NYTimes: Tangled Up in Spam
ezekieldas writes "Congratulations to the SpamAssassin developers and community! There's a mention of SA in the NYTMag as "one of the best tools for network administrators..." in an extensive article entitled
Tangled Up in Spam.
The article is quite substantial and the author, James Gleick, is more technically educated than what we've come to expect from the big press. Central to the story is the complexity in dealing with spam effectively in both technical and legal terms and the confusion it brings upon the neophyte. The conclusion drawn may be oversimplified but nonetheless pragmatic: 1) forged headers should be illegal 2) a specific header entry should identify the email as unsolicited."
Spam entangles YOU!!!
I'm tangled in shoes!
Want some shoes?
I been using Spam assassin for a while now, it is sad to say, but email would be almost unusable with out it.
now that it has been advertised in NYTmag, more people will become aware that spam is something they can actually stop. Can't wait for the new tricks spammers will use to disable anti-spam programs.
No, I don't want to register!
By simply filtering out all e-mails that have the word "Nigeria" in them.
Work sucked, until it became unemployment, when it became slightly more tolerable. -Tet
Libtroll is a fast, platform indepedendant trolling library written in visual basic. It supports crapfloods, first posts, old ike, ??? profit, in soviet russia, and goatse links. Using libtroll, trolls can effortlessly generate lameness filter breaking trolls that get bites *and* modded up. This version only supports slashdot, future versions will support slashcode, phpnuke, postnuke, scoop, darkportal, and over 20 other slashdot clones.
download
>>> 2) a specific header entry should identify the email as unsolicited." NO NO NO There is no excuse for sending spam. I fail to see how marking it as junk makes it any better. So I can sort it from the mail I actually want? NO. Just stop people sending me crap I don't want.
Sig is taking a break!
I was wondering how many large corporation are using SpamAssasin. And if not, why not?
Consensus is good, but informed dictatorship is better
... since archived material is considered so old that it doesn't require a registration. ;-)
S PAM.html
http://archive.nytimes.com/2003/02/09/magazine/09
Beware: In C++, your friends can see your privates!
illegal is great in theory, but there is no possible way to enforce that on a world wide basis.
white lists are the only way to stop spam.
The conclusion drawn may be oversimplified but nonetheless pragmatic: 1) forged headers should be illegal 2) a specific header entry should identify the email as unsolicited
Why does everyone in the USA assume that everyone else in the world will somehow obey US law when it is made "illegal"?
So how much spam am I likely to get if I give in and register with NYTimes so I can read the article?
Two weeks ago, on my old email that I don't use anymore, I decided to "unsubscribe" from all these lists, thinking it would "confirm" the existence of my email address. However, the number of spams I get has reduced from 15-20 to 3-5 a day ! I'll have to see if it goes up again in a few weeks though...
now use SpamAssassin. Basically, a set of new headers is attached to the e-mail of the form X-Spam-foo, and if X-Spam-Score is 7.5 or greater (on a scale of 10 I believe), then X-Spam-Flag is yes. It's really useful for sorting out spam quickly, and I haven't gotten a false positive yet...It doesn't get all of the spam, but it gets the vast majority of it...
Spam is a technical problem, so why can't we come up with a technical solution? For example, it should be impossible to forge headers, not illegal. Why rely on a legal solution from many of the people who have brought us such brilliant solutions as the DMCA and the CDA in the past when all that's required is what our community has always been good at: sitting down and thinking things out?
Try not. Do or do not, there is no try.
-- Dr. Spock, stardate 2822-3.
Filter any e-mails containign the phrase, "this is not an unsolicited message".
"Sic Semper Tyrannosaurus Rex."
Spam Spam Spam Spam
Where does it come from, Uncle Sam?
"Monty Python, don't you know,
When the madness was in full flow"
But what when the accursed stuff
Leads one to declare, "I've had enough!"?
"My son, spam's easy to fail,
When you stop using hotmail!"
-Mark
Looks like we have the supremes on our side; if we could just congress to issue some letters of marque and reprisal on the spamhausen, we'd be getting somewhere...
What a strange bird is the pelican, his beak can hold more than his belly can.
I think that breaking that economic model -- ending the reciever-pays system for email -- is the only way to fix spam. If you had to pay some amount of money -- event 1 cent -- for each message that is delivered, spam would stop being economical. And that's the only thing that's going to make it stop.
-Esme
Copy and paste this into a bookmarklet:
; nu mbers="0123456789";document.forms[1].login.value=" ";document.forms[1].passwd1.value="";document.form s[1].passwd2.value="";document.forms[1].email.valu e="";document.forms[1].birth_year.value="";documen t.forms[1].zip.value="";while(document.forms[1].lo gin.value.length1)document.forms[1].gender_check[1 ].checked=true;document.forms[1].birth_year.value+ =numbers.substring(strindex=Math.round(Math.random ()*9),strindex+1);document.forms[1].birth_year.val ue+=numbers.substring(strindex=Math.round(Math.ran dom()*9),strindex+1);document.forms[1].zip.value+= numbers.substring(strindex=Math.round(Math.random( )*9),strindex+1);document.forms[1].zip.value+=numb ers.substring(strindex=Math.round(Math.random()*9) ,strindex+1);document.forms[1].zip.value+=numbers. substring(strindex=Math.round(Math.random()*9),str index+1);document.forms[1].zip.value+=numbers.subs tring(strindex=Math.round(Math.random()*9),strinde x+1);document.forms[1].zip.value+=numbers.substrin g(strindex=Math.round(Math.random()*9),strindex+1) ;document.forms[1].country.selectedIndex=Math.roun d(Math.random()*236);document.forms[1].income_sele ct.value=Math.round(Math.random()*10)+1;document.f orms[1].industry_select.value=Math.round(Math.rand om()*36)+1;document.forms[1].title_select.value=Ma th.round(Math.random()*36)+1;document.forms[1].fun ction_select.value=Math.round(Math.random()*16)+1; document.forms[1].paper_select.value=Math.round(Ma th.random()*3)+1;document.forms[1].submit();
javascript:letters="abcdefghijklmnopqrstuvwxyz"
There shouldn't be any spaces in there, so cut them out if slashdot inserts them. When you get to the NYTimes "you must register" page, click the bookmarklet. It's not the most beautiful solution, but it does the job.
Sure all these programs help, but think about what creates spam in the first place.
There are clearly people out there willing to buy the things offered in spam. Obviously not that many, but enough to make a profit. I think that there should be more of an effort to target these people and tell them not to buy stuff from spam!
There is only so much a program can do to stop spam. As we've seen numerous programs have been made, Spam Assasin being one of the best (I use it), but the spam just keeps coming
Until there is no incentive to send spam in the first place people will do it despite any laws against it.
The one big feature missing for me in evolution is a spam filter. Fortunately, spamassassin works great even if you have to run it locally. Here are some instructions for evolution users who need to run it locally or are lucky enough to have spamassassin installed on their mail server.
Be careful what you outlaw. If the law is too broad, it could easily be used to prohibit not only headers in email messages, but in connecting to a web server. How would you like to have it be illegal to lie about what browser you're using? Or refuse to send a referer?
Fuck jewes,fuck socialists,fuck niggers,fuck jeltsin, fuck gays,fuck
russia, fuck equal rights,fuck old people,fuck hippies,fuck police,fuck
ugly girls,FUCK YOU!!!
Who gets to ensure that mail headers are not forged and that mail is unsolicited/solicited? First, e-mail has no phsyical boundaries so should it be by local governments? There have been times when I signed up for something I forgot about, and I received e-mail many months later, thinking it was spam. If the users can't tell what is unsolicited or not, how will we know what is solicited mail?
The trick is to have 2 email addresses(I used to have 3 but the company hosting the third one went belly up). Private and Public, on the public one put everything, password confirmation, slashdot details, EVERYTHING, give this to all your friends, never check it, you don't have the time to wade through them all.
The other one(private) don't give it to anyone, never reply to anything sent to it and if asked deny ever having regestered it.
The first will get about 400 SPAMs a day, the second, only about 4 a week.
And thats how you beat the internet.
Read Errant Story.
All about NY Times - Spam, Registration and unbiased news unlike CNN
Also on
Programmers who wrote Kazaa.....
Three Estonians programmers wrote Kazaa code
Kazaa looks for salvation
The conclusion drawn may be oversimplified but nonetheless pragmatic: 1) forged headers should be illegal 2) a specific header entry should identify the email as unsolicited.
I don't know what is meant by unsolicited -- and I doubt that there are good definitions that are practical. Nor do I want any single e-mail ever to be treated as spam because some unsophisticate forgot to (or didn't have the software) to make the e-mail unsolicited.
I *DO* want the anti-spam laws to have teeth and very few exceptions -- for that, the criteria for spam should be sufficient to permit adequate filtering (to be useful), not be content-based (to be constitutional), and should be relatively objective (to be practically enforeceable).
Thus, in lieu of forcing headers to identify whether an e-mail is solicited, i would punish falsely identifying an e-mail as non-broadcast. That is to say, an e-mail is not broadcast if it was sent to, say, fewer than 200 different addresses that had not specifically opted-in by affirmative request to receive it.*
Then, we simply get most e-mails clients to flag routine e-mails as non-broadcast, and you have a decent result.
*the only tricks here are (1) subtle and non-substantive changes in each e-mail making them different and (2) sending e-mails on behalf of many different sources (from 1000's of different e-mail accounts). The solutions can be readily addressed by (1) referring to the e-mail and "substantially similar" e-mails (the copyright standard); and (2) referring to e-mails sent by or on behalf of a particular individual. Thus, the person commissioning the spam is always liable for the crime -- regardless how many different persons send the spam on her behalf.
when people say SpamAssassin is good - they should really be talking about 2.5
that is the version with the Bayes fully in it and it is head and shoulders above the previous versions IMO
There are some odd things afoot now, in the Villa Straylight.
