the toughest of opponents, most people quail when confronted with his opposition. Spammers generally do not have the werewithal or the reputation to stand against an ISP who shuts them down. Gilmore has indirectly taken on their cause, and because of the size of his guns, might actually help them in ways they could never help themselves.

    I have had dealings with Mr. Gilmore in the past, and feel obliged to say that, in my opinion, he was arrogant, uninformed and misguided. He is the quintessential kneejerk activist. He has done good things for Internet freedom, but his obtuse actions in recent history seem to say that it's time for this horse to be put out to pasture. Mr. Gilmore, I think it's time to pack your bags and move to a beach in Bermuda and enjoy your piles of money. Or perhaps feelings of guilt at being uncommonly rich are what drives you to do these things?

  125. Bernard Goetz Runs a Blacklist too by Anonymous Coward · · Score: 0

    How this got a 5 is beyond me. You make his point about outlawing cars far better than he did.

    Sendmail isn't spamware. Open relays aren't spamware. They have legitimate purposes far and above any illegal or unethical uses. It was around with open relays long before people realized they could abuse them.

    Open relays like this could be maintained better, but it isn't the operators obligation to jump through hoops, especially when he has a explicit, legitimate reason for wanting to run it that way. He isn't breaking any laws or ethics. There may be better ways to run it, but all of them remove the anonymity that he is pulling for.

    I have had this argument before, but if you remove the ability to be anonymous, you have removed free speech. YOU should read the first ammendmant, and all subsequent court rulings. If he is interested in free speech because of the anonymity of the open remailers, than more power to him.

    On the other hand, and to bring back up the analogy of cars, if a man steals my car, and uses it in the commision of a crime, I am not responsible. If I lend it to him, and he uses it to commit a crime without my knowledge, then I may be civily liable. If he uses it with my fore or aft knowldge to commit a crime (and I say nothing in terms of aft knowledge), I am criminally responsible.

  126. Shooting the messenger.... by lynx_user_abroad · · Score: 4, Insightful
    Just for a moment, suspend your instinctive outrage and listen to reason.

    The Internet used to be about openness and trust. Back before Canter & Siegel; the "Green Card Lawyers", back before the Net was opened-up for the Dot Com's and commercial postings.

    Back then, having an open relay was no big deal (it was even expected) because we were all friends working for the betterment of the Net, and each other. There was no "cut off their air" because the Internet was a cooperative; their air was our air. A network gains strength as a whole whenever any part of it is strengthened.

    That was the Internet that Gillmore grew-up on (and helped found). Perhaps you can't remember, or perhaps you were just too young to remember what it was like back then.

    That was back before the Fall of '93.

    First it was spamming shutting down USENET groups, which begot CancelMoose.

    Next we started seeing email SPAM, which begot procmail and it's necessary filters.

    Then port 25 was blocked, and peer-to-peer email was to be nevermore.

    Now we're starting to reap what we have sown.

    The Internet will soon be owned by one or maybe two large network providers (AOL/Time Warner and/or MSN) and every packet you send will travel only with their permission; through paid transport or non at all. Intelligent routers will give these network providers the ability to block (or charge for) any activity they think they can make a buck off of.

    And once there's a single majority player, it's all over. Internetworking always benefits the smaller organization more than the larger one (because it gains access to more resources in the bargain) but only benefits both sides until one gains a majority (at which point providing network access for your competitor cost more incrementally than providing the resource yourself).

    We have lost the Internet to those who would claim it as their own and carve it up over those who come in good faith and trust to build and to share.

    Think about those whom you loath the most, and what characterizes them all. We hate airline shoe bombers because they exploit the trust inherent in our air travel system to harm us where we are vulnerable. As a result, we must all remove our nail clippers when we fly.

    We hate the RIAA and the MPAA because their actions to shutdown legitimate sharing of copyright materials. Their actions are a response not to the person who wants to rip the CD for their car, but to those who abuse the trust by ripping a track and making it available to all comers over the internet. And we (most of us here, anyway) hate them because of the price we must now pay as a result. We may find ourselves losing Fair Use forever because of the actions of a few individuals who's use was anything but fair.

    We rant for columns on end about Microsoft's abuses of the market; and what we complain about is the abuse of trust we have placed with them. Then we complain about the latest Microsoft security vulnerability, and again it's about trust misplaced.

    We complain about spyware, about online privacy, about the rights we've lost, about abuses of the GPL, and in each case it's the trust we've lost, and usually about how many Karma points we're going to grant to whichever post points this out in the funniest way.

