Slashdot Mirror


The Story of "Nadine"

Guinnessy writes: "We've all accidentally typed in a wrong email address sooner or later. But can it all go horribly wrong? On http://www.spamresource.com there is the story of Nadine, an account of what happened after an Internet user accidentally gave a wrong email address when she visited a web page and signed up for a sweepstakes. Live in fear...."

84 of 270 comments (clear)

  1. Old News by netfox39 · · Score: 3, Informative

    http://www.honet.com/nadine/

    1. Re:Old News by gambit3 · · Score: 4, Funny

      yeah, but at least it was the SAME Old news that it was yesterday!

  2. I've read this before (spoilers) by Telastyn · · Score: 4, Funny

    Apparently the story is about a slashdotted webserver...

  3. nice job! by flynt · · Score: 5, Funny

    We've all accidentally typed in a wrong email address sooner or later.

    Classic Slashdot grammar!

  4. Typoing your email address can be a drag by PEN15 · · Score: 5, Interesting

    Several years ago, I made a typo in my email address when I was updating the contact info for a domain name. Without double-checking I sent the confirmation back to InterNIC. It wasn't till the next day that I realized the mistake. In order to get things back under control, I actually had to register the typoed version of my domain name, so that I could receive InterNIC's mail there.

    It's the kind of expensive mistake you only make once! :)

    I kept the typo'd domain for esoteric value, and yes, I now get plenty of spam there. Some things never change.

    1. Re:Typoing your email address can be a drag by brer_rabbit · · Score: 3, Funny

      kind of like mistyping a stock ticker? Buying 100 shares of SUN versus SUNW can be pretty pricey (and no, I wouldn't know anything about such an incident. I'll deny it all).

    2. Re:Typoing your email address can be a drag by mshomphe · · Score: 5, Funny

      Dragging this offtopic, a good friend of mine was told to invest in Cisco Systems a few years ago. But he just heard the name and, being a non-techie, bought a bunch of shares in Sysco, the food services company.

      Cisco went down, Sysco went up. Talk about pulling a Homer....

      --
      She sat at the window watching the evening invade the avenue.
    3. Re:Typoing your email address can be a drag by anthony_dipierro · · Score: 2

      Several years ago, I made a typo in my email address when I was updating the contact info for a domain name.

      Good thing this law hadn't passed yet, or you might be in jail!

    4. Re:Typoing your email address can be a drag by Guppy · · Score: 2

      "kind of like mistyping a stock ticker? Buying 100 shares of SUN versus SUNW can be pretty pricey (and no, I wouldn't know anything about such an incident. I'll deny it all)."

      Depressed prices for heating oil and jet fuel have hit SUN pretty hard, but if gasoline prices rise sharply this summer (which many analysts are expecting), Sunoco could hit $45 or so within the next few months. Plus, they pay 0.25/share in dividends per quarter. Not a bad stock to be in, IMHO.

      Disclosure: Long SUN.

    5. Re:Typoing your email address can be a drag by DrSkwid · · Score: 2

      lol my dad did that too when I gave him an insider tip

      my colleague watched his £3000 turn to dust as the company went bust and my dad made a few quid when he bought the "wrong" stock!

      The company had gambled their future by planning to finance a deal with the stock rise they would get when they announced the deal to the markets. Unfortunately the price went down instead and about a week later we were all out of a job!

      --
      There are places where the networks are not touching,and there are places where they are-Boeing's Lori Gunter
  5. All your base... by Debillitatus · · Score: 5, Funny
    We've all accidentally typed in a wrong email address sooner or later.

    What you say?!?

    --

    Come on, give it up, that's

    1. Re:All your base... by JimPooley · · Score: 2

      Don't misunderestimate him...

      --

      "Information wants to be paid"
  6. Prevention measures by yoyoyo · · Score: 5, Interesting
    This sort of thing could be avoided if companies used confirmed opt-in. That is, when you enter your email address they send an email address to that account with a unique url in it. They only email you their newsletters if you you click the link.

    That also prevents your email address from being maliciously signed up to these sorts of lists, so it's the sort of thing every reputable mailing list should do.

    Of course, no spammer is going to bother with confirmed opt-in, so we need to go after ISPs that allow these non-confirmed lists to remain on their net-space.

    --

    --

    --
    I have taken more out of alcohol than alcohol has taken out of me - Churchill
    1. Re:Prevention measures by Wolfier · · Score: 2

      How about - if you enter your address they send you an HTML email with an embedded web bug that automatically gets a link with an ID?

      You don't even have to click any link...just opening the email is enough.

      Of course I block my email client from getting external images... ;)

    2. Re:Prevention measures by DrXym · · Score: 2
      That might stop the crap going to wrong address in the first place, but the story demonstrates that even if you did voluntarily opt-in, you'd find it very hard to opt out.


      Besides, if I wanted to get someone spammed I would just stick their email addresses in a few usenet posts, webpages etc. and it would soon get noticed.

    3. Re:Prevention measures by Dwonis · · Score: 3, Informative

      The whole idea of confirmed opt-in isn't to confirm *if* there is an address on the other end, but to confirm that the recipient is really the one who signed up. The "web bug" you propose doesn't address that problem.

  7. /. server part 1 by reflexreaction · · Score: 2, Informative

    Nadine -- The Story Begins Once upon a time, there was a senior citizen in one of the Southeastern United States who was apparently confused about what her email address was. Because I have no desire to cause this lady the slightest inconvenience, I will call her "Nadine", which is not her real name. I'm also going to change her surname to "Smith", which is likewise false. (NOTE: Because I have no desire to avoid inconveniencing any of the other players in this tale, hers is the only identity that has been altered in any way.) On or about the second day of March in the year 2000, Nadine visited a web site belonging to an outfit called delivere.com. While there she apparently entered a sweepstakes, gave delivere.com some personal information and (I presume) agreed to receive email advertisements from various parties from time to time. The email address she gave them consisted of her first name and the domain honet.com. What the actual email address should have been is something about which I can only speculate. To confirm (to Nadine) that she had signed up, delivere.com sent a message to nadine@honet.com. (This was the First Big Mistake: the message should have asked the real owner of "nadine@honet.com" to confirm that the sign-up was genuine.) A semi-automated process at honet.com noticed the message and sent a "No such user" message to the appropriate addresses (at least one of which was bogus). Normally, that is all it takes to stop any further traffic. Such was not to be the case here, however.