The uneducated guy that send this story in, need to know that was instrumental in taking Chaos theory from an obscure science in Santa Fe into something that almost every scientific discipline benefits from. Incl CS. .
Help fight continental drift.
I don't know about the other things the author mentioned, but forged headers should be illegal.
I know /.ers have a habit of commenting without reading the article (ya think?) but this article is worth reading.
I am not sure if you have to register with NYTimes (I registered years ago) but its worth registering for free if needed. Its a well thought out article.
Tequila: It's not just for breakfast anymore!
bc 1.061 15002721066717499970560475915292972092463817413019 002224719\3 739477476921318606372636178984\0 17775070151511403557092273162342868889924175446071 9\5 8090483994093090003497\1 9871700937907982098462523537398128174081811\0 82855201484221006095893241244593103505751919630294 13832634742802\6 39370400238207308545653067447714859\7 18678381165470458727612711126998867843493017586142 497017\7 987307048236318734734842180\6 105622847799586289633293928168787475865603473791\ 5 7055930979119465756398917686972170262497\6 29918606531157083493680769804948170607437684746785 58652825501\4 35323966214778965479104541869346\5 63917026341604354229856108549326870868151717454045 545\6 552816295172649366879479\8 761661340148199686747394077600288553371849754\8 54815019229716721173113248608110210121258893903751 4478889744791331\5 4018156357895522961871250053798259915\8 54605420376995311733285509656036372119940623227260 44020003\9 19646712822010257214109160409\9 52873769554560279984457347340632778582449773361833 \6 644848964141894347893\8 450703629203132825255297223387618655295760\3 92079618178724557632468820998367177998089417491686 1191540469301\4 8169001292545468245289432144487702\1 63237766773559402659230087980647343973738527232446 92826\9 21952629935015973523847830\5 67453451124591288886991684357767642560409114990\ 5 884739130529850712\7 735590346500026916493632949115086477464\4 18095868473311198122989269564183230349586377140301 7366660778\4 8375291822737480958496977561043\0 49514458221213527859270297608124363941459394041101 24\7 45492656438230232155785\2 49801592029855566655958908654984763015387239\4 84168037058128133333970537210068213915754595612352 916618248559570\1 533506472493824769330065184875328270\4 28156370572397770557792141350903859146735371121611 5279620\3 9463853265642033099898123662\6 2511536570624880501960785081268875545352169467212\ 2 08795535416004889789\6 60195255600307730906692488664558219440047\9 41569123947347269776844239565780381392307120675846 604383033333\1 286689909487110757546132154147185\1 90682306033088610766493414160198589650868570091681 7734\1 4775688641465919333572863\7 7129230388799932396711358512609400882024121916\
6 16724610515814317667818515615351604097586757525690 42438798815881269\2 80724853932749628328378475515388241948\5 07768359459708179608912108284820777351065349964416 938518464\9 517900820700049329200857289827\3 74954168571922560670663944390216359206349025623685 9\3 6347117436592311659210\8 1413928245728750872865708588702495381930919\4 88687164082458992115619664035358062981306476521319 19835140349031\1 84526978102429749510799115578274404\1 61958413839389399221732173754583444188878373049845 658787\7 386922588872500718733848464\1 524302252986679424877010000296131154908241005737\ 6 3327384259744143529043448944035077539873\4 68755159457055267513925347947701731127357889493866 84980073901\6 47836311243500990031439308622007\8 00391206100830174081569732350299607726689280034329 578\8 148112313543013664865230\7 208144292594861066528813416573196825791124411\6 41997012060839814232045258535244684350825310791565 0290667765064906\6 3166249067458766181197378402612691178\4 40786559308906002827030723531535734559244388764705 49124616\6 90144972626295175726334631623\5 10837269439451956787903848985417629671585426630133 \9 953890707563669113726\1 230604028652822285835656857948559527412527\6 77933393877006881914281286353559830832974216433580 9936894710485\8 8688988792468128821048618185821351\0 98409222753068207169829157997615067799291373615226 67569\2 84413220675994900000760229\9 63746287556191436553754758232529704395484082216\ 3 484565329342947905\5 232083777417300397762932320233073318213\4 93188026815026787675217460759335457846331267355125 5765575824\8 7664079023404405917663982503332\4 42067138245094873396994864008244336391375723031760 82\0 41933281226346282020753\6 65191607232659347102406866766046138830533773\1 92181776181191339930722251810233840830895678838113 610807616267854\3 979747405986114294894753868420155633\1 04285734975548398296710003160888945435573976937889 4940698\1 4208839138178798804502405288\4 5958699983588623603582665715396185796757899220605\ 1 22012747193769946819\9 30788106671610218084317475160866246224055\2 86653016416711892605253817776309930663717946545589 891424846667\0 173308221909748003136263335750768\8 56095165397743348342146159845260641588481315559147 7711\0 7427395776799622566579232\5 9388390163278574933581142569455119443070711081\
0 72152169856830759206302967138905570372429791674149 37760828346941137\5 72519001227975829763903650637089098831\8 54556081981641667771023372533052780731744918394028 048086608\4 909530735404939458850431760980\9 29914132465758514352113345202795389934328328236757 2\8 5318048850889760796712\2 9124285384717371486376408625324901198105402\0 47069661968704584930039792476252619102710426052156 33356772295221\6 72199700066051562836184396287523177\7 93094916396493152215749052044199199548353842438940 949408\0 012645373658973624984452397\2 965619543688943426532007546549223459628892835934\ 3 9559565409712917357380278372648881250746\9 85190720017437824511188680767434519366967546743421 56348801131\8 56917366342730485530670305892457\1 40899064521119064190660736266114146160924487930332 718\2 065545934488390973778005\1 817276669435013670895184103740920009723954243\0 66482875376506879193016239676764024193629764833397 3663903998405801\0 7827879824893133872678641875730730049\7 47839943577642115752781344890272219373089837208504 37360053\3 39622787713920974067058108447\2 48471624569168310875186460135160479142667459162811 \9 018277672970038107997\3 081491892343298429676953657139605552941278\6 28481204659552798454040937948593095138199470546107 2765143569104\2 0931692200730546082690187785358135\4 10606174655193530215600674212809923781613457318079 18041\6 58426087332829562120643461\5 32715734008259091321154388931240867701571917509\ 2 597102765531098215\8 486741996617294120964090554368759204552\8 21993315431600691334596735071152610400195598083033 5598215856\6 6225096008808251041639945368583\1 11213023081015691085144717119905219919183184657598 79\4 93450943737974065154368\4 93966854997922700454309153444224805690339830\0 73249561452573811783157384929530406182776100625594 815608394014392\0 848713942768045621882921530094791386\2 97019969686395088897631044724080510469839804202397 9991958\1 7434736636634572961720528223\8 0448473869313344553149051396252892709682869538264\ 0 04894094221630778110\1 01862232408390425443825074578573537956601\0 69794485373579880760051565672821146463804895551462 384021874419\2 003077247314645274777450060316480\6 32723383204249498123009231051678830169113751550422 1349\0 0082345547356888041717861\2 5976523499411173769760875624470514877222147557\
0 00534459235637979155593692353200702631822730053741 14037513224360615\2 18358014044072002968904867221558909468\2 18295445177641560347764846687693058167121763033176 268724569\3 181410145801203399123469963828\9 38803203743575563692562192743561241575719104974293 3\1 2237358449156178728238\4 1378631677892051807672986496844035559961502\4 34393063652832178775185194432087615964740107448476 84868199829342\9 01551502936985442243650727711658996\6 30344265409886447541243745606168339070528776934447 462350\2 092515037866014802666753177\6 763296313442115692407194499982591252024794714284\ 5 7870153025829510052088368636349319630477\1 78801136340649638457391724738823560547562289546677 38081945931\5 81656981818426879203420099581863\5 57728120097808040284134091387292493753890809886403 394\4 183493906823093986223030\0 052987951885797379548736587568786087247403765\9 46378264029196673555240970641514367875693601141883 2314318417352791\6 8347905673080323071352342734883009644\1 44158529072012219633669837807734374502146364879406 88126659\1 45923139970802136789284323060\8 91640934542975080415121021160987222187442418385996 \0 142339237646919342813\7 339770871514114435003454385605765219191495\6 41693797988331786582992402043603883798584358251715 6103445735113\3 3154314252730442213715617041624589\8 61521615435040595459605021727122493113086764626564 98246\0 39876523996567619294153760\5 07259812239845079085520778144498058104067746952\ 8 242219480833517459\9 794446906871690557084144075439460438175\3 54020886015774069838692557501529297843252048463096 9206668650\2 3262251567567802291299832718334\9 44386450635264367727038887359210839385376550512676 97\3 05110398488179732744444\5 14883105576487509803405594953799037114407487\0 67235509781133547932286036303023775456845416410194 059592725045555\0 807602126586882196509106278325155966\7 28106963295831250181039274820264249036096036936941 0389692\8 6905960708066212436570575987\1 6576008269742425521569326703747777053782978374334\ 1 21601250999312873831\1 19870718355717620953275467245453116395591\0 72296842692124673249714094718578388138174316300880 604579047687\1 403394912669933900350593847151451\4 29182906809755045768309238169538761686669910267038 6522\1 1348928748371305557085971\6 1022335343062984859328474127839717635343351452\