    So when Gillmore sticks his nose out and actually still trusts the community he helped to create, you shoot the messenger when you should be shooting the message.

    It's not the open relay that's harming your computer; it's the virus, and the impure pond scum who wrote it!

    You want the RIAA off your back? Give them a reason to trust you.

    You want Microsoft to change their ways? Stop paying them for the trust they've stolen from you.

    You want to keep spammers from sending UCE to you? Spread the word that spammers lie.

    And if you want a free (speech) Internet where ideas are judged by their merits, rather than by the forum where they are delivered? Speak up and be heard.

    Or don't. This Internet is already lost. Trust takes decades to build and seconds to destroy, and all of it which was once here is now gone for good.

    You want to know what built the free software community? Trust is the operating system of the free software movement. Destroy that trust and free software will not survive. That's one reason why it's so important to assign your copyrights to the FSF (so they can defend them) and to contribute to the EFF (who understand all this stuff).

    --

    The thing about things we don't know is we often don't know we don't know them.

    1. Re:Shooting the messenger.... by bungo · · Score: 1

      If I had a mod point today, I'd give you a +1 insightful.

      ... and maybe a : +1 Ah, Those were the days.

      I discovered Usenet in '86. I joined in the C&S greencard flamewars.

      I remember the never-ending September, and how it was before hand.

      I agree with almost everything you say, including :

      We have lost the Internet ...

      You are right my friend, we have lost the internet. It is too late. It was too late many years ago.

      There is no going back. It will never be the same again. The best we can do is accept what has happened and try to go forward. It this means the days of open-relays and anonymous emailers are gone. We can't being back the past, so we shouldn't keep trying to live in it. We should move forward, and do what we can to make our old values reflect in the new world (wide web:) order.

      Close all the open relays, let the traffic be controlled. Instead, be a freenet node, and set up web-based email with at least a little security. Try new ways to create the old community.

      --
      "The best part? I became an ordained minister while not wearing pants." -- CleverNickName
  127. Re:Not a jackass. A cypherpunk. by Anonymous Coward · · Score: 0
    Isn't it obvious that the reason he wants to keep his relay open is so that his cypherpunk friends can send less-traceable e-mails?
    Isn't it obvious that his motivation isn't relevant? We all know which road it is that is paved with good intentions. His open relay is a breach of contract and facilitates spam. The fact that he is either too pigheaded to recognize that or too selfish to care doesn't change the ground truth.
    the hypocrites here
    You're the only hypocrite that I see here. Spam interferes with our freedom of speech.
    Does it have unwanted side effects? Yeah. Freedom always does.
    The most basic freedoms are the right to be left alone and the right to control my own property. He is attacking both with his open relay.
    Look, let's be frank here: spammers will always find open relays in Asia.
    Wake up and smell the coffee. We are starting to see more and more servers blocking big chunks of Asia for precisely that reason. At some point in time 210.0.0.0/7 et all will have to decide whether they want to control their open relays or become intranets.
  128. All Open Relays by Anonymous Coward · · Score: 2, Informative

    One of 25. Which are
    210.242.232.25
    61.129.53.82
    205.200.155.2
    203.92.100.186
    211.21.47.218
    211.97.214.53
    200. 72.36.42
    210.101.186.3
    210.12.164.230
    202.108.1 09.222
    195.22.21.14
    61.78.199.6
    211.99.206.199
    216.244.152.250
    211.219.246.25
    211.154.129.31
    200.253.229.66
    202.102.200.103
    210.176.173.60
    1 40.174.2.1
    202.53.64.195
    202.104.108.226
    and a few non-resolveable ones.

    See http://securityresponse.symantec.com/avcenter/venc /data/w32.yaha@mm.html

    Already submitted them to ordb.

  129. Re:Not that easy - yes it is by Anonymous Coward · · Score: 0
    Gilmore does nothing wrong himself, I think.
    Even if you ignore that fact that he is violating his contract with Verio, he is still wrong. There is a legal concept known as "attractive nuisance" that covers his open realy.
    Blame the people who send spam first
    Certainly, but then blame him second.
  130. Re:Not a jackass. A cypherpunk. by kelnos · · Score: 1
    Look, let's be frank here: spammers will always find open relays in Asia. Always. China's recent baby steps forward notwithstanding, you know that this is true. This is part of the spammer's job.
    bullshit. that's like saying, "well, there will always be murderers out there no matter how hard we try, so we might as well stop punishing the ones we do find." ok, so that's a little bit dramatic. but still, that kind of attitude is why we do have spam. yes, spammers will always look for open relays. but the more that are eliminated, the harder they'll have to look, and that creates a delay in their spamming. as more and more open relays are removed from the picture, we'll have less spam.

    two thumbs down to verio for caving in.
    --
    Xfce: Lighter than some, heavier than others. Just right.
  131. What John Gilmore is. by Doktor+Memory · · Score: 3, Insightful

    John Gilmore is not just a clueless know-nothing who refuses to close his mail server out of ignorance.