    --

    We had to destroy the sig to save the sig.
  8. Idea!!! Lets get revenge! by jeanluisdesjardins · · Score: 3, Funny

    Lets start slashdoting spammers!

  9. Both sites choked - Google to the rescue by Seth+Finkelstein · · Score: 5, Informative
    Bandwidth-choked.

    Read it off the Google cache

    (Note to people accusing me of karma-whoring: The search formatting above is non-obvious)

    Sig: What Happened To The Censorware Project (censorware.org)

    1. Re:Both sites choked - Google to the rescue by jafuser · · Score: 5, Informative
      I happened to catch this article just as it came up on Slashdot so I managed to get most of the pages before they disappeared.

      Mirror

      --
      Please consider making an automatic monthly recurring donation to the EFF
  10. Why not fix it the old-fashioned way? by WebCowboy · · Score: 3, Informative

    A bit OT but...

    If you made a mistake in your contact info, you could've rectified the problem by voice phone and fax. That's what I did when the contact info for a domain I registered had to be updated because the email was an expired domain for a now-defunct company. Network Solutions had surprisingly good customer service and once they verify the credentials via fax (or even snail-mail) they will make any changed required without the use of email.

    That way seems low-tech and backwards, but you don't need to register an otherwise useless domain and it costs nothing more than your time (certainly mot much more than the trouble of registering a domain and setting up the DNS).

    Us techie types should be careful not to overlook the most simple solution because it is low tech...

    OTOH, the useless domain could be useful to keep track of how many OTHER people make that typo...kinda like the Slashdor site...

  11. I hate spam, but ... by smoondog · · Score: 5, Insightful

    Perhaps I'm confused (or maybe it is because I got bored and only read 10 of the many links on that page), BUT, I don't find the story of Nadine all that unique or interesting. I get piles of spam everyday and I haven't opted-in to anything. My most spammed address gets over 100 messages a day.

    In my experience, trying to follow up or research these spammers is generally a useless waste of time. Bounce them, sue them or further change the law. Doing more is just going to frustrate yourself, IMO. Remember when you call around and get put on hold and follow the paper/isp trail you are wasting a lot more of your time than theirs.

    -Sean

    1. Re:I hate spam, but ... by Mr.Intel · · Score: 4, Informative
      I don't find the story of Nadine all that unique or interesting. I get piles of spam everyday and I haven't opted-in to anything. My most spammed address gets over 100 messages a day.

      Perhaps the story itself is not so unique, but I find his analysis very important to understand.

      From the essay:

      "Subject only to the agreements and contracts that an Internet entity has with its providers and customers, that entity is absolutely sovereign within its own domain. Service providers and system administrators are completely free to decide to accept or reject any network traffic they choose; they simply must accept whatever reactions such decisions may evoke from those with whom they have agreements.

      An individual consumer's service providers have absolutely no economic incentive to provide transit and storage for advertising, especially advertising delivered by email. On the contrary, many providers have discovered that swift remedial reaction to consumer complaints about unwanted communications can both increase customer loyalty and decrease operating costs. As a result, the unwritten "I will carry your traffic if you will carry mine" agreement is subject to re-evaluation, with the possible conclusion "I don't care whether you carry my traffic or not, so I won't carry yours." And there are many ways to say "I Won't".

      He states that this goes against the very flow of information that transpires in other forms of media. I find it fascinating that people expect to have a captive audience on the Internet because they did on TV, radio and magazines. Frankly, this is a new world and it isn't governed by the same rules.

      --
      ASCII tastes bad dude.
      Binary it is then.
    2. Re:I hate spam, but ... by qrys · · Score: 3, Informative

      I think I am under that same impression as you are. Someone's getting a lot of spam? Who cares. I get tons of spam. My hotmail account (as listed above) gets at least 20 spams a day probably more- but that's why I still have it around. (Although my main e-mail still gets some spam).

      Are there people out there that really care?

      I thought there was supposed to be something gone terribly wrong in this article (like someone killed as a result of spammers)...

      Much ado about butt-kiss..

    3. Re:I hate spam, but ... by Eggplant62 · · Score: 3, Informative

      For you newbie spam fighters out there, here a few links:

      http://www.samspade.org
      http://www.spamhaus.org /rokso/index.lasso
      http://www.spamcop.net
      http:/ /www.spamfaq.net/spamfighting.shtml

      There's no reason to get upset or frustrated when looking for spammers. Rule 3 says they're stupid so they're usually rather easy to trace down, if you know what you're doing. Once you've taken the time to educate yourself on how to read email headers, trace through them to find the originating ISP, open relays/proxies that forwarded the email, and decode the spamvertised URL, rooting out any redirection services or encryption used to obfuscate the spammers actual website (read cash generator), it's like anything else and can become second nature. It only took me about six months to get a good handle on all of the above and then another year to refine it to a science. I'm currently administering my own Linux mail server. I'm also pulling mail out of two POP accounts, one of which gets the majority of my spam, the other which has never been published anywhere and hasn't received spam... YET. I'm using a combination of DNS-based blocklists on postfix, iptables and a procmail filter to keep my spamload down to about 1-2 messages a day.

      The only thing I can say is use the above links and get familiar with the process. Read news.admin.net-abuse.email and ask questions of the inhabitants on how to fight spam. Make certain you stock up on Nomex underwear as it can be a pretty rough group to follow. A speed reading course may be helpful to keep up with the flow of articles.