7 99525206073550788274388716530212655855625801111013 06029064583984069\4 46411974494209007906723699310263715178\0 33884821682519604312065586570303995552088655776705 988252771\8 051054068908786646460095049929\4 07799445610640747511667222207602820764121878112002 9\1 9399338533107737666062\3 3588343577423293762351006466212604626553973\9 02662340416775906044456694180700269258854443926314 70918887738677\7 30404040202520015236482607837236195\7 32084461036800862377415535362463712364747205024424 534718\7 197281727396271895135098815\6 457455107276161637759413365571771711616457371187\ 7 8080732181562412099870067274363513125312\3 66458524628977279877159643098398332644533966622195 28386413838\8 35345527009937596615676899106768\2 21512898387304938641827529678459656896106141122235 674\4 826328884614097177615079\7 448673066965921891169260064429334341821774261\0 29440343948307930222497969742588593425301762375937 9309309620080570\9 1402749717128214524369657310025385103\8 47929019435356828769514493680305216134996336430312 55534786\4 14837002248357751592371663251\8 80207358088274673694904073569544149133375263000172 \4 944115728192694524040\0 174005978762715997317395453390364986996115\5 79526324703834382793478731830972509770843118674104 9988293820103\1 6969831872306569053419342930578114\6 75557856102648230958694618393772775762536840090595 31353\3 43239113347044974001243249\3 77489765429280737182489514361924757084725087318\ 6 675901661321684558\6 988983706428301601956935339390001904475\6 60395416661691688222201460946123733535005821001392 1896983251\9 4075217016986995246738452320120\5 26770711564619169027228500979004643408614014769475 24\6 49566422846224046333270\2 74336160662567235622878672594233809472297015\5 88473737694604587853593952212886772583688944890111 013759635668535\7 679731806190641353752281136230340909\9 56898192504011133235072025978701592175212943013295 7568282\1 3758534191190388020983579830\8 3825971613224368445054392498341881930981997720800\ 2 58173642917071698822\2 79612368756969454949729090295419262084926\9 51232689130023648099871367983730644859240785216597 612551778156\7 737761778516595830672578468844299\1 27705872638995384002179747086563349209397581957729 7749\0 8636427500595642019903095\7 9599467214712029401419925495644744922632929377\
7 08467267587262762583214179558698894891298085166707 70910728107772484\1 57535088090882966955592209154276253820\3 89878577307262932296821225681139069482670620021470 350463474\5 343695819391059302499915521010\5 51627127915917687092167406237650393515219559260324 2\2 5407105240521699226468\2 0804407131236894459708057895581383748532688\9 57306177127663437989652061543375024588556754022655 67005204869531\1 85534617515679000022370901717496890\7 10607068279682496659269206521586465266960354655802 678595\8 443040808713152759751727705\1 127325855598636263273573581508742271836277078816\ 1 7561193416036716068338050687896497262817\3 48732853523562982894678902315041114717891364389153 40879104307\5 67178735028905420900132243187479\0 79592381383492071110051130421024618450755967374685 544\8 702307030996135069128441\9 182200854953992314688245441474613701996217546\3 27472233807126070028595128644350019390827244796478 6082275784375443\3 4436429039554160779162279216017013979\9 22398184203064597253041051350729744958331598358388 49810728\1 85534847231992763058516460422\2 86015341581659352989195485499450093664295244850865 \3 900532227272489618189\6 196275372732158965758508205361297895262683\3 55898285452582243255540080454629771926265414616937 4171333710442\6 7793549524780766981914688852642598\7 35432611230972515961346897209626909943320763464868 31671\7 36264649176978751651725826\6 74035724337920059542677068166580801305671078201\ 8 795547018918038545\8 911986946447340641850404191496369062385\8 27566191222967881917338629343523355459221919678344 0557750543\3 0625721251024692947430980823358\9 45080575935016746312853929413572292771967511250010 50\6 94540551359121655107039\3 29622140099102546407738247996394642581877728\1 67283793163613123591568072661720163463920607593340 222250489950129\0 840992463472856434470933957905564051\5 43218192455803214193068714650208345880479586438733 8831012\2 1526293284116452365835018119\6 0066247707121872748590742816819636582392077995656\ 7 86385174135693531693\2 05418114539950888177105763502704195616064\9 32635559768064705050854392901382288483044906358936 363123593283\5 299795610423202669728726541457385\0 87771100050432709063884587952928887687236347976988 2784\7 3093942912835417401716034\3 6755677479183987687525896864016157864427287829\
7 63820367842580394107142773031049464071963786359235 54989937940264791\2 14120847199443368103126438306917127504\1 98687570291225533801983985392267146411109569259403 344581383\6 274641741937758594269476884892\7 25425041886089524896543986753701312431586053634831 7\5 2072258010416417753538\4 0579199876184299159028481985769645485459745\1 91320299174279770727457889779594067077535196596833 31745655526100\0 89760864326848949667017593063598666\4 14076899857760549225913768331342576559165022521542 094692\1 838988533244468899085220111\6 269840593065044992229435666410152220627204843008\ 1 7783614902272782585283696789152490883370\7 82824505101616030872270652259396107321970542690045 16902956655\7 84607029560233935600810863190890\1 61696006598325344413764076795857835698796668161242 564\7 657209833522612080517964\0 145136455214456268535389449303448277625360759\3 65278929651241061577725862365146084048471984904643 5630642771858974\9 5419506941267688204544462147244537396\9 95287987181973578662556481792582396034970401303575 83096420\9 65962686991383113964186010535\7 13079500949263052765935023304596912872902911642697 \2 947242858305211598305\9 813765680749405643169694250818153517301293\8 40816410701139029679802821513808078167590723778214 0377463055642\7 2211618618600409543685419678101442\5 39963734469474261695074004549051028365369452497983 06396\9 62751436850660969300403601\1 82615685220671594845121670589507947929740400021\ 8 948516950483114474\5 269264064708007272364747767520484303826\0 17063931629351990335881284515187350479093586243540 7780426010\8 2239744286037176855814120378901\9 80969508903159918385310581529775852909381758476376 78\2 31089106837099546598965\9 72815695898866291651263458076673943274640382\1 61801006978259996643236989918722450738690545733062 808720202390837\2 194498649111343705401578533103072896\6 02318367494306667039254994908130600362623455671084 6457438\0 5328882727952390012293701503\0 7296485883254066274351218046158684815172679597438\ 9 44447902287535787250\8 50776621282862593310968602235924287507820\8 49436224438481768905657870977321746136398741932608 450483371716\7 040121705850513959943009636337536\2 91972609401446865876494590652270682706711105761960 4777\4 6036944654299941802956216\3 8870068674559784136578573070159652559596939730\
6 86507327720797402259536672845996484293935365095571 11272775550933173\2 41702164072927257769112370301531756705\7 60041674899279490593605352271256849996683523692754 716082046\7 674716662977971456534017227824\4 01969240795672758386908207374832022885696910966079 2\0 3960470877804587264622\7 3654893795114016566370541684111404523969308\9 01600587047680831356924319360578450298300189568596 09617517104431\4 90714447739259220055650108945124098\2 69244468587162773129999441054675429358516218797655 598612\3 545435644061488298667107960\8 704380316520524480194226460005140491883808412458\ 2 2326168572677061610012675337898573974984\4 31674036200859178971136158209705752910143797212097 46524363771\1 82349812280284862925432567764055\1 02523321576473712066579816625563015856670411214523 317\7 779331403228246292368252\4 403839271741245078677012665280694246266147662\9 47636400253716974920737516111143946802045490
Copyright 1991-1994, 1997, 1998, 2000 Free Software Foundation, Inc.
This is free software with ABSOLUTELY NO WARRANTY.
For details type `warranty'.
