Slashdot Mirror


Cornucopia of Spam

Eric Savage writes "The IETF, through IRTF, has formed an Anti-Spam Research Group. If there is any hope for a technical solution the problem, it appears the first significant step has been taken. More info here in itworld and here in ComputerWorld." Three more exciting spam related posts inside, including news from the Nevada legislature regarding spam, Arkansas dislike of the meaty email and "when students go bad" torklugnutz writes "The NV state assembly just voted 41-0 in favor of a bill which allows spam recipients to collect up to $500 per piece of spam. The new law also requires ADV to be added to the subject line so that recipients can more easilly identify unwanted ads. In addition, spoofing of sender's email address or having an invalid return address is made illegal. The old law imposed a $10 fine on spammers, but required prosecuters to collect it. This law will, more than likely, increase my chances of reading the spam I get so that I can try to cash in. So, maybe I CAN make an incredible amount of money from this "Amazing Offer""

And in Arkansas: A.G. Russell writes "With House Bill 1008, Subtitled "Unsolicited Commercial and Sexually Explicit Electronic Mail Fair Practices Act." Arkansas looks to join other states that have criminal and cival legislation in place to deal with spam. Can we help them craft this?"

And from academia: mansemat writes "Seems spammers are using a new tactic these days by paying students to send spam over univeristy networks. This particular student will be disciplined by losing his computing privileges, and being educated on the policy he violated. One can only hope the education includes being subscribed to every pr0n, male enhancement, mortage, etc. spam on the planet." Should have booted the miscreant.

21 of 199 comments (clear)

  1. What's the point? by Omkar · · Score: 4, Insightful

    After all, we know how law-abiding spammers are. And how effective the government is in combating computer criminals. I really don't think this will make a difference.

    1. Re:What's the point? by cobyrne · · Score: 4, Insightful

      The point is that there is no point in a spammer sending out an email that does not contain instructions on how to obtain the product/service being advertised. And, therefore, it should always be possible to track down the person responsible for the spam. The point is that, without the promise of $500 for each violation, it was not economically viable to track down the spammer. Now, it may very well be.

      I once managed to track a spammer to a town about 2 hours drive from where I live. If I had been able to collect $500 out of my efforts, it is something that I would do more often...

    2. Re:What's the point? by Dan+B. · · Score: 5, Insightful

      Well if the goverment made as much money out of cracking down on spammers as