      Hope this help....

      Rich
      --
      Consumer Watchdog! Yes, we're rough on bogus businesses! And today,
      Consumer Watchdog reports on protecting you, the consumer, from being
      consumed by dangerous products and phony packaging. -- Firesign Theatre
      TINLC Unit #2309 Death to all spammer accounts.

    4. Re:I hate spam, but ... by mcc · · Score: 3, Insightful

      This is important *because* it is so common.

      It is a good general view of something that happens every day, all over. It is a good forensic analysis of what can happen from just *one instance* of submitting an e-mail address to a single sweepstakes site.

      It may not have helped most of the people on slashdot right now to have read this, but i think this is a good, well-written article to give to someone who doesn't read slashdot, doesn't know any sysadmins, doesn't have to deal with spam, doesn't incessantly read web message board posts by sysadmins who have to deal with spam, and doesn't know the extent to which this stuff goes on.

      More importantly, it is a good article to show businesses who are considering using spam to advertise.

      If you read all the way through the nadine chronicles (a good part of the middle could probably stand to have a "you can just skip this part" disclaimer, really..), the end is actually targeted directly at businesses considering advertising with spam, telling them why they should not and why their money will most likely be wasted if they give it to a bulk-email-advertising firm.

      Just because you and i know (or think we know) everything there is to know about spam doesn't mean that everyone in the entire world does. And this is one of these issues where the people who are most important to reach are the ones who are currently uninformed..

    5. Re:I hate spam, but ... by HiThere · · Score: 2

      20 isn't a lot. I probably don't get 20 an hour, but ...

      Of course, it's partly a matter of how long you have your e-mail address, and how well you secure it and keep it hidden. I don't really go in for that, and I'm also on a lot of mailing lists. I suppose that at some point I'll switch email addresses, and drop most of the accumulated links. But I see spam more as a reason to use a non-html mail program (like kmail) than as a reason to really get upset about things. I may eventually even construct a bot, and use spam to train it. (That might make for some amusing exchanges. I wonder if spammers harvest the cc lists? I could get them talking to each other. :-) )

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
    6. Re:I hate spam, but ... by anthony_dipierro · · Score: 2

      Of course, it's partly a matter of how long you have your e-mail address, and how well you secure it and keep it hidden.

      Not on hotmail. I've set up email addresses on hotmail such as "sdjkleiojsel" and never used them for anything. Within a week I am receiving spam. The addresses are leaking out somehow.

    7. Re:I hate spam, but ... by Dyolf+Knip · · Score: 2
      Not on hotmail. I've set up email addresses on hotmail such as "sdjkleiojsel" and never used them for anything. Within a week I am receiving spam. The addresses are leaking out somehow.

      There was actually an experiment done along these lines. 12 email addresses started with various providers. Some left untouched, some used exactly once with things like message boards, registering a domain, using an AOL chatroom, that kind of thing. Interesting results.

      I also seem to recall an article about someone who designed a webpage with a mailto: on it such that every person who visited it saw a different email address. I can't remember where I saw it or what the results were, though. :(

      --
      Dyolf Knip
    8. Re:I hate spam, but ... by Yottabyte84 · · Score: 2

      It's actualy been down for nearly 2 weeks, I'm starting to miss it. :(

  12. Tip by slugo3 · · Score: 2, Informative

    Sign up for a Yahoo email address and use that address when signing up for anyting. Dont most people do this? I know i do and it keeps my real address relitivly clean where my "sign up" address gets hundreds of emails a week.

  13. Re: The point of the Nadine story by gorbachev · · Score: 5, Insightful

    The real point of the Nadine story is demonstrating how spammers are reselling and distributing spam lists.

    Some of the spammers hitting Nadine's Email address are trying to act as responsible members of the bulk emailing industry, while at the same time blatantly violating online privacy policies (their own, and their list suppliers') left and right.

    The point of the story is to point out how effective "industry self regulation" really is.

    Proletariat of the world, unite to kill spammers

    --
    In Soviet Russia, I ruled you
  14. Re:I'm no email antispam guru... by Caradoc · · Score: 2, Informative

    You mean, like SPEWS? http://www.spews.org

    I am not SPEWS.

    --
    Specialization is for insects. - R.A.H.
  15. Re:Now what about spam-terror? by reaper20 · · Score: 5, Informative

    It's not perfect, but Spamassassin is pretty damn close.

  16. Spamcop by dankinit · · Score: 2, Interesting

    I'm using spamcop.net and it's cut down on my spam by about 85%. Cost is $30/year for having your email filtered. Some spam (15%) still gets through but you can submit that to them to ensure others don't get the same spam as well.

    (I have no affiliation with spamcop.net except as a satisfied customer.)

  17. Are you sure? by Sc00ter · · Score: 2
    That these spammers are sharing e-mail address.. or could Nadine be using the same bogus email all over the internet? I know I do. I go to a site that requires my e-mail address for nothing more then spamming purposes (like to dl some software, Acrobat for example) and I type in a bogus email address.. And I usually use the same one. It seems logical to me that Nadine could be doing the same thing.. And this poor guy owns the domain that she picked.

    Sure, some of it could be from spammers sharing addresses and lists, but some of it might not be.

    1. Re:Are you sure? by J.J. · · Score: 2

      I don't use bogus addresses, just the work addresses of the guys I went to college with.

      And they wonder why the spammers seem to keep finding them every time they switch jobs...

  18. This = Great way to kill off a hotmail account ... by indiigo · · Score: 3, Funny

    I purposely have done this.

    See, I signed up for a hotmail in it's early stages ('97). I used it for everything, including online purchasing, friends, family, you name it. At some point something happened-- one of the forms I filled out, or someone sold my same, and I started to get mail addressed to my real name, at that address. This semi-scared me.