scale=25000
sqrt(sqrt(2))
1.189207
4666682269171598707813445381376737160
7756785360862538
087105038499725591050098371044920154845735674
795908038489658843005041
378
79824408022800821729272058615366
88873345762
0054131455143891998743766762178516178317
5371569868426364827
9964594007561544437157418903039869712943062486253 5173412915359753112\
154467461590864776065174459
475333
41846497924890995156337829985950876
61861396145218
4853154452663650494401971033761795345642476
5103651810774498212513
6
529159414395971379484218025872
612204691
14922143214985729797309216961229956894
90116842040036569
1088669512833451521516512921024113577318717078
7480547695612873957585974
0355
912658706024685775133767337382085
129492855151
10813677553477191243857364102424525609526
54240696065868240146
1091704856341716742050743352838370798943416431872
6034811959546478552228509325
4459077
376868660758271483607797981278170134
610695977256616
29240243490299127918280955457432198824746262
34648431605080864723750
27
0395893093420019844118075464024
3296195508
347293639532226607004681869405648218923
894864610871744989
49586601769276446907559083505115632527985192933
87937511309653200513861754
28035
9295963247353738450703896140263369
8094622109053
788961412162544015804408135424944600429810
271885909662428444119
47905077351940138554325964625
70662738
3201254695930154553168455132028378926
9650486600923646
574625823972753928944029906308773505068370959
671527213007113884995529
387
85653156258189148607859831372945
29490420195
1521684419035654997183118718674853083712
5569225112550407643
4461217350920360555949201791349627768734464380522 0391077348871020186\
529404051161888260339507320
165025
89846479950987799909706403594875873
97511312128937
8288866893429529276288434494666500845121032
6149994993015874120501
5
970012513431671240422772712469
138120796
78832867616644851926539641386183509365
84027865199435455
3950241815596444706960198554736720186973919878
9472741238535902671155089
5431
938112970686953766682521100705616
525111360721
25607226140458321600304157616549591997258
71578647643524744588
9992351528711442721834322690132215086741293167675
3360486423423646043122141177
6598839
931011392856235219424799356522470104
283534165070476
72173189400825477835096595194598369444647698
92893973390714794754621
81
5798642521194891771832796580313
7019835138
396438123725431235571228115938602547594
601311944343572803
28951287776947286419746697515705219090750999724
33117930336414606441304861
69285
7245678011913211674817181208679453
1003242055300
413293491205770458919320923507437090168324
710699620626232080913
58938467108807131326346297064
54480469
2296435578685484260432279239537315844
8457325863876352
717831439050314225047294320609699306178942793
747686970997110532718322
438
86890794356797954175364867432060
86530619784
8529963499854894750750622864880801467004
7606302396820667305
8708317051650141705471352516973036066892644752880 2773332642829840841\
397874622448744253890223039
544404
79103859443128802280625260342482817
46295016148026
4301050659018983245228783171383429144944759
2562600937441770291627
0
209023143617962725677220078834
845466644
18202894713567240853660261338560585335
70948865169699735
4886729393594006292052635704886673478408728728
6693599498654052656759762
1658
214874636319902569125436198302782
799841686358
14728018627407012023324233931806128980146
87253821476888549944
2938267412196983348359006139110311098217069606555
5651376825306273561894281587
9007790
654941447045343427897315989044730950
211589738741142
13335175757296877530634279268831649367686608
60570090835335387347317
06
0804144659644040919024943673270
6306513951
426811927475780501152371310604490489825
146661932221567582
90325542600905573247062532985027948698045113264
24797745024119003891746454
91955
4408160914159678858358881829997137
1579848754707
178130300799078030534135193145856808696898
868120054900711447215
86708646661874313658030184278
14576009
4588689387439992334440639483964505655
9558985159830123
031266435300376719055066900951302875471504007
332830716932017567115257
320
49235873881798694156075319259385
19938951696
0408939314199280372494983004791503665057
4270410430167671147
5089070494566556725672241632055195666134133258497 4520609714431257697\
985690348694707560126440341
412266
17268389137137224259864529149171915
30958642556430
7371180847922457376660752567386036648373540
6459851669366628201010
6
629174070963679997831905697646
281731135
36759528286014314060532046893549945981
10200082037890435
3413334131829118035740773443588810569508050179
5681350369009329150495888
1007
737808928149252148742951831579802
288149146360
09915760050256146418035965575290981752620
42530290939427806036
3425515491391253108929305070141011352797035519630
0896063843285732846306383975
0179727
215888337834669447377300572694656833
799819346071682
16055381688098044234138884656108381905358654
12553992354117206554015
10
3624871201845442193917293460851
0550414752
112143322015861035646795598857664548726
112959403519142242
00316490378267719226622177183448113443976476141
05605254228348035671740280
66891
6268850523683874358490055208730538
8037177955446
603753961968765587031910807862133809188547
546146610395483676291
52681637539825714915099962417
15354304
2230500822528539343496521724104692615
8370473419776477
530792858045480979910814208044538581342309483
255181810431074476867078
738
38772546789357398147474907443961
83229871679
8867564302719688595560617915014299943912
9803833034529436722
2764099581329188509959586138800668241222334130855 7373264049781906203\
532427124386988207294032357
298020
09686070755005841237521487039638550
18004011975898
5862507813884308371732930878753868323292493
1814671171154768972730
2
488311105195401948238744083044
298577048
56483384261962979292339587265139823714
54996061237201000
8354937084958656861568242937229140402753410418
8731200417019114881032106
3573
485001893322313896429010100972132
523997336764
00119382567432979484369520995742747768178
18505566116801445832
3128285429293165766859886258767381331109384702079
2569765210018763626345619634
7244397
074670712553268526060911738759179635
902257544776433
44111181720478585921497978701855082502982678
04492152600849334778291
68
5906754815811161230177852158229
9678178237
303572211449762258186021821271489217957
296912559240686728
37557568627412816078474301298789256944868162422
48144044229021666836555851
85808
6328500884889984690891037674342484
3649216553887
987473105442457938390515847546383895283953
132516974509373946253
72307245619925029013063654168
00164339
4352796814747099632738162529499967151
5666567162589463
993325432011442297363987920074319004181318141
232067376641938583013069
518
88851569813032701095284233112720
34086680110
2273675734469115207879680817622376662061
5969794627474760542
5154683184296981930317827498691998550471293220241 7419120239936309491\
357977823317734152128844705
064167
30830666627116525346046749308992917
44166732312017
2280463871768964472874666010107339266365558
8484420269275608238536
2
504266215744659848556825545706
302327573
03003905073170238914282135152171156253
88926538469220297
2343738900112727809556370590434372256730805825
4035740491678765199948076
5561
437929509269157473580179323160943
905240460213
40420350801776893787026187437338246937535
78598732853654653235
0202956468170971066701888025931680902237824021530
6488228982399440713796005160
7413118
093703509141655261211478711007843992
184986368659375
48606922557142512214928624308971188134431606
62491204903692261020392
02
2429388031627809958518302191612
8996087405
534742889570526227494641768636904146540
147581339681400669
11072173127972140003112841992536724585576507352
83704574412079369617711120
57443
8176295434406045583245536197065210
8252617440420
024830670500126744172641019237996768491810
292060824116604960825
79852874275869833474826591442
26386753
8410317180274936507410313163007916991
7534793412668000
283803191348392884319784194787363251952289912
466759005289272922111168
830
40640959831078007899134158871230
83933590585
2587517067624963228155393471445852350533
7255457643149740597
7083150429304701488627710631153872450345174910361 0500409516265557016\
179612251443467546514298620
759169
59007074245056656668704089142336216
37077828322084
8284874306283556544977734476483770521516964
4744473763014339502561
8
655931322491870081420926216553
815553457
43972072016007882006755111011992014398
34884301217323037
2247712291250935568519269474090406658515389984
9839774605615606696204003
5284
116519610713509816350003487820910
280367200572
00589867297325550476015098069326406123806
09854425265402866578
0587266943529596967751054019697088052980814851988
0386468342766108740748141724
5489143
734303727156594840911282053465004709
922201050704833
92504943300928061373971192585028648767696786
11024067028934934043107
16
5107144932634875628852673191362
4940857611
002853710353063822546114793414010963985
344610168715855453
78080435263336255379066543330179437920861205200
46890484633648376080241462
32964
5458939957110320121802749242100450
7875120034195
666759150309749122048313467867389802589273
829123517318811690402
61280401912402692247889288666
63568843
9405239083176500988474643555498881722
7656101012962742
029370129722906032641459442578089244057880999
865126088042570745751141
343
50264794842565421850664123615776
62708600217
2732248364343686043934948389272112986021
9006096410820495424
4210091228541316390607397113586392276861032721946 3423807114131680987\
843772599344019862424158306
262848
12683702995969189062930137849621117
53209614929441
5584742711054160053811907966742236119212090
4596066698936313729815
5
I know what you mean. You'd think that this piece were copied from something Glenn Reynolds wrote or something.
Here is a link to a text-only version of the article.
Article
Its effective.. as stupid as that sounds, if it wasnt they would not be wasting $$ on it.
Id love to see the types that do fall for spam, but they must be out there.. somewhere..
---- Booth was a patriot ----
I've been using Cloudmark's SpamNet for the past few months and it's been working quite well.
The smart thing that SpamNet does, is that it relies on its users to determine if something is spam or not. If some email lands in your inbox and a few hundred SpamNet members have proclaimed it spam, it most likely is, and it gets immediatly filtered out. This has the net effect of a few user's needing to filter out a few message ocassionally, while the vast majority of messages are filtered out for all users. Although SpamAssassin seems quite good, it's still based upon filtering rules and spammers are constantly tweaking their emails to try to get around them. Since people are still better at determining what's spam and what's not, I find that its accuracy is generally better.
SpamNet isn't perfect though, as far as I know, it only works with Outlook on Windows and doesn't have a Unix, Linux or Mac version. It also sometimes filters out valid bulk mailings, but overall, I would definitely recommend it.
I should be able to ask Hotmail (or whoever) "I have message #xyz from your domain. Does it originate from a user in good standing?" If the ISP gets too many queries for an individual account, it will stop vouching for it.
Likewise, you need a database of "ISP's in good standing". I.e., who is known to play by the rules with MSSMTP?
Verification would serious server resources, but better that than spam.
-mse
Who steals my .sig, steals trash.
Fiat Lux.
SpamAssassin's a great idea, but for the non-technically minded user, POPFile's the best choice. Bayesian filters, learning, kickass UI, and a Windows installer (and Perl for other platforms.)
>>1) forged headers should be illegal 2) a specific header entry should identify the email as unsolicited
Don't we ever learn from the past? We've all seen the unintended consequences of poorly-crafted legislation (e.g. DMCA), so why run to the shelter of more restrictions which, in the end, will only cause us more problems? Like the criminals trying to scam your mom with the Nigerian-hold-my-money-for-a-day scam are going to suddenly begin obeying the law... yeah, right. Which begs another question: what law, in what jurisdiction? Even if the US were to pass this law and ruthlessly enforce it (domestically), all scammers would simple flood us from offshore servers.
The solution is not legislation, it is the creative use of technology. Build software that "learns" what is spam and what isn't, then evolves to keep up with the changing tactics of the spammers. Something like PopFile
I own a domain and so can give each site a different email address (foo@mydomain, bar@mydomain, fum@mydomain, etc.) so that I can tell if they squeal. I get the NYT's very nice daily headline summaries, so they certainly know how to reach me. In eight years I have not seen even one spam with the nytimes email. I wish I could say the same of others....
:)
Granted there is always the risk that they could be hacked, as their main page was some time agi, but what's life without risk?
The only headers that should be preserved are perhaps the Received: lines which show that route that the message has taken. Still, I can think of a legitimate reason to muck with these - if a company network has a sufficiently complicated internal structure, these headers might reveal some information that they don't want widely available.
Hi, :) :(
I said that here once (I think). Instead of
simply filtering out the spam -- which cannot
be a permanent solution from general conside-
rations, since spammers are adaptive too --
act against it. Send them a false credit card
number with some made-up name. People say that
thus one may cause trouble to someone innocent.