    Unfortunatly, you are correct. He is not doing this out of ignorance. He is doing this out of malice.

    --

    News for Nerds. Stuff that Matters? Like hell.

  132. Siding with the ISP by Fizzlewhiff · · Score: 3, Insightful

    It looks like the majority of /.ers are siding with Verio on this one. I read Gilmore's web site and he has some interesting views on a lot of things. His opinons on SMTP blacklisting and list operators control over ISP's is a very good read. I think Gilmore makes some valid points and raises some valid concerns. For example, The current list of anti-spam restrictions is not written down anywhere that I could find; you only find out when a blacklist notice appears in your inbox, telling you that you are going to be thrown off the Internet unless you immediately change. Next week they could demand that any ISP which is also a phone company must cut off phone service to alleged spammers; the following month demand that every ISP turn over credit card and/or customer address information on demand. (Some people claim that thir "fee" for reading a spam is $50 or $500; I'm sure they would like to immediately charge somebody's credit card for it,and let the details and legalities sort themselves out later).

    One thing that is being missed is he was once the co-founder of this ISP which over time and various mergers is now Verio. When he founded his ISP their policy was to give the subscribers the ability to do what they wanted. My ISP has changed hands several times in the last three years. With each change of hands there is a new TOS agreement. What is acceptable use today might not be acceptable use by the owners of tomorrow. As it stands my service is getting cut down one port at a time. Rather than educate its customers about viruses and exploits my ISP would rather just block the ports that are exploited. In their mind as long as they provide a portal web site to thier subscribers they are providing service.

    I'm glad there are people like Gilmore who have the resources to challenge ISP's. Who else is there who stand up for the rights of the customers? Surely its not our government who passes laws like the DMCA which strips away our privacy when it comes to the internet. Today Gilmore's battle is with SMTP relays and blacklist operators. Tomorrow it might very well be the RIAA and ISP's blocking ports of known P2P clients.

    Call the guy crazy if you want but I think his fight is a good one. Its about freedom, something which is slowly dying on the internet.

    --

    'Same speed C but faster'
  133. His right by macdaddy · · Score: 3

    His right to free speech on the Internet ends at my inbox. Period.

    1. Re:His right by Anonymous Coward · · Score: 0

      > His freedom to free speech on the Internet
      > ends at my inbox. Period.
      .
      And that's where your responsibility begins. Exclamation point!

  134. The other mail relays that the virus uses: by Anonymous Coward · · Score: 1, Informative
    Excerpted from Symantec's site
    ...if it cannot connect to the email server listed in that registry key, it will use one of the following:
    • webproxy.teaorcoffee.com.tw
    • supab.stn.sh.cn
    • sitic.com.cn
    • server.benmoss.com
    • pokkant1.pokka.com.sg
    • pdc.hrserve.com.tw
    • outmail.dongfang-china.com
    • ns.sillim.hs.kr
    • ns.binter.cl
    • microimportservice.com
    • mailsvr.hanace.co.kr
    • mailserver.kaimi.com.cn
    • mail.yinda.com.cn
    • mail.win-tex.com
    • mail.pusanpaik.or.kr
    • mail.cmr.com.cn
    • mail.clinicasanborja.com.pe
    • luckybusan.com
    • linux2.ele-china.com
    • crato.urca.br
    • ahbb.net
    • ntserver1.pascon.com
    • toad.com
    • mailinx.nettlinx.com
    • www.sztge.com.cn
  135. AMEN! by overunderunderdone · · Score: 2
    This guy is dogmatic in his elevation of one freedom to the expense of all others. From his web site (note: TLG is the ISP he founded that Verio bought):
    TLG exercises no control whatsoever over the content of the information passing through TLG. You are free to communicate commercial, noncommercial, personal, questionable, obnoxious, annoying, or any other kind of information, misinformation, or disinformation through our service. You are fully responsible for the privacy of, content of, and liability for your own communications.

    That is how an ISP ought to be run. Unfortunately a set of anti-spam extortionists have been blacklisting ISPs that have policies like this, until it's very hard to find a network like this that actually connects to the rest of the Internet.