    So recently I went to cancel the account. Hotmail by default will consider your account "cancelled" after inactivity of 90 days. I cannot click something that says "Forever, never use this e-mail" My fear is that others will get this e-mail after I have cancelled it, and they will see my real name.

    The best solution I have come up with is to fight fire-with-fire. I now sign up for every mailing list I can, each with a different real name. I now belong to over 400 mailing lists(including /.), some legit commercial businesses, some obvious spam. The mailbox fills up roughly every 30 hours. I plan to continue this for a few months, until it will be impossible to distinguish my real name from the fake names. Whomever picks up the account next will be in for a treat as they open their account and start getting thousands of messages a day, random names, and all.

    It's so sad it's come to this.

    --
    fslg503-985-8686503-985-8686503-985-8686503-985-86 8650 3-985-fdsg8686503-985-8686503-985-8686503-9
  19. I get 10,000 spams a day! by newerbob · · Score: 2
    Sounds hard to beleive, but it's true!

    I have a domain that's ONE LETTER OFF from Yahoo. (Well, it has one extra letter).

    Very often, wise-asses mutate their email addresses when posting to USENET with this additional letter, thinking they've stopped their spam. They haven't. *I* get it.

    Of course, I don't see 99% of it--it's thrown in the bit bucket. However it is disturbing how much I get. Not only from email address grazers on USENET, but from people who use fake email address--often in my near-miss domain, and sites that gladly add it to their mailing list without a confirming email. Some of these are otherwise "reputable" companies, too. (This is so they can claim they have 4 billion registered users--easy to do if you don't verify!)

    --

    --
    Ask the Ya-Hoot Oracle Anything!
    1. Re:I get 10,000 spams a day! by Bryan+Andersen · · Score: 2
      I have a domain that's ONE LETTER OFF from Yahoo. (Well, it has one extra letter).

      Strip the letter and forward it... May not be the wisest thing to do, but what the heck.

  20. Misdirected spam, etc by crawdaddy · · Score: 2, Insightful

    Years ago, I registered the email account crawdaddy*AT*hotmail*DOT*com. Since then, several other "crawdaddy" accounts have been opened on hotmail. Many of these people forget to tell their friends/services they're signing up with that there is a number that follows their name, ie. crawdaddy69@hotmail.com. I have gotten several misdirected emails, including personal invitations to join someone on a trip, details of someone's personal life, two very detailed accounts of someone's sexual exploits, and one highly suspicious email that indicated something very illegal and fraudulent was going on somewhere and that the "crawdaddy" that should have received it is involved somehow. Of course, I also get exponentially more spam on this account that I do on any other account that myself or my friends have had for the same period of time. I now check my inbox twice a day just to clean out spam so that my hotmail account isn't temporarily disabled because it's reached its limit!

    1. Re:Misdirected spam, etc by snilloc · · Score: 2
      I feel your pain. As you can see, I was stupid enough to use my name for my hotmail login (circa 1997).

      In addition to the mountains of spam (some "legitimately" my spam, much of it not), I have received personal email for about 6 (IIRC) distinct individuals. Three are military-affiliated. I got mil-school grades for one kid (who did not do very well...), casual remarks about ... erm... let's say "adventures" in Columbia, and a (former?) military woman who signed up for some wedding site's list (among other lists).

      The first time I realised people were mistakenly using the account I owned was when I signed up to download an MS-Office97 patch. I was told by the server that I already had signed up... would I like to have my password emailed to me? Why sure! So I signed in (pw was a woman's name), changed the pw, and got my download.

      The worst quasi-spam was when some teenage girl gave "her" email out to all her friends, causing me to be put on what may have been the world's biggest forward list... and on the forward lists of other girls on the forward list... and so on...

  21. So many trash addresses by blindbat · · Score: 2, Insightful

    Make you wonder just how many *millions* of trash email addresses and fake names are in many databases that collect info from web forms.

    How often does a person enter false info because one *has* to to download, proceed, etc.

    1. Re:So many trash addresses by edhall · · Score: 2

      A lot of them are trash -- probably most. I (unitentionally) have some experience with that. You may be next.

      One of the SPAM generators out there seems to take the mailing list in batches, using the first name of a batch as the "From:" address and the rest as the "To:" addresses. This has two rather evil effects: the first address gets (1) bounce notices and (2) complaints.

      I was the unlucky victim of this program a few days ago. I got about ten bounce messages, some of them for a half dozen or so bad addresses (the program was smart enough to group messages by receiving domain), for about 30 bogus addresses in all. But I only got one complaint...

      -Ed
  22. Re:I'm no email antispam guru... by ShaunC · · Score: 5, Informative
    But why doesn't someone do this deliberately? That is, create a domain for the sole purpose of receiving spam only, and automating a banned email list to other servers.
    This is already a fairly widespread practice, though there's no need to use a special domain just for that purpose, or to keep that domain secret. In fact, you want the spamtrap to be quite public, otherwise spammers aren't going to find it. All you need is a dedicated mailbox - even a freebie Hotmail account - to create your own spamtrap. Seeding the spamtrap is simple, and can be done using any or all of the following methods:

    • Post "test" posts to a few newsgroups, I suggest alt.test and alt.business.multi-level, using your new spamtrap address as the From and Reply-To address. (Technically, test posts are not appropriate in alt.business.multi-level, but if you want a fast track to spam, that's the place to go.)
    • Visit the "remove" links in spam you already get at your existing mailboxes, and type your spamtrap address into the remove box. If you have the time or patience, you can do the same thing with spam which contains a remove address instead of a link; send remove requests from your spamtrap. Removal is spammerspeak for opting in, so this will grow your spam collection quickly.
    • Embed a mailto link to your spamtrap address on a couple of webpages you control. Make the mailto visible only to web-scraping robots by linking to a 1x1 pixel black image file in place of a period on your page; human viewers will see it as a period, harvesting programs will see it as fresh meat.
    Whatever you do, don't give your spamtrap address to anyone for legitimate email, and don't sign up for anything using that address. If you follow those two guidelines, every single message that mailbox receives is guaranteed to be spam. This will give you the ability to archive, auto-report, etc. the incoming mail without fear of false positives.