The chances are practically zero, methinks.
If many people do that, the spammers will be
flooded and drowned. It is a PITA to do it
manually, but surely there must be a way to
automate it mozilla ?
.
If they advertise web-pages, DOS them with
continuous downloads. Actually, I do this
once in a while with wget. Again, one person
doing it can contribute nothing, but many
ones CAN. If 1% of the "victims" download
each a 10 000 copies of the page, the spammer
will pay for bandwidth more than the eventual
profit from gullible fools will be. And the
spammer can do practically nothing against
a multitude doing this. This approach is
scriptable.
.
Finally, there are the spammers that do not
give any web forms or pages. I got such one
today, from the last dictator of Congo's son
The pro-active defense does not work then
.
It seems that the real final solution will be
not what I describe here, but creating subnets
of trust that reject email from the outside
unconditionally.
Go figure.
Is this thing on? Hello?
what he is saying is like requiring gun manufacturers to come up technical solution to prevent guns being used to murder people instead of just making murder illegal. the author of that comment is just making broad, pandering statements about the power of technology and how smart we all are. he isn't proposing a solution. he is not saying how it would be phased in. it's just worthless anti-government grand standing.
Gliek's is the best anti-spam article I've seen. I read this article yesterday and then emailed David Price, my Rep, and John Edwards, my Senator, urging them to support national prohibitions or regulations of spam. I urge you to do the same. Politicians bow to pressure. Apply enough citizen pressure and you can overcome even lobbyists.
I am not an expert on much, but I have written servers of various kinds and have some understand of SMTP and networks. Corrections to my naivite are welcome :-)
Seems to me that the problem could be self correcting if there were no forged headers. If spam could always be traced back to its originator, or to a bad relay who accepted forged headers, then only 1% of the recipients would have to reply to flood the miscreant's mailbox.
So why is it not possible to prevent forged headers? Why can't SMTP relays reject mail whose most recent Received-From: header does not match the the sender? As long as you can trace these backwards, at some point you will hit a forged header or the originator. If the header is forged, that means the the next relay did not verify headers, and is a worthy target of complaints about spam, as good as the originator, in fact.
If only 10% of SMTP relays and ISPs enforce this, that would seem to me enough to flood spammers with complaints.
Why would this not work? Worst I can see is it would take a few months to become widespread enough to have an effect, and early adopters would have a slight processing overhead increase, due to having to check for forged Received-From: headers.
Infuriate left and right
>>2) a specific header entry should identify the email as unsolicited
I can see some problems with this. If I send a message to my mother out of the blue is that unsolicited?
I haven't read the article (I don't like the NYT and avoid it when I can) but I'm sure the idea is that this applies to commercial email, but that's a dangerous distinction to make if you ask me.
1. Spend 10 bucks, buy a domain name (eg xyz.com).
2. Set up a few email aliases to point to your real email. eg:
joe@xyz.com ---> you@hotmail.com
temp123@xyz.com ---> you@hotmail.com
spam123@xyz.com ---> you@hotmail.com 3. Never give out 'joe@xyz.com' to anyone except friends/family.
4. Use the other emails for signing up for things on the web or in usenet.
5. When you get your first spam addressed to 'temporary21@xyz.com', delete the email address (no more spam from that source!).
I find this method works extremely well. By using aliases in this way you effectively hide your real mailbox. Even if your hotmail account starts receiving spam you can just get a new one and point your aliases at it. Also, if you change ISP you don't need to change your email address.
If you use it to forward to a hotmail account it might be better if the hotmail account name isn't a dictionary word or name (ie. use a random string for an account name that the 'bots won't guess.
You're screwed if your 'trusted' address gets out there but if you're careful you'll at least get much more use out of it before needing to kill it.
Is this the same James Gleick that wrote Chaos: Making a New Science?
Well, it has never been successfully tested.
The most important Q, if gov't help is going to mean anything.
Enforcement is currently a state problem, for the dozen or so states that have antispam laws. Even if they can establish jurisdiction, they have to locate the offender. An asst. attorney general I chatted with in Washington state described an almost comic crusade to get ONE spammer who set up under a different corporate name every week. They used three private investigators to track him (successfully), suggesting to me their investigatory resources were limited. Anyway, they couldn't afford to do this with everyone, and this one example was located in-state!
I was surprised the author didn't really talk about state laws at all. They're kind of the laboratories for the eventual federal effort, and state law/enforcement will be complementary.
Once there is a law on the books the "cyber" aspect of it is only as issue for tracking. Postal mail and telephone calls have "no physical boundaries," too, and actually it is the crossing of state lines taht is an obvious source of federal jurisdiction. The rest is standard law enforcement. The FTC, which the author briefly visited, was busy enough with outright fraud, where it already has jurisdiction, just as it does over fraudulent TV ads and newspaper ads and product labeling and so on. I can say that I've seen some very good work by the FTC, even leading to jail terms for the guys who just won't give up. (The jail term I saw was for criminal contempt of court.)
I think they're going to need to provide a private enforcement action, as with the fax law. The gov't resources would still be needed to track down and prosecute the really tough ones, such as the WA case I described. We already have some relevant experience from the anti-junk fax law.
Recognizing spam -- good Q. I don't have any trouble recognizing 99% of it. For teh false positives, it should be possibly to allow the merchant to provide evidence of opt-in, and if enough complaints are tallied there would be further action.
Seems to me that the problem could be self correcting if there were no forged headers.
So the headers trace back to a fly-by-night ISP in Gangdong-gu, Korea. What are you going to do about it?
Why can't SMTP relays reject mail whose most recent Received-From: header does not match the the sender?
Because some people use services like pobox.com which forward incoming mail but must use their ISP's mail server to send mail. Your proposed solution would put that useful service, and many like it, out of business. (No, you can't trust reply-to headers to work. Many packages wrongly reply to the purported from: address rather than the reply-to.)
The big problem I have now, new in the last two months or so, is that many of the spams are now uuencoded text bodies... so the filters don't work on them. They are reconstituted by the client (Eudora in my case), after passing through the filters.
Unfortunately the filters (e.g. Spam Weasel, Eudora,etc.) don't have an "automatically reject if no text components" option.
Can you provide evidence of opt-in really? Some company maybe have purchased a list, but where does that list come from originally? It goes beyond just who is sending the e-mail, right?
Change to something like IM2000 (http://cr.yp.to/im2000.html), spam vanishes in a poof. Keep around with the current broken system, and we'll have ever more draconian laws in ever more futile attempts to suppress it.
Check out an online service called SpamArrest.
For about $20, you route your incoming domain email through their whitelist email servers. Anyone who's not on the list is automatically sent an email with a link for people who want to be added to the whitelist. The link takes you to a page where you have to type in a word that you see on the page (the word is in a graphic and is partially obscurred to twart spammer countermeasures).
Of course, a spammer could just click on the link and add his name, but is he going to do that for all 60,000 emails he just sent out? Probably not.
Can't one of the karma-whores post the full article?
Come on, I know we won't slashdot it but I am just
too lazy and paranoid to register
and switch on cookies in my browser.
Yeah, bitches... Andre-3K here. Got the dual boot action going on. Ya'll can't harm me. Ya'll cain't HARM me. It's over.
Humble as a mumble in the jungle of shouts and screams... Guess I'll hafta reroute my dreams.
Peaskie-weeskie.
O
U
T
K
A
S
T
There are also philosophical problems with such a scheme which others can explain...
Any sufficiently advanced technology is indistinguishable from a rigged demo
--Andy Finkel (J. Klass?)
Okay, switch to plan B. We don't just call it illegal, we call spamming a "terrorist activity." If the spammers don't stop, we shall make war on their routers, launch cruise missiles against their ISPs, and freeze the financial assets of known spammer cells.
Just once, just ONCE I'd like to see the constant erosion of personal liberties work in MY favor!
You want the truthiness? You can't handle the truthiness!
For what it's worth, an ever-so-slightly longer version, lacking a few bits of Times editing, is posted here, at my own site. And may I say how helpful and fascinating the many Slashdot discussions of this subject have been?
Spam is a technical problem, so why can't we come up with a technical solution?
...
I don't know, why can't "we"? "We"'ve been trying for nearly a decade, and haven't made the slightest dent in the onslaught.
Note that post-delivery filtering ignores the main problem of spam -- the cost to the ISPs and mailhosts, who need bigger pipes and bigger servers to deal with the massive loads of incoming spam. The cost of these pipes and servers is, of course, passed along to us, the customers.
For example, it should be impossible to forge headers
Sure, we'll just design new protocols, get everyone in the world to agree on them, create implementations, debug them, and then deploy them everywhere. That should only take, oh, say, a few more decades!
Why rely on a legal solution
Who said anything about relying on it? What's wrong with a multi-pronged attack? Technical solutions have (so far) got us nowhere. Surely it can't hurt (much) to try some other approaches.
Furthermore, spam is not entirely a technical problem. It's also a social problem. Many (possibly most) spammers refuse to admit that what they're doing is wrong. After all (they argue), if it were wrong, surely it would be illegal? So, making it illegal will completely undermine that argument.
the people who have brought us such brilliant solutions as the DMCA
And the people who brought us laws against dueling and slavery and junk faxes. Yeah, not all laws are perfect, and many lawmakers are stupid or corrupt. But to go from that to "we shouldn't have any laws" is just silly.
If we can pull it off.
With Bind 9, we finally have a decent, working implementation of DNSSEC. This will allow for a new breed of secure, verified websites and email, and (Finally!) makes a RBL actually mean something.
How's that you ask?
Well, one of the biggest problems with SPAM is the forged header, open relay issue. It's a complicated issue, and one that doesn't have an obvious, "in your face" kind of answer.