    These extortionists claim that what they want is to control their own computers. But their approach is to disconnect from any ISP that refuses to impose THEIR SET OF TERMS on the ISP's customers. This was merely an annoyance when they were 1% of the Internet. Now they are 40% or more, turning a cut-off-our-nose-to-spite-our-face policy into a "refusal to deal" antitrust issue.
    It all sounds loverly, idyllic and wonderful. But abstract rights are expressed in and sometimes have practical limits in concrete realities. Our rights, even our most fundamental rights, end up conflicting with one another. As was famously said: your right to free speech does not extend to yelling "fire" in a crowded theater. But why not? Because then it is trampling the rights of the other theater goers. This guy has a right to say whatever he likes but he has no particular right to oblige other people to provide him a soap box. Let him go out and buy his own soapbox. He started an ISP before - let him do it again. Those that freely choose to enjoy listening to all the free speech they want can sign on up. Those who just want to enjoy private conversations with their friends and co-workers can opt for services that provide some protection from Gilmore's friends interrupting all the time.

    If spam was only an occasional annoyance then I would agree with Gilmore that it is not worth "limiting free speech" to reduce. But spam has gotten to the point where it is itself a significant barrier to, if not free speech, let's say free communication.

  136. Re:Not a jackass. A cypherpunk. by #if+0 · · Score: 1



    >> Shutting it down won't curb spam or viruses, it'll just take away a privacy tool.
    So bad seed ISPs in Asia are a problem so bad that we want to block all of Asia, while an open relay closer to home is a privacy tool??

  137. Open Relays, Free Speech, and Virus Propagation by Anonymous Coward · · Score: 3, Insightful
    His defence? He wants his friends to be able to send email through his server from whereever they are.
    There are lots of ways to do that without running an open relay. I could explain his position as simple cluelessness, but given his background it seems more likely that he is just playing dumb, knows full well how to do it and has hidden agenda.
    Is it a good thing because it promotes the free flow of information?
    No. In fact, it obstructs the free flow of information, because the spam it facilitates drives users over their quotas and causes them to lose messages that they wanted to receive.
    Do the ethics change because someone writes a virus that uses the server to propagate?
    No, the ethics don't change, but the evaluation of his actions changes. The Devil is in the details, as always.

    The classic example is to ask what you think of the ethics of throwing an old woman to the ground and beating on her. I'm sure that most people would agree that it is wrong. But add the additional data that she was on fire and you were beating out the flaims, and the whole picture changes.

    Gillmore whines Any measure for stopping spam should have as its first goal "Allow and assist every non-spam message to reach its ecipients." That is bogus, as I'm sure he knows. The first goal should be to use all available ethical and legal means to impede and penalize those who spam or support spam. Gilmore's open realy is one of the legitimate targets. Gilmore can set his own goals, but for him to presume to tell us what our goals should be is chutzpah, and, IMHO, ample reason to add him to private deny lists.

    Gilmore, throughout his diatribe, ignores the first principle of the anti-spam community: It's not about content. Nobody is searching his messages for naughty words or non-PC text. Rather, they are processing whatever messages he choses to send from IP blocks that they are willing to accept traffic from.

    My ISP blocks traffic from certain addresses. Are they censoring my correspondents? No. Are they interfering with my personal liberty? No: in fact, they are enhancing it: I dropped my previous provider because they were not willing to impliment blocking, for technical rather than ideological reasons.

    1. Re:Open Relays, Free Speech, and Virus Propagation by Anonymous Coward · · Score: 0

      Gilmore didn't 'whine' or 'diatribe' anywhere in the article. You need to stop ranting, though.

    2. Re:Open Relays, Free Speech, and Virus Propagation by Anonymous Coward · · Score: 0

      "The first goal should be to use all available ethical and legal means to impede and penalize those who spam or support spam."

      .
      God, you sound like Ashcroft! Dude...it's e-mail. Get over it already and configure your stuff right, so you don't have to see it.

  138. To Be Fair by overunderunderdone · · Score: 3, Informative

    To John's credit he acknowledges this problem with spam and also proposes a solution Grokmail. It looks like it will be an email reader that will use an intelligent agent to filter your mail. But as I see it his solution fails in two ways.