    Shaun
    --
    Thanks to the War on Drugs, it's easier to buy meth than it is to buy cold medicine!
  23. Re:Idea: Damaging alternative to MAPS by Maserati · · Score: 2

    Better. I collect spammer phone numbers. Anybody want a copy of my list ?

    --
    Veteran, Bermuda Triangle Expeditionary Force, 1992-1951
  24. I need a lawyer... by gnovos · · Score: 3, Interesting

    The thing that I find amazing is that these spammers are flat out lying. They claim that ficticious entities "opt in" when they clear could not have done so. Doesn't this constitute some kind of fraud? Is there no legal recourse?

    --
    "Your superior intellect is no match for our puny weapons!"
  25. Original by Pac · · Score: 3, Funny

    Now, if you really want to impress us, come up with a search that returns all pages in the correct order.

    :)

  26. Re:Now what about spam-terror? by Bouncings · · Score: 2
    Spam is terror, of course, and now we have ... The Axis of Spam:
    • DoubleClick
    • Direct Marketing Association of America
    • Open Relays
    And remember. If you give porn sites your email address, the spammers have already won.
    --
    -- Ken Kinder ken@_nospam_kenkinder.com http://kenkinder.com/
  27. Re:I do it all the time by HiThere · · Score: 2

    I prefer nemo@hotmail.com
    I doubt that anyone would actually be silly enough to use that address for real, even if their name WAS nemo. Sometimes that character says his name is Odysus, or Odeysus (or some other variation).

    --

    I think we've pushed this "anyone can grow up to be president" thing too far.
  28. Re:POOR MODDING!!! (Actually, no) by Omerna · · Score: 2

    That was the biggest Karma whoring I've ever seen. Not necessarily a BAD thing, but something that shouldn't be modded up to +5 informative/ interesting on EVERY post. +3 is fine, but more than that is the guy beating the system. Good idea though.

    --


    No sig for you.
  29. Single-opt-in lists help fight spam by NewtonsLaw · · Score: 2

    Yes, it's true -- the very single-opt-in mailing lists that are used by spammer scan be used to fight back.

    Spam Can Be Fun

  30. Fake Email Addresses by P!erCer · · Score: 2, Insightful

    Whenever I am asked for an email address from an non-reputable site, I simply give a fake one such as wigglebroggle@frogtoggle.com. My friends do the same thing, except they always do randomaddress@hotmail.com. I know a lot of people who do that. Hotmail must be swamped with invalid emails... Also, I bet some of the "fake" addresses turn out to be real and some poor people start getting spam they don't deserve. "Accidently" type the wrong address...ha!

    1. Re:Fake Email Addresses by rgmoore · · Score: 2, Insightful

      If that's the case, you should use a known invalid address. Just use something like nobody@127.0.0.1, which is guaranteed not to go to anyone who doesn't deserve it. ISTR that there are even some reserved names that are guaranteed not to work, and I seriously doubt that most software actually checks for address validity before letting you proceed. Or you could always use something like postmaster@theirname, so they wind up bombarding themselves with spam if they try to use it.

      --

      There's no point in questioning authority if you aren't going to listen to the answers.

    2. Re:Fake Email Addresses by ScottForbes · · Score: 2, Interesting
      Whenever I am asked for an email address from an non-reputable site, I simply give a fake one such as wigglebroggle@frogtoggle.com.

      Making up domain names still pollutes the namespace, though -- imagine if people made up telephone numbers the same way. Why not use example.com instead?

      The example.com, example.net and example.org domains are reserved by IANA for use in testing and documentation; they're the equivalent of a telephone 555 prefix, only less obvious. See RFC 2606, or visit the example.com web page.

    3. Re:Fake Email Addresses by 0xA · · Score: 3, Funny

      I do this too. I pity the poor bastard who has fuck@yougys.com

      :)

  31. Use me@privacy.net instead by driehuis · · Score: 5, Informative

    Please, don't pull domain names out of a hat. There is an official fake address that you can use:
    me@privacy.net
    See their website for more info.

    A friend of mine runs a domain that happens to be used a lot by people who think they enter a non-existant domain, and it's driving him nuts. Well, there is some amusement value in noticing how many variations people come up with, but still...

    --

    Bert Driehuis -- All I asked was a friggin' rotatin' chair. Throw me a bone here, people.

    1. Re:Use me@privacy.net instead by BarefootClown · · Score: 2

      My favorite two addresses for web forms are root@yourdomain.com and administrator@yourdomain.com, where yourdomain is the domain of the site hosting the web form. I've only seen one company that uses Javascript to filter such addresses (Adobe, if memory serves, but don't hold me to it). At that point, I encourage them to spam me. ;-)

      --

      "Make it ten--I am only a poor corrupt official."
      --Captain Louis Renault (Claude Rains), Casablanca

  32. Re:I do it all the time by gmack · · Score: 2

    my employer owns sackmail.com ... for some reason we have been getting a lot of spam to lickmyhairynuts@sackmail.com.

  33. That only answers half the question... by Ungrounded+Lightning · · Score: 2

    But why doesn't someone do this deliberately? That is, create a domain for the sole purpose of receiving spam only, and automating a banned email list to other servers.

    [Details on how to set up the TRAP deleted.]


    That answers the first part of the question...

    But how about the second part? Is there an existing tool to automate the conversion of the collected spam-trap mail into denials of future mail deliveries (and perhaps also to purging of still-enqueued letters to real addresses earlier in their mailing list order)?