DNS is designed to tell you where to go, and SSL/Certs make sure that you got there. Why aren't they joined together? The fact that you are the DNS server for a domain makes it clear and obvious that you are an authoritative designator for where you are supposed to go - why have this wholy separate and dis-jointed SSL/Cert that can't even be made to work consistently?
If an ISP can issue DNS-SEC certs with impunity, we might actually see a reason to have encrypted and ISP certified email.
And suddenly, the ISP is back in charge again, able to validate every email going out as coming from one of it's customers. Revoke the cert and their email becomes unreadable.
Now, we have an email system with a powerful mechanism built in that is:
1) Standards compliant
2) Easy to implement
3) Clearly laid out
4) Cheap
5) secure
6) private - using the ISP's cert to identify yourself doesn't mean that the ISP can read your email! (like they can now - the command is "mail -u _username_")
What's not to argue with? The issue of locking down an open relay becomes a non-issue - an ISP could simply identify an "s-mail" server (secure mail) that will only relay for those holding a valid cert at that ISP.
Roaming wouldn't be an issue, nor would open relays or forged headers.
A brave new world? Yep. One I'd like to live in? Yep. One that's coming? We can only hope...
I have no problem with your religion until you decide it's reason to deprive others of the truth.
Why is this in the NYT magazine and not the front page of the NYT. Perhaps /. readers should be emailing (or snailmailing, or faxing) NYT to get this on the front-page. Something that costs ISPs billions(?) of dollars per year would be extremely relevant to the readership of the NYT.
I'm a stereotypist.. if all the previous comments this guy made got a -1 modpoint, why should this one be any brighter?
I have no problem with registering. It's when it expires in a short amount of time, and you have to reregister. Lather, rinse, repeat.
That fly by night ISP must get its internet connection from somewhere. And it isn't as easy to set up a fly by night ISP as a fly by night account on an ISP.
I must need education on pobox.com. If they originate the first Received-From: header, isn't that good enough? It's either a valid connection from one of their customers or it isn't. Are you saying that because the Received-From: header is not a valid To: address, the scheme wouldn't work? I am not thinking of the SMTP relay replying to the email, never, only verifying the chain of Received-From: headers and rejecting a relay if the most recent is wrong. I know you can't rely on headers in general, they can all be forged, and you can send mail without any headers, or at least very few. But the Received-From: header check would still fail if the most recent was forged. And all you have to do is reject email if the latest one is forged. Nothing to do with replying. Now if a recipient doesn't like the email, he can always complain to the oldest (or oldest valid) Received-From: header, whether or not that is the riginator or the originator's ISP. And if 1% of the recipeinets do, ISPs will be much mre careful about signing up fly by night accounts.
Infuriate left and right
If you use MS Outlook (we are forced to at work), try out Spammunition. It's a free Bayesian spam filter that's integrated right into Outlook. Works really well. No spam problems any more. This bayesian approach really works.
Well, I just finished perusing the article, and I partially disagree with Gleick. His proposed two-part solution is:
a ve-been-a-long-time-ago.com.
;)
1) Forging Internet headers should be made illegal. The system depends on accurate information about senders and servers and relays; no one needs a right to falsify this information.
2) Unsolicited bulk mail should carry a mandatory tag. That alone would put consumers back in control; all the complex technological challenge of identifying the spam would vanish.
First, I don't think part 1 will really help. Sure, it would be nice if all email contained accurate headers, but I think he's specifically referring to the headers that document the path the email took to reach a victim's inbox. The problem is that, as long as spammers continue to forge headers, they can evade prosecution. It's like saying that bank robbers should not be allowed to wear ski masks while committing the crime. Sure, tellers can still remember the approximate height/weight/build of the robber, and might even be able to get a peek at the getaway car, but such a law would only increase penalties for spammers that are identified and prosecuted, not make indentifying and prosecuting them easier. And that's what part 1 is really for -- identifying and prosecuting spammers who violate part 2.
I don't think that will work either. Of course, I would have supported part 2 at least before I read the article, but Gleick makes some interesting comments with regards to licensing agreements. What about all the people that go to web sites, fill out forms (a la NY Times), and click "I agree" to get access to the content they wanted in the first place? MS uses licensing agreements for critical updates to give them the legal right to access any windows user's machine and delete programs they don't like. There's no reason to believe that web sites (or other entities) wouldn't use "terms of service" agreements to get "permission" from web users to send commercial email.
If part 2 were implemented, all internet users would get (in addition to the forged headers we receive now) would be a bunch of emails without the UCE flag claiming that we signed up to get the email when we clicked "I Agree" at i-dont-remember-visiting-this-site-but-it-could-h
Here's another idea:
1. Contact and educate sysadmins who run email servers that are spam-friendly. To qualify as "spam-unfriendly", an email server must add a header to every message passing through with the IP address of the machine from which it received the email. If every mail server were "spam-unfriendly", recipients would be able to positively identify the IP address of a given emal, and the ISP in turn would be able to identify the person who sent the email (if the need were there).
2. Create a double opt-in/opt-out system. That is, in order for one person to legally send a commercial email message to another person, the recipient must have _opted in_ to receive that message. In addition, anyone may _opt out_ of future messages at any time. This would protect those who accidentally opted in to receiving spam by clicking "I Agree" on a web site by letting them undo their mistakes.
Of course, this system would never work. At its core, every system for combating spam is based on making either the act of spamming or employing someone to spam less profitable. This scheme, along with many others, rely upon US law to do this by associating a legal, financial penalty to bothering people with spam. Spammers can evade the system by going off-shore and continuing their business.
One system that I think has a lot of promise is creating a mail client that sends 50KB (or more) of data to every web site mentioned in an email that the user marks as spam. If everyone were to use such a client, spammers would effectively end up DDoSing their own e-commerce site. Performing the act that bothers so many people (sending out batch emails when 99%+ of the target audience is not interested) would be directly and unbreakably bound to suffering a denial of service attack thus preventing the less than 1% of victims who end up responding from being able to make a purchase. In a system like this, spammers have two options:
1. Send "spam" only to those people who they have a good reason to believe would be interested.
2. Give up.
I'll deal with two possible objections right now:
Well, if everybody used a spam filter like spamassassin, spamming would become unprofitable and spammers would stop. Also, ISPs networks wouldn't be taxed by all that extra traffic being sent.
Nope. Spamassassin is good for now, but its fundamental effectiveness relies upon there being detectable differences between spams and legitimate emails. For example, the email:
Hey dude, what's up? How was the boating trip? Hey, I know you've been shopping around for DVD players lately, and I saw a sale on them over at amazon.com. You should check it out -- they have some awesome deals on multi-disc boxes.
could be from a legitimate source. It could also be a spam. If you can't categorize this email, how can you expect a computer to do it?
As for the end effect on ISPs networks, there's not much that could be done about that as far as I can see, since the whole system is based on using all of the bandwidth available to the spammer's (or the spammer's client's) web site, or at least using enough of it to cost them a bundle.
Could malicious users take advantage of this system to lauch DDoS attacks against innocent web sites? In other words, doesn't it provide black hats with 100:1 bandwidth multiplication (1/2KB email results in 50KB directed at the target web site)?
Yes, yes it does. This is the only reason why I think the system, as described, shouldn't be implemented. I've thought of various ways around that (e.g. combining the spam-unfriendly email server concept with this system so that spam-friendly email servers (if there are any in the message path) or the spammers themselves take the beating, or limiting the maximum 'punishment payload' size to the size of the spam to prevent bandwidth multiplication), but none of them have struck be as being The Best Solution yet.
That doesn't mean I'm going to stop chewing on the problem, though.
No, really. It must be an IE thing.
I've been using Mozilla since forever. I also miss popups, and I put a long list of ad sites in the proxy box.
Besides, I'll just Google for the article. I'm not going to give the terrorist loving bastards at the NYT a hit.
But most importantly of all, we cannot forget that American consumers are responsible for spam. That's right, spam is OUR fault. It is our fault because no matter how many messages are filtered, and no matter how many websites are closed for spam complaints (or get DDoS'd by rampaging slashdotters), they still make money. They make money because of that infinitesimally small group of consumers who buy stuff from spammers. That small percent is what makes it all worth it to them.
The day that spammers' profit margins drop to nil because consumers refuse to buy from spammers is the day that spam vanishes from our inboxes forever. No laws, no filters, no problems.
Unfortunately, as P.T. Barnum would put it, "There's a sucker born every minute..."
At our school, we don't earn a degree when we graduate—we earn pi/180 radians
There are many perfectly reasonable reasons why you would want to provide an alternative to the default value for many SMTP headers. It's when you lie and mislead by using values that *other* ISP's use in their own headers that you are said to have "forged" them. Bogus "Received" headers can be considered "forged headers" as well, as they are not added by the MTA per the SMTP specification, they are crafted by hand to make it *look* like they were added by an MTA.
These are forgeries. Providing alternative (but still "correct") values for some SMTP headers are not.
(Technically, instead of mucking with the From header, you might want to consider adding a Reply-To and/or Errors-To header instead.)
Well, you can already be sued in any place you have a "presance" in, which is interpreted pretty broadly. In other words, just fine the spammers if they're in the US. If they physically leave the country, well, good riddance...
Hi John,
...
I got this from my friend who works at the mall - check this girl, she's hot!
Spam is not a technical problem.
It is generated by the most complex processing system known (The Human brain) and obeys to one of the simplest known principle (or absence thereof: greed).
That's a pretty potent combination.
Certainly not one for a machine to match.
No AI based solution will ever be able to reliably block spam, it's like handwriting recognition: I can't even read my own handwriting sometimes!
Spam is a human problem that has two sides:
- Some nutters will stop at nothing to sell you something (expecially if the numbers look good).