    1) It is not yet a reality.
    2) it doesn't address the burden on the network of masses of unsolicited mail. His solution will actually make this much, much, WORSE. If his system works and everyone uses it. Then it makes the most sense to send your commercial email to (quite literally) everyone! Those that don't want it won't even see it (though it will have been sent to them), those that do will. Win/win for everyone right? You don't see unwanted spam though occasionally you will get an unsolicited commercial email that actually interests you (hey, it could happen). The spammer gets his message in front of every single interested potential customer in the whole freakin' world! Yay!! But behind the scenes the network is transmitting EVERY SINGLE commercial message to EVERY SINGLE user. Masses of useless data that will never even be seen - probably many orders of magnitude a greater volume of data than that which is actually going to be seen and used. Perhaps technology will make this a viable system (seems outrageously inefficient though)

  139. Did anyone notice the verison number ? by ccandreva · · Score: 3, Informative

    Connected to 140.174.2.1.
    Escape character is '^]'.
    220 toad.com ESMTP Sendmail 8.7.5/8.7.3; Thu, 7 Mar 2002 14:40:04 -0800 (PST)

    Sendmail 8.7.5 ? Forget open relay -- unless he's been patching this by hand,he's going to be rooted any minute !

    http://www.netcraft.com/presentations/interop/se nd mail.html

  140. Tell Verio what you think by howardjeremy · · Score: 1

    On his web-site Mr Gilmore suggests contacting his provider (Verio) to let them know what you think. Sounds like a splendid idea to me. Here's the message that I sent (I don't believe in republishing other people's addresses, so I've anonymised them. The correct addresses are available from the toad.com URL linked below):
    ----

    From: "Jeremy Howard" INVALID@fastmail.fm.INVALID
    To: "Darren Grabowski" INVALID@verio.net.INVALID
    Cc: "John Gilmore" INVALID@toad.com.INVALID,
    "NOC Security" INVALID@noc.verio.net.INVALID,
    " Vantive Updates" INVALID@vanwebserv.verio.net.INVALID
    Subject: Comments on open relay at toad.com

    Dear Darren,

    John Gilmore suggests that people should contact you regarding the treatment of his open relay at toad.com:
    http://www.toad.com/gnu/verio-censorship.html

    I am a director of FastMail.FM, a popular email provider. I would like to applaud you for trying to help rid the Internet of open relays. We have
    recently completed an analysis that suggested that for each 10,000 messages that arrives at our system from open relays, only one (on average) is valid email, while the remainder are unsolicated commercial email (UCE, or 'spam').

    There is no valid reason to run an open relay SMTP server. There are many effective authentication mechanisms. For instance, at FastMail.FM we use SMTP AUTH, which our users have found to be a convenient and robust method for authenticating with our SMTP server. We also provide a web interface for sending email, which allows users without access to a client supporting SMTP AUTH (although most do) to compose messages, format text, spell check, maintain an address book, and so forth.

    We block all messages from open relays, and we scan frequently used sending IP addresses for open relays automatically and send positive results to some DNSBLs such as ORDB.org. We would encourage you to do the same.

    We have a very active user community that receives over a thousand posts a month by enthusiastic users. Every time open relay blocking has been discussed here by our users it has been overwhelmingly supported, as has the support of DNSBLs that list open relays.

    We encourage you to maintain your stance on closing open relays. Furthermore, I hope that Verio will consider taking a more pro-active stance against "spammers" in the future--there are still numerous known spammers operating through Verio's network despite repeated emails to your abuse desk informing of the problem.

    Thanks for you time,
    Jeremy Howard
    Director
    FastMail.FM

  141. Keep the Internet FREE by plunix · · Score: 1
    First of all, I share the hatred of spam common among most who post here, and most internet users in general. But I have this to say to those who advocate government or ISP control of content:

    What the hell is wrong with you people? If you have a problem with receiving spam, fucking deal with it yourself. It's YOUR responsibility to read the mail you want and discard the mail you don't, not some ISP or government agency's. Do any of you even realize that all you are doing is contributing to the limitation of your own freedom, ability to use the internet the way you want, and privacy when using it?

    Government regulation is certainly not the answer, nor is it legal (for the US government at least, read the Constitution)

    Neither is ISP blacklisting or filtering a suitable solution. It denies the user (ie. the person who has the receiving email account) the ability to decide for himself what he wants to receive on the internet. An ISP should provide access to the internet - nothing more, nothing less. It's the user's responsibility to pay attention to what he wants and ignore or filter what he doesn't.

    -

    Also read http://www.toad.com/grokmail/antispam.html

    We should all be supporting Gilmore for his firm commitment to a free internet, not denouncing him.

    1. Re:Keep the Internet FREE by Anonymous Coward · · Score: 0

      Amen, brother!