    Better yet: It could also modify the behavior of the SMTP server so it spawns a (limited nubmer of) "sticky TCP connection" child process to hang the spammer's bulk-mailing tool. Deploy a bunch of these puppies around the net and spamming becomes impractical once the spammer's mailing list has acquired a few addresses on spam-trapping sites.

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
    1. Re:That only answers half the question... by ShaunC · · Score: 3, Informative
      Is there an existing tool to automate the conversion of the collected spam-trap mail into denials of future mail deliveries (and perhaps also to purging of still-enqueued letters to real addresses earlier in their mailing list order)?
      That I don't know. I do know that several blocklists, including the well-regarded SPEWS, use their own personal spamtraps to develop their lists of who's spamming. To the best of my knowledge, SPEWS translates their spamtrap mailboxes to their blocklist manually, not automatically; this assumption comes from several SPEWS errors, including one a few days ago which erroneously blocked a large portion of the internet (64.x.x.0/24 - 4.x.x.0/24).

      I've never investigated the details, as I don't have the bandwidth to host my own publicly available blocklist. I would if I could. I contribute to the proxy.relays.osirusoft.com blocklist, but that's only because people don't hit me directly for the queries.
      Better yet: It could also modify the behavior of the SMTP server so it spawns a (limited nubmer of) "sticky TCP connection" child process to hang the spammer's bulk-mailing tool. Deploy a bunch of these puppies around the net and spamming becomes impractical once the spammer's mailing list has acquired a few addresses on spam-trapping sites.
      If I'm thinking what you're thinking, these are known as "teergrubes" which is the German word for "tarpits." A spammer connects, and his spamware becomes trapped in several hundred SMTP connections which don't close, but instead transfer something on the order of 1 byte per minute. The spamming program gets hopelessly hung up in sockets that won't close, preventing his machine from opening more connections. A lot of people who run SMTP relay honeypots also run them as "teergrubes."

      Shaun
      --
      Thanks to the War on Drugs, it's easier to buy meth than it is to buy cold medicine!
  34. Re:This = Great way to kill off a hotmail account by codexus · · Score: 2

    Uh, aren't being you a little paranoid? So what if someone gets your real name in a spam mail? I don't see why they would find that so interesting.

    --
    True warriors use the Klingon Google
  35. Fake addresses don't work by driehuis · · Score: 2

    Spammers are very apt at verifying that their address lists actually work. Ever get a spam that seems really outlandish? A spammer asking for assistance in time travel? A kook that proclaims the end of the world is nigh? A totally empty message body?

    Chances are they were just checking to see if the mail bounced.

    If you have your own domain, try this experiment. Create an e-mail account, say: john.doe@your.domain. On your home page, publish the e-mail addresses john.doe@your.domain and jane.doe@your.domain. Make sure mail for your virtual jane is bounced with a "no such user" error. Watch how long it takes for john.doe to start getting spam. Check your logs for attempts to deliver to either john or jane.

    If your experience matches mine, spam for john will be at least tenfold of what jane gets after about a month. After about a year, the relative difference will level off, but if by that time you create jane.doe@your.domain you will probably notice that she is very popular with spammers who do not speak your language.

    One can debate which is worse, the bombardment of spam in a language you can read or the bombardment of spam in a language you can't, but feeding spammers fake addresses will only "hurt" the extremely stupid ones.

    Not that there's any shortage of those. I get spam advertizing piano lessons in South Buenos Aires or airco repair in Hong Kong, and I own no airco or piano.

    --

    Bert Driehuis -- All I asked was a friggin' rotatin' chair. Throw me a bone here, people.

    1. Re:Fake addresses don't work by dbirchall · · Score: 2
      > Spammers are very apt at verifying that
      > their address lists actually work.

      Riiiiight. That's why in the last 3 months, just as an example, my mail server has rejected almost 50 attempts to mail djb991227@scream.org - by the SAME outfit (networkpromotion.com).

      And get this - they all came from VERP addresses, so if they *did* have a clue, they could've done bounce processing, etc.

      If anybody didn't draw the obvious conclusion, that particular address existed briefly, over 2 years ago. It's been gone for 2+ years. And networkpromotions.com didn't *start* trying to spam it until this February.

      If spammers were good at screening addresses, my server wouldn't be logging those failed attempts. Or the failed attempts to addresses that have *never* existed in various domains I run. Or the failed attempts to things that aren't even addresses, but Usenet message-ID's.

      Not to say that "legit" businesses do much better at this, of course!

      -Dan

    2. Re:Fake addresses don't work by driehuis · · Score: 2

      Maybe this has something to do with it?

      May 7 10:13:40 postfix/smtp[21587]: DDA0282CC: to=, relay=listserv1.networkpromotion.com[142.166.168.2 13], delay=197242, status=deferred (host listserv1.networkpromotion.com[142.166.168.213] said: 451-System error, mail not delivered. 451 Error opening 'MD_LS3-16310300.TMP': There is not enough space on the disk.)

      They're dorks. Spammers do come in flavors (and some even double up in multiple categories; there are at least two mainsleaze^H^H^H^H^H^Hstream e-mail marketing companies that have seperate domain names and IP addresses for squeaky clean opt-in e-mail lists and honest to god spam). It's been a while since I read Nadine's sorry tale, but ISTR both companies figured in it.

      Thanks for the pointer, I didn't have them in my filters just yet.

      I still suggest you do the experiment. It worked for me (and for my Nadine -- sigh)

      --

      Bert Driehuis -- All I asked was a friggin' rotatin' chair. Throw me a bone here, people.

  36. Let's do the same. by jmv · · Score: 2

    Say I receive a spam mail from spamcompany.com, I could go to alsospam.com and register to receive mail at doesnt.exist@spamcompany.com. Do that a couple times and you endup with spam companies using their resources to spam eachother...