- Some idiots will genuinely think a girl called Sangria has the hots for them - type in your credit card here darling.
Don't worry: if you've read that far, then you're probably not that dumb.
Of course the solution is legal.
Here in the UK, I used to receive a fair amount of junk mail. There is however an opt-out list which I subscribed to and all I get is a few of them a year for the guy who used to live here before me.
So, yes, forged headers should be illegal.
And no, an 'Unsollicited mail' one is not a solution:
Why?
Because of this:
"Hi Tee, I am your long lost cousin in Australia - I found your e-mail on your web page, So good to be in touch again..."
A header that says whether or not the email is advertising is a better idea. If the values of this field follow an agreed classification, you could actually filter IN *voluntarily* things you are genuinely interested in.
The inforcement problem about spam will eventually be resolved. Europe is getting bigger and more integrated, the USA are a big chunk too. Now if these two and, say Japan or Taiwan agreed to block any other network that does not adhere to the guidelines, there will be a lot of pressure from inside those banned countries to make them adopt compatible legislation.
Of course it takes guts (something politicians rarely have), technical awareness (ditto) and time (Well fortunately we have plenty of that - it's only our patience that's running out.)
Check this site it's hot: http://www.aptilis.com/
(Sorry couldn't help...)
Teebo.
All of the Congressmen now carry BlackBerries.
I hope they won't keep ignoring the problem until some Saddam conspires with major (North? :-/ ) Korean spamhouses, e.g. bulk-"un"subscribing the pagers of U.S. government by "opting out" on their behalf as a reprisal for Operation Desert Spam.
is called Faster, and it should be required reading for everybody on the planet.
You cannot apply a technological solution to a sociological problem. (Edwards' Law)
Sounds like Sneakemail.com, which does have additional benefits.
Spamgourmet lets you create disposable email which forward a specific number of emails before disintegrating. And if you get penis enlargement spam at your nytimes.20.yourname@spamgourmet address, you know where it came from.
>> it might be better if the hotmail account
>> name isn't a dictionary word or name (ie.
>> use a random string for an account name that
>> the 'bots won't guess.
Alas, but such a name will be recognized as spam by the spam-spotting-statistical tools and so can only be used to send messages and never used to send a message. For example, buffy0412xxxmeb13mxy@hotmail.com (as Mr. Gleick himself suggests in the NY Times article) is obviously a spammer and is either doomed to be black-holed or deleted by an intended recipient.
Mmm.... Burger....
"the author, James Gleick, is more technically educated than what we've come to expect from the big press."
Maybe because after many years as a reporter, he founded Pipeline, one of the first big ISPs.
I think it would be great if you could actually prosecute someone for forging headers. Unfortunately you don't know who that person is, now do you?
But how would you ever determine is something is unsolicited? After all, there are a lot of registration websites that have a tendency to quietly flag you as willing to accept spam from them. If I missed it, does that still make it UCE? If it does, how do I now remove myself from all the lists that I am now on...
Spam has a solution and it doesn't have to be so drastic as to put in this kind of legislation or use whitelist only maling lists. We just haven't figured it out yet.
No registration needed for this link
A M. html?ex=1045704785&ei=1&en=2560fd607d65a46 1
http://www.nytimes.com/2003/02/09/magazine/09SP
I think that the router should not use this information to shut anybody off. Rather, it should use this information to reorder its routing priority tables. Thus the router will serve its most spam-free peers first, handling the heavy spam forwarders only when it has time. Eventually consumers will leave ISPs with poor throughput, so ISPs will have a much stronger incentive to track down and terminate their members who spam.
I wasn't impressed. I can remain spam free by not giving out my e-mail address on websites or public forms. My main e-mail address is given only to those I trust. All others use a spam@... address. Ah, the joys of owning one's own domain.
I stay spam free with little effort.
Now, if Spam Assassin involved ninja and hence, ninja action being carried out on actual spammers, I'd be damned impressed.
So what was the e-mail with a score of 27?
"Hello, I am a Nigerian prince who is selling XXX-brand diet pills that also have the side effect of enlarging your penis. Also if you forward this email to five other people and tell them to each send you a dollar you can make money fast."
*ducks*
Or you could just have an authentication system implemented systematically as part of the protocol, such as with Spam Interceptor.
Ace
Spam assassinates YOU
He's my freaking personal hero. Mod him up!! (or something).
Well, you should try SpamAssassin 2.50-cvs with the Bayesian filtering.
;)
I have it configured to use AutoWhiteLists, and I had to tweak the scores assigned to the various bayesian filter rules a bit (they didn't have enough weight by default).
Since then, every single mail I've gotten has been correctly identified as either spam or not spam. It is *amazing* how accurate the bayesian filters are. When no other SA rules identify the mail as spam, you still see that the BAYES_90 rule was activated (90% chance the message is spam).
Just don't forget to use sa-learn-spam and sa-learn-nonspam so that the Bayesian filters are more accurate! Luckily, I haven't deleted a single mail (spam or not) since Nov 2001, so SA had a large base of spam to learn from
Just make a local page on your box, load, and forget for a few days. Email might not cost 'em much, but I'm betting they pay for bandwidth for their web sites. And if the site itself isn't spamming, but somebody promoting it is, you can bet that the actual spammer is gonna hear from the web site operator pretty fast so long as you include the entire url.
m l]
m l]
For dialup connections:
[html]
[head]
[meta http-equiv="refresh" content="10"]
[/head]
[frameset cols="100%" rows="*" ]
[frame name="main" src="http://www.spampage.com"]
[/frameset]
[/ht
For broadband connections:
[html]
[head]
[meta http-equiv="refresh" content="1"]
[/head]
[frameset cols="100%" rows="*" ]
[frame name="main" src="http://www.spampage.com"]
[/frameset]
[/ht
Check out where Gleick quotes Feynman on the inherent risk of Shuttle flights. Prescient, that Feynman.
We dont need rules on *how* to send uncolicited mail - anything that is codified like a header that lets all spam be ignored *will* be ignored by spammers who will continue to cloak their identity and do everything they do today.
Stopping spam at the receiving end doesnt prevent it from using storage space and bandwidth that your ISP has to pay for. The only way that does is by stopping it from being sent - with strictly enforced anti-spam policies which ISP's use to disconnect any services to anyone sending spam.
The ONLY rule we need is DONT SEND UNSOLICITED MAIL, and the only way to enforce it is for ISP's to disconnect all services (connectivity, hosting, dns) to anyone found sending spam. And since so far, many ISP's dont seem willing to take such a hardline, and actually enforce their AUP's (maybe they like the money spammers are willing to pay them, the only way to force them to do so is to force them to choose between their spammers and their non-spamming customers - one good way to do that is SPEWS
The only way to stop spam is to make it so no ISP anywhere is willing to sell service to spammers.
as commercial speech, spam isn't entitled to any particular first amendment protection
It doesn't matter if it's entitled to protection or not - it's theft.
The first amendment guarantees the right to say whatever you want - it does not guarantee the right to an audience, or to force people to pay to hear you. (Both of which apply better to spam than "commercial speech.")
The whole "free speech" argument is a red herring.. spam is as deserving of "free speech" as any other type of harrassment - which is to say NONE.
If you're a company and want a good spam solution check out BrightMail, or someone that resells their service. It's not the cheapest, but it REALLY works. No false positives and no overhead.
BrightMail monitors many, many, email addresses for customers and others that they seed. When an email hits a number of those addresses quickly it is forwarded to their NOC. A person looks at it and decides if it is spam. If it is the message is blocked from all other customers. It works very well.
Spam is not about content. Not everyone even agrees what constitutes spam when they are evaluating it based on content, so how can a program or a recipient community do this? What makes mail spam is stuff like sending it unsolicited and in bulk. It won't matter what the content is.
I have signed up with some companies for announcements about their products. While that company may not be spamming, their content could have a lot of the same wording as another company selling similar products, but is sending it to harvested addresses. The latter is spam, but the former is not. How do you tell based on the content?
Tools that evaluate a message based on content are probably going to classify both messages the same way. If they are both classified as spam, then one of them will be "collateral damage". If they are both not classified as spam, then the other will be "leaky pinky". So I still prefer to block spam on the basis of the behaviour of the sender.
now we need to go OSS in diesel cars
IMO, the solution is use both legislation and technology. The legislation needs to target people that send spam, and people that cause it to be sent. It needs be broad enough to catch spammers who use off-shore agents to do their dirty work, and companies who get spammers to do their advertising.
The technology needs to be there because no legislation will stop all of the spam. Even if the legislation was universal across all jurisdictions (not plausible), and strictly enforced everywhere (not plausible), there will still be some people who think they can get away with spamming, or who don't think or care about the consequences.
The legislation needs to be part of the solution because technical solutions have an inherent risk of collateral damage; e.g. email being incorrectly labelled as spam. This is not acceptable for some email users. Furthermore, spammers will continue to be a step ahead of anti-spam technology for the forseeable future. IMO, the only hope is a "intelligent" email agent that does a better job than a good (human) personal assistant.
Paul Ford (http://www.ftrain.com/) suggests "[a]n imperfect alternative to fighting spam which no one will implement, but which would be more satisfying than existing proposals". Basically the idea is for the Spam Filter to reply to each and every spam with a randomly generated fake reply. The full article is at http://ftrain.com/spam_quick_idea.html.
One critical flaw is that routers are Layer 3 ("Network") devices while emails are Layer 7 ("Application") data.
The lowest level you could block an email at is Session (and that's being optimistic), which means it has to be done in software.
Routers have a simple job: encapsulate frames into packets, and forward those packets between networks (that's what the "Inter" in "Internet" refers to) to be assembled into segments. The router itself has no idea what the contents of a given message are; that is verified by Session-level software on the sending and receiving hosts.