  142. Gilmore's Anti-spam Cruisade by Anonymous Coward · · Score: 0

    Doesn't anyone else find the irony in allowing open realy's yet at the same time advocating anti-spam software?

    http://www.toad.com/grokmail/antispam.html

    Come on bud! You can't have your cake and eat it too!

    1. Re:Gilmore's Anti-spam Cruisade by plunix · · Score: 1

      Did you even read the page you referred to? There's nothing "ironic" about it. The simple fact is that Gilmore does not support spam. He supports the freedom of the internet. Given this, it is not surprising that he supports legitimite spam protection that each user can decide and control for himself.

  143. Hypocrisy? by crucini · · Score: 2
    The general population of Slashdot has very different views of P2P (go after the user!) vs open relays (shut it down!) even though at its heart they are the same issue.

    Maybe you are making the common mistake of assuming that the same people are involved in both arguments. Anyhow, I think the "go after the user" argument is idiotic. If you really think that copying music is wrong, then Napster, Gnutella, et al. are wrong and should be punished much more severely because they are industrial strength infringers. The attempt to ascribe non-infringing uses to these tools is utterly dishonest. We use them to transfer material that cannot safely be published on the web. So my position is:
    1. Spam is wrong. Therefore spam support is wrong.
    2. Copying music is not wrong. Intellectual property is a legal fiction. Therefore supporting the copying of music is not wrong.

    All the people crying "go after the users" will be very unhappy if this is actually done.
    1. Re:Hypocrisy? by King+of+the+World · · Score: 0

      Er, I use Gnutella because it's easier than setting up a damn server just to share files. I do not break the law.

  144. Re:Gilmore is right, MAPS, SBL, and Spews are wron by Anonymous Coward · · Score: 0

    Actually, some of us feel that the solution is to do away with anonymnity in the email domain. A weblog like this site can provide an anonymous forum if it so chooses, but what's the point in allowning anonymous email? Mail should be authenticated at all relay points on the way from source to destination. That will get rid of spam, and it won't interfere with communications.

    There are hypothetical instances where this would be a problem. But there are hypothetical instances where anything can be a problem.

  145. Virus' bad, but restriction worse by dh003i · · Score: 2

    Look, whenver virus' or spam get propogated, its bad. No question about that. But that doesn't mean that the law should restrain ISP's or individuals with routing services. Remember the lesson Lawrence Lessig taught us -- the intelligence in a network should be at its ends (e2e) not within it. Networks where intelligence is within the network are static and can't evolve or adapt to new changes. This doesn't mean that ISP's shouldn't be allowed to filter out SPAM, use blacklists, filter virus', etc (so long as they're not filtering out things just b/c they don't agree w/ them). Indeed, the internet would be even slower if ISP's let every spam request go through. But ISP's shouldn't be forced to abide by certain standards. After all, we, the END user, have the ability to filter out that crap, and not even download it based on the header.

    As for virus' propogation, its not the fault of an ISP or a router. Virus' only propogate becase people are stupid enough that they don't use virus checkers and that they open up obviously questionable "executables" or otherwise dangerous files. As a simple rule, any thing you get which isn't from someone you know, or isn't something you requested, is probably a virus, spam, hate-mail, political hogwash, some stupid chain letter which you really don't find interesting, or a combination of the above.

    Lets not blame ISP's and because the "ends" are ****ing dumb sometimes.

    That's like blaming Ford because they didn't include precautions in their car to prevent someone from crashing into a wall.

  146. Everyone is WRONG (or... why no happy medium?) by namespan · · Score: 2

    Actually, I think everyone's wrong. Why does the only choice have to be totally open relays or blacklisted/blocked off?

    One wonders why you couldn't have an SMTP server with some anti-spam restrictions like:

    1) will only deliver to a limited number of recipients -- say 1-5

    2) will not accept more than 1 message every 5 minutes from any given IP ("Slow Down, cowboy!")

    3) uses some kind of authentication that changes in a way easy for humans to pick up on, hard for machines

    ... something like that. It doesn't seem to me that any of these would be too hard, given a couple of free afternoons and Net::SMTP from CPAN.
    OK, I don't have anything specific in mind for #3, but 1-2 aren't rocket science and would make spamming hard.

    --
    Libertarianism is rich wolves and poor sheep playing gambler's ruin for dinner.
  147. Re:Not a jackass. A cypherpunk. by maxpublic · · Score: 2

    Hey, and I have the freedom to blacklist his sorry ass for having the open mail relay in the first place. After all, your entire argument is predicated on freedom, and that cuts both ways, Tonto.