  37. The funniest thing about this story was... by Kamel+Jockey · · Score: 5, Insightful

    I really hope that the author of the article implied sarcasm when he was "not worried" that the spam sender had a "privacy policy" registered with that TrustE or whoever the authority of the week happens to be. I can't believe people actually believe any site's privacy policy. Sure it says all the BS about how they won't sell your info, but of course it also says they can change it at their discretion, which is how they get around it. Call it the "Darth Vader" rule of contracts.

    This reminds of a friend of mine who was outraged that her supposedly private email address (which she only gave to 3 friends and never posted it online anywhere) received spam. I told her it must have been her ISP that sold her email address to a spammer, if none of her friends indeed didn't give it out. She told me it couldn't have been them because it was "illegal" for the ISP to do that. Of course its "illegal"... doesn't mean they won't do it though!

    IMHO, no privacy policy is worth the paper on which it is written (which is true because most are not printed out). No matter what any site's policy says, it is safe to assume that they can and will sell all of your personal information to the highest bidder (along with everyone else). We need to stop being naive enough to believe that companies actually care about our privacy. As long as its profitable for companies to sell information, it will always happen.

    I hope I didn't come off as a troll, but this cynical view is based on many years of experience dealing with online and offline vendors. None of them has ever respected my privacy, and none ever will. But knowing this, I can adjust my buying habits to ensure my privacy isn't compromised too badly.

    --
    In case of fire, do not use elevator. Use water!
  38. Or use plussed addresses by driehuis · · Score: 2

    The trick of creating company specific addresses works if you have full control of you e-mail domain. If you don't, it's possible that plussed addresses do work. If your e-mail address is john.doe@company.com, enter john.doe+evilcompany@company.com when Evil corporation wants your e-mail address to download, say, their Evil Player.

    If plussed addresses don't work at your provider, bug them.

    A really sophisticated way of doing this is to use TMDA, which extends this concept into time-limited addresses as well as more classic notions of "tagging" an e-mail address.

    --

    Bert Driehuis -- All I asked was a friggin' rotatin' chair. Throw me a bone here, people.

  39. But did she win?! by pyrrho · · Score: 4, Funny


    I read the whole thing and I still don't know if she won the sweepstakes and then the poor dear didn't even hear about it or get her oodles of cash.

    --

    -pyrrho

  40. Sneakemail can't even save you by alanjstr · · Score: 2

    I'm a firm believer in Sneakemail and customizing email addresses for each site you visit. This shows that, unfortunately, even non-existant email addresses still get spammed. That drags down their resources. What we need to do is get rid of the open relays and the like. Its obvious that MAPS and RBL will only be able to do a certain amount of blocking. Spammers are very creative and have minimal costs.

  41. Re:Filter a good chunk of it automatically... by Matts · · Score: 2

    70%???

    That's terrible. We should be doing a lot better than that. Please let us know where we might be going wrong for you. For other people we're doing around 90 to 95%.

    Matt - one of the SpamAssassin developers.

    --

    Matt. Want XML + Apache + Stylesheets? Get AxKit.
  42. Spam makes email useless for me, what to do? by Ars-Gonzo · · Score: 3, Interesting

    I've been the technical editor for Maximum PC magazine for almost two years. Before I worked here, I worked for Ars Technica. At some point or another all of my email addresses have been posted on high traffic, public websites. Heavy spam has been a part of my day-to-day life for the past 4 years.

    It's gotten much worse lately. On any given day, I get about:
    20 viagra sales pitches
    20 penile/breast enlargement ads
    20 get rich quick schemes
    30 different porn ads
    10 you've won something messages
    and another 20 or so messages that don't fit a category

    Add anywhere from 3 to 20 assorted virus infected messages, the 20 or so press releases that come in every morning, and I don't know why email's even worth fooling with for the four or five messages that I actually read every day. Most of the repeat spam gets filtered and stored in a special folder, but I still end up seeing 25% of the total spam in my inbox every day.

    Does anyone actually think that spam control legislation would help at this point? Most of the stuff I receive comes from the Pac rim countries or Russia. Anyone know any Congressmen or Senators who are pro-spam control?

    As a short term solution, does anyone know a spam-filtering good POP3 client, or preferably a proxy I could use to filter spam that uses the MAPS or SPEWS lists?

    ///Will Smith

  43. Advertising? What advertising? by Animats · · Score: 3, Interesting
    I'm only vaguely aware that there's advertising on the Internet. Mail goes through SpamCop, web browsing goes through WebWasher, and searches go through Google. What ads?

    There are some e-commerce sites that don't work right behind a WebWasher proxy, but most do, and I buy from the ones that work, so there's no problem there.

  44. Re:Idea: Damaging alternative to MAPS by miracle69 · · Score: 2

    Even more Damaging would be this inventive scheme.

    All it would take would be a couple of bogus addresses run by a few people in different locations. Let these things become well-known spam-sluts.

    Collect the addresses of the spammers for the first few months. Then, change the account so that, with each spam it recieves, it sends an email out to a well-known usenet spam-harvest list with emails of the spammers, as well as randomly generated addresses from the spammers domain.

    To further make this evil, though it might cost you that account, have a .forward that uses this aforementioned spam-legit-list and forward all spams to them, as well as the randomly generated email addys at the spammers domain.

    --
    Linux - Because Mommy taught me to Share.
  45. Re:I'm no email antispam guru... by conradp · · Score: 2, Informative
    I've been doing something like this for about 2 years now. In fact, since I own my own domain, I make up a new email address for every company that I sign up with, so I can know exactly who sold my email address or gave it to one of their "partners" without my permission. For example, if my domain is example.com and I'm signing up for some account at potentialspammer.com, I sign up with the email address cppotentialspammer@example.com (my initials are "cp".) I do this whenever I buy something online, register at a site, etc.