Imagine it from the router's point of view: all it knows is that this packet is coming from 100.101.102.103 and going to 65.66.67.68, and that it has a few bytes of data -- the rest of the message may well be forwarded by completely different routers.
In summary, the Network layer is an inappropriate level to attempt to detect spam.
All's true that is mistrusted
If we had free healthcare in the US, and they paid for penis enlargments...NO MORE BIG PENISES BY MAIL!
also if they lowered the age of consent, no more overpriced pictures of IMPORTED LOLITAS!
and if some states got read of their adultery laws, NO MORE LONELY HORNY WIVES!
and if some other states legalized sodomy, NO MORE SLASHDOT!
It's a link to the article without registration ... via the archives (very clever :)
OK, don't shoot them, but maybe conduct a poll. Find out why they are stupid enough to purchase anything offered through an unsolicited commercial e-mail. Find out if they actually believe that anything purchased through an e-mail will increase their penis/breast size, allow them to lose a ridiculous amount of weight, make an impossible amount of money or get the best mortgage rate around.
And then shoot them. A lot.
Please don't humanize the morons around me. It makes me very uncomfortable.
Here's an essay on a proposal for eliminating spam.
In some ways, making forged e-mail headers illegal is both a technical and legal approach to at least part of the problem. I currently use SpamCop and the Open Relay databse to filter my incoming mail. This combination does a reasonable job of fordcing all incoming e-mail to my server to have an unforged header. That is, the mail must actually be from who it says its from and can't have been sent through an open relay. SpamCop does a fairly good job of weeding out the spam that still meets these requirements. Making forged headers illegal would allow every U.S. ISP to do the same without someone saying that not being able to send spam with forged headers violates their right to spam. This setup traps and rejects a spam or two (on average) every day for me.
The only problem is, this is done at my expense (sendmail is so much fun and so intuitive to administer) and at the expense of the people who maintain the SpamCop and ORDB databases. Also, I still get the random loser who gets a list of e-mail addresses and fires off a Nigerian money scam e-mail to me from time to time. Nothing will stop idiots from believing that they can get rich quick from something like this including requiring unforged e-mail addresses. My solution to these is to just forward the e-mail to SpamCop and note in my "personal attachment" that the person sending the e-mail should be prosecuted for fraud and that the originating ISP should also be prosecuted if they don't do enough to stop the problem.
They that can give up essential liberty to obtain a little temporary safety deserve neither safety nor liberty.
Ben
Strange -- I've had the same NYT login since 1994.
In the script I was working on today, users are able to RSVP themselves and friends to an event. The friends then receive an e-mail that appears to be coming from the person who used the script.
This is necessary, because if the e-mail had come from the domain of the person whose site contained the script, either (1) the recipients might not recognize the address and they'd ignore the invitation without reading it, or (2) it would get flagged as spam by some program.
If there's some kind of draconian, DCMA-type law against headers, then simple CGI scripts will land all sorts of people like me in prison. So, if they're going to pass a law, they'd damn well better do it sensibly...or better yet, don't do it at all, because it could never be enforced anyway.
Shame on Google.
When I said
... I meant the Received: header, and my experience has been that the server which adds this header includes the IP addresses of both itself and who sent it. Thus an SMTP server could verify this header when receiving a message. If an SMTP server receives a connection from 1.2.3.4 with a message whose Received: header says 5.6.7.8, then the server would reject the message, possibly logging a non-compliant server.
Why can't SMTP relays reject mail whose most recent Received-From: header does not match the the sender?
My bad
Infuriate left and right
I host a few web sites for friends on my servers residing on my dsl line. I'm learning how to properly run a mail server right now, and am going to be going live with it fairly soon. The mail server will receive email for the web sites, which are in the same ip block, adjacent ip addresses. Some of my friends know how to set up their mail clients to download the email from my server (imap), and some won't know the first thing about it, as they use aol for their internet connectivity.
In both situations, using www.PieceOfMetal.com as one example, and www.WindowBreakersAndInstallers.com as the second example, their customers will be sending them email, to sales@pieceofmetal.com and sales@windowbreakersandinstallers.com. My friends will be downloading to their a)mail clients, or b) their aol account.
Still with me?
Now taking the aol user (window guy) as the first example, he doesn't want anyone to know that he is obviously stunted in the brain for using aol. So when responding to his customer inquiries via email, he doesn't use his aol account as his return address, he uses his sales@windowbreakersandinstallers.com return email address in emails that he replies to.
Is the above action considered a forged email? Would this fall under the jurisdiction of and in violation of any laws already passed regarding "forged"?
If he takes it a step further, and takes out all references to aol in the header, and replaces it with his sales@windowbreakersandinstallers.com email address, an email address which works, and which identifies him, and with this procedure not being used to send anything unsolicited, is this considered "forged"?
I actually used to do the first example above myself some years ago (about 5 or 6 years ago) because I had a working web site that received a lot of traffic, but I couldn't figure out how to get the damn aol info out of the headers. I was able to use the web site email address as a return address though. The web site was hosted at a hosting provider, and with my limited experience at that time, it's what I knew how to do. I was also stuck with the aol account, and didn't have the bucks for a different isp. That was around the time when a pokey ass pentium 1 cost around $2500 (with what was it, 4 mb ram?), and you had to mortgage the house for a couple hundred hours of compuserve.
Overclocking? Back then, the hot shit was the chips that could double/triple a processor, taking a 486/25 to a 486/50, and a 486/33 to a 486/dx100
Now that was overclocking!
The solution is not legislation, it is the creative use of technology. Build software that "learns" what is spam and what isn't, then evolves to keep up with the changing tactics of the spammers.
sure. then the spammers evolve to beat your antispam. then you evolve more, and defeat their anti-anti-spam. after a few cycles, you need a Beowulf cluster to run all the rules and an AI to filter the remains and untag false positives. Then, since spammers are *making money*, they buy TWO beowulf clusters and THREE AIs to beat you...
then, while you are speccing out a new beowulf cluster of beowulf clusters, you realize that you will always lose, because the spammers are making money. In fact, you have already lost, because they are making you spend money too.
what can we do to end this anarchic "whoever has the biggest guns makes the rules" condition? If only we could organize our society, and make rules to improve our lives so we are not at the mercy of the unscrupulous....
sometimes government DOES need to step in and set limits on massively unwanted behavior.
Better idea: ditch SMTP/POP protocols in favour of new systems which makes spam advertising less cost-effective. For example, instead of forwarding all email to recipient, how about a protocol that stores the message on the sender's box and forwards only a "you've got mail" header? Spammers would then have to store billions of messages on their own systems or use up CPU resources to create on-the-fly content. Best of all, the sender's address could never be forged or else the recipient wouldn't be able to receive the content.
I have being using an e-mail address for months without recieving a single unsolicitated e-mail, until I signed up for the Motley fool and I get a advertisement for a printer which has no reply address. Any one have similar problems with dealing with Motley fool?
Assuming that'll never happen ('illegal' never stopped a spammer, and they'd never comply with a suicide-tag), an easier way would surely be to provide header analysis in email clients, or mail servers, or both.
If I (as a user or mail server admin) could detect (a la Spamcop) forged or rewritten headers and discard/bounce those messages as fake, most of the immediate problem is addressed. Why don't mail clients/servers offer this out of the box?
That step achieved, those messages from non-forged addresses can be filtered and, if spam, automatically actioned with the source ISP - that should be the role of anti-spam software, IMHO.
See Also: SneakeMail
This ought to be something an individual user could set up without much work : just delete all email that does not contain a keyword from a list of keywords. So work related email must contain the name of the 'fizzy-pop' project, mail from friends contains some other keyword, perhaps their name. Everything else gets sent back to the sender with an explanation. This would make it just about impossible for a person unknown to you to send you any email at all.
At the college I graduated from (And a number of others, I know Columbia University uses a similar system), you are assigned a netID. Your netID consists of your initials and then a number. (For example, mine was atd7. If you have a common set of initials, the number can be in the 50s or higher.)
Needless to say, the address namespace at school has in the past year or two been the victim of brute-force dictionary-based attacks on our namespace.
The moment one of these emails doesn't bounce, BOOM. Your email is valid and the spam starts rolling in.
retrorocket.o not found, launch anyway?
To stop spam will require doing things which are illegal in every country and repugnant to anyone with a conscience. The penalty for sending spam must become so horrifying (for the spammer, personally) that he or she just wouldn't dare. "Civilized" western societies are incapable of this kind of retribution, prefering to play with legislation or technical non-solutions, so we drown in spam, laws against it, and expensive solutions which claim to, but don't, eliminate it.
The Russians have won. They have made the world a cesspool of distrust, greed, fear and hate.
Suppose we pass a law that make forging Received or From headers illegal, and makes it illegal to send a message that is substantially similar to 50 or more people, but requires that at least 50 people receiving the message complain to the FCC in order for any prosecution to occur. With such a law in place, it would actually help to have people forward spam to the FCC. They could collect those messages and work to prosecute people who send spam.
I like the idea, but I don't think this method would work. Law enforcement would have to trust spammers to not munge the headers in order to give investigators the ability to track down and prosecute violators.
Your post gave me another idea, though. What if, in addition to legally mandating bulk mail tags and correct headers, the government were to set up 'spam sting' operations. The idea would be to advertise the presence of an unprotected open relay hosted at a (financially compensated) university or business. All spam sent through that server would be checked for compliance with spam laws, and offenders would be prosecuted.
The idea would be to make illegal spamming not impossible, but so risky as to not be worth trying (because spammers would not know which servers were sting traps and which were merely poorly-administrated). Of course, this would only curb annoying spam sent from within the jurisdiction of the government implementing the spam laws/stings, but it's a mostly harmless step in the right direction.
The original article is owed that.