    Max

    --
    My god carries a hammer. Your god died nailed to a tree. Any questions?
  148. basic authentication by coyote-san · · Score: 3, Informative

    Or perhaps a bit more to the point, he could set up authentication for his friends. That's like making duplicate keys for your friends (where you are authorized to do so - not a "janitor" situation) while still keeping strangers out.

    This won't give 100% accessibility, but it's a reasonable compromise. If he wants 100% accessibility, he should set up a web mail server interface, again with some form of authentication.

    --
    For every complex problem there is an answer that is clear, simple, and wrong. -- H L Mencken
  149. Re:The worst victims of open relays are its operat by mxs · · Score: 1

    Hrrm .. While this is a nice story, your advice should be taken with a grain of salt.

    A company that has a reasonably big pipe to the net and does not notice the simplest of errors until it really hurts (monetarily speaking) will have a lot of problems, anyway.

    Seriously, an open Proxy ? And nobody noticed ? An open ftp server with no quotas ? And nobody noticed ? A filled pipe ? And nobody noticed ? If you ask me, that just speaks of /very/ bad sysadmining. There are very simple tools to check for this kind of thing, and there are very pretty graphs to be drawn for traffic. Just make a habit of it to look at it every now and then. I know I do, and I know I stopped quite somee **** from coming down on our network. It's really not that much work, and it's really not worth 6000 Euros. Ever.

    I have to shudder when thinking of how bad security will have to be if even such basic "exploits" worked so well for so long in your company ...

    That said, yes, an open relay will cause you headaches. But I'm guessing Mr. Gilmore knows that. I don't respect him for this decision, though I do have respect for the man.

    ttyl,
    mxs

  150. Re:Not a jackass. A cypherpunk. by Anonymous Coward · · Score: 0
    Isn't it obvious that the reason he wants to keep his relay open is so that his cypherpunk friends can send less-traceable e-mails? A noble goal, even though it has unfortunate side-effects regarding spam and this new virus.

    Their rights end where mine begin. When his open relay can be used to spam the shit out of my servers, my mailboxes and generally trample over my rights, he is just plain shit out of luck.

  151. The new Slashdot Twitch by phred · · Score: 2

    We could call it the Slashdot Twitch. That's when your knee starts jerking because you won't bother to look into the facts and context of a story before you leap to conclusions.

    If those of you afflicted with the Slashdot Twitch at the moment actually read what John Gilmore has said about this episode all along, perhaps you will be able to alleviate your symptoms before they make you look foolish.
    Especially those of you who shot your mouths off, called him names and blackholed toad.com without a second thought.

    The point John was making all along, for those too lazy to actually read what he wrote, is that braindead ISP policies that are designed to address issues in a technically deficient but corporately convenient way, that get in the way of people who know what they are doing, are irrational and to be resisted.

    I've known John for a long time and I have my (friendly) disagreements with him -- "please would you support getting FreeS/WAN going on FreeBSD" was my last one he didn't go for :) -- but really, John has done a terrific amount for the net and for our inherent right as human folks to communicate. And THAT is what the whole tussle with the Verio middle managers is all about.

    --------------

    --
    Bill Gates Is My Evil Twin.
  152. Hrm. by autopr0n · · Score: 2

    A few simple rules would prevent this, like only allowing mail with a FROM: feild of a user or something, or as others do with allowing SMTP relaying after you've logged on with POP or IMAP.

    Sure, his friends might be able to send mail from anywhere, but will they be able to send mail to anyone once his box gets blacklisted?

    --
    autopr0n is like, down and stuff.
  153. It's a bit more complicated by autopr0n · · Score: 2

    A lot of you have been saying that Gilmore is just a customer of Vero and has to abide by their service agrements. That might not be the case. According to his website: The Little Garden (with John Romkey, David Henkel-Wallace, and Steve Crocker) A medium-sized Internet Service Provider in the San Francisco Bay Area. now merged into Verio. We mostly sold T1 and 56K Internet connections to businesses. We were distinguished from many other early commercial providers by our common-carrier attitude: "You are free to resell the service that we provide to you, and we will not censor it." This enabled a whole crop of smaller resellers in various locales to buy from us and offer other services to the public (like modem-based Internet connections).

    So it isn't that Gilmore is "just a customer" but rather Gilmore started a company and vero merged with it. This would imply he had a bit more sway in the way things are operated.

    --
    autopr0n is like, down and stuff.
  154. They need to shut this guy down... by Eric+Damron · · Score: 1

    I don't like getting 100 pieces of spam per day telling me that they can increase the size of my penis by six inches...

    I mean, how much bigger can it get? ;-)

    --
    The race isn't always to the swift... but that's the way to bet!
  155. EFF Members by augustz · · Score: 2

    I was an eff member, but no more. You're money is going to pay for idiots like this. It's been said before, but this is not censorship, and casting it as such is damaging to folks truly fighting for free speech.

    Cancel those memberships.

    John Gilmore has every right to run an open mail relay.

    Verio has every right not to sell Internet service to people who want to use it to run open mail relays.

    John Gilmore has no right to demand Internet service form Verio.

  156. Re:Not a jackass. A cypherpunk. by cluge · · Score: 2

    >Isn't it obvious that the reason he wants to
    >keep his relay open is so that his cypherpunk
    >friends can send less-traceable e-mails? A noble >goal, even though it has unfortunate side->effects regarding spam and this new virus.

    How is this relay sending less traceable e-mails? Has Gilmore re-written it so that the header information is always incorrect? Why can't his "cypherpunk" friends send their own untraceable e-mails by simply bounceing off one of the many open proxy servers? Why don't the spoof an IP to send an e-mail? Why don't they use an e-mail server in China? Why don't they use strong encryption like Gnupg so it doesn't matter if they are sniffed?

    Gilmore is full of the brown stinky stuff, and your argument smells the same. Oh yeah, and it doesn't hold any water either. Come on, an open relay is a "privacy tool"? Please..... Your "layer of obfuscation" is nothing more than a layer of manure that has nothing to do with the "privacy consiousness" of anyone.

    --
    "Science is about ego as much as it is about discovery and truth " - I said it, so sue me.
  157. John Gilmore, you lame *uck by Anonymous Coward · · Score: 0

    You're as bad as those you move against. Run for office man, you'll win.

  158. Gilmore's a bad guy but not gnu.org? by Anonymous Coward · · Score: 0

    There's a subtle irony to the fact that Gilmore's argument is the same as gnu.org applies to their mailing lists (http://www.gnu.org/prep/mailinglists.html#Spam) and yet the same condemnatory posters can't stop falling over themselves preaching the perfection of all things gnu.

  159. MOD THIS DOWN by Anonymous Coward · · Score: 0

    Someone please mod this dumbass down to -1.

  160. It *IS* bad for promoting the free flow of spam. by Anonymous Coward · · Score: 0

    It *IS* bad for promoting the free flow of spam. It's extraordinary that the question's even being asked here on /.

    I get anywhere up to 15 spams a day. Anything that increases that load is a Bad Thing in my book. Open relays are a Bad Thing. The netizen who runs one is doing the RL equivalent of shitting in the street, or perhaps a better description would be he's providing a toilet in the middle of the street for others to shit in.

  161. It's not about SPAM, it's about Anonymous Relay by charmer7 · · Score: 1

    Folks arguing about spamming are missing the point. John does think spam is a free speech issue, and was allowing spam to be relayed through his server. But that has not been the case for at least several months. John reconfigured his email server six months ago to make it almost useless to spammers. Yes, that was a result of threats from Verio, and yes, you can forward a small amount of email (anonymously), but you can't relay large amounts. That doesn't stop the server from being useful to lots of virus-infested hosts to forwrad small amounts of email (each). But I think you should think about whether that has any significant impact on the ability of this virus to propagate. Look for another follow-up on the impact this has on me.

  162. Happy Now? Name Service for Eritrea Jepordized by charmer7 · · Score: 1

    Verio yanked John's internet connectivity about 11 am this morning, with 3 hours warning.

    Unfortunately, that means they yanked my internet connectivity as well, because we share a T-1 connection. And that means that name service for the country of Eritrea is on shakier ground.

    Had they given me more warning, I would have been able to arrange for alternate connectivity. As it is, it's going to be a rough couple of weeks.

    Look it up if you want:

    whois -h whois.networksolutions.com =er

    I'm at 140.174.131.100; packets to which now stop at John's subnet.

    There was nothing exigent about the alleged virus propagation that required this kind of response. I think Verio was just using this as an excuse to get John because they're pissed at him after trading legal threats about his relaying spam. (See my other posting if you want to argue about spam relay versus anonymous email; as of now John's computer is pretty much useless for the relay of spam.)

  163. Re:Happy Now? Name Service for Eritrea Jepordized by charmer7 · · Score: 1

    doh! i meant that before they yanked his connectivity his computer was pretty much useless for the relay of spam. but see my other article to discuss that.