    When I first started this, I thought I'd "catch" a huge number of companies selling or using my email address without their permission. But what I've noticed over time is that I almost never receive any spam at these addresses. That is, probably 95-99% of the companies that I've signed up with have respected my preferences and have not sold or spammed my email address. Nearly all the spam that I receive (and I get a lot, though switching to the fastmail IMAP mail service has cut my spam significantly) is sent to:

    an old address that I used 10 years ago to post on usenet

    the address that I used when registering my domain

    I think it's somewhat heartening that most companies that I have any real business or interaction with have properly protected my email address, the spam seems to come almost entirely from various types of harvesters.

    --
    "To be absolutely certain about something, one must know everything or nothing about it." -- Olin Miller
  46. Re:I wish. by conradp · · Score: 2, Funny
    Spammers aren't smart, but they're probably smart enough to strip the ".gov" addresses before they fire up the spam blasters.

    Maybe some are, but plenty of them are not. I've received a fair amount of spam at my "af.mil" account. A short note to the owner of the spamming domain or advertised service, including some mumbling about misuse of federal government computer systems constituting a federal crime, usually shuts them up, without even needing to point out the fact that they're sending spam to an organization with precision GPS-guided munitions!
    --
    "To be absolutely certain about something, one must know everything or nothing about it." -- Olin Miller
  47. Geez by Russ+Nelson · · Score: 2

    Geez, back in 1998, I consulted for MatchLogic on their email system. They seemed on the up-and-up, but of course that was four years ago.
    -russ

    --
    Don't piss off The Angry Economist
  48. Re:even better. by cybermage · · Score: 3, Funny

    The email talked about their time together and how she was having second thoughts when she called his house and his wife answered.

    I responded that she must have the wrong email address.


    You could have told her that your, that is his, wife was interested in a threesome and watch the sparks fly instead.

    If you feel like a little mischief, mistaken identity can be a beautiful thing.

  49. spamcop helper by dickens · · Score: 4, Informative

    I move my spam to the "spam" folder on my imap server. So it never even wastes bandwidth coming down to my workstation (over a dialup).

    Then I use this script to fire it all off to spamcop once a day:


    #!/usr/local/bin/perl
    $reporting_addr = 'submit.yourspamcopidhere@spam.spamcop.net';
    $/ = undef; #slurp mode
    $buf = &LT #slurp
    @spams = split(/\nFrom /,$buf); # split on message header
    for ($i=1; $i&LT=$#spams; $i++) {
    open (MAILER,"| mail $reporting_addr");
    $msg = "From " . $spams[$i];
    print MAILER $msg;
    close MAILER;
    }

    Not perfect, and you still have to visit the spamcop site to finish the reporting thing, but it's semi-automated at least. And forgive my clunky perl idioms.

  50. Poor Nadine... by ScooterComputer · · Score: 3, Interesting
    Just wanted to pass along a funny that relates to the "Nadine" story. It doesn't get much funnier than this...

    My grandmother is 75; her birthday was in October. Just prior, she suffered a heart attack, and I decided to resurrect an old Performa 6360 for her so that she could email and ICQ with my mother and aunt. I provided her an email address at a domain I own. The address had never been used prior. My grandmother had never used a computer, and even getting her to be comfortable turning it on was a challenge. I don't believe she EVER successfully sent my mother a message by herself...although I could be wrong. I would bet that she used that computer a grand total of ten times.

    A few months had passed, and I had a sneaking feeling that she wasn't using it. I would ask her, and she'd sheepishly admit that she "didn't have time" to sit and work on it. (Yeah, right. She's 75.) So one day in February I decided to peek into her mailbox to see if there was any mail in there that MIGHT be important...I was FLOORED by what I found.

    I now have a mail folder sitting in Entourage that consists of 767 (!!!) unread messages. I simply can't bare to get rid of them. The first is from September 20th, 2001, and the last was sent on February 21, 2002, when I killed the account. None of them were "for" her (from people she knows). And some of the products being offered would probably cause her to keel over.

    I am currently simply /dev/null-ing any mail incoming for her address...and I'm sure that if I'd remove that filter, the mail would still be flowing. If anyone (say a reporter, member of Congress, or FTC) would like to have a copy of this archive, I'd be happy to pass it along.

    767...I love the internet!

    --
    Scott
    "Hokey religions and ancient weapons are no match for a good blaster at your side, kid."
  51. Spammers simply try variants of names... by geekotourist · · Score: 3, Interesting

    IHDAOS (I have done analysis of spam)

    It is very likely not the ISP- the money they spend on help-desk complaint people would outweigh the cents received from a spammer.

    Spammers will make up lists of names. If you are a john smith, you will get spam. period. Because their lists will have john.smith@X, johnsmith@, jsmith@, johns@... they take lists of the most common names and put together all possible variants. I've seen many cases where they forgot to BCC the list... "asmith, bsmith, csmith...aasmith, absmith..."

    Unless your friend's email address is unguessable. Then its likely someone cracked into their system and got the list. Selling it? they'd have to be desparate idiots.

  52. The Government should do this, dammit! by alispguru · · Score: 2

    The FTC has an email address for people to report spam (uce@ftc.gov). Anybody see any reason why they shouldn't create virgin email addresses, wait for spam to them that says "this was sent to you because you opted in" , and then haul the bastards in for fraud?

    Private citizens can create spamtraps and use them to report the spammers to the authorities - why not cut out the middleman?

    --

    To a Lisp hacker, XML is S-expressions in drag.
  53. Re:president@whitehouse.gov by WillSeattle · · Score: 2

    To make a long story bearable... I managed to send mail on behalf of the president - to a legitimate address.

    The whitehouse actually tracked it back to me (Not difficult as I was not trying to hide - just stupid).


    Oh, c'mon, they always bring Krispy Kremes and coffee when they interrogate you. So long as you show them the id barcode on your neck, they usually let you go after a couple of hours ...

    -

    --
    --- Will in Seattle - What are you doing to fight the War?
  54. Your sig by oni · · Score: 2

    LOAD?

    Holy cow, I haven't seen those commands in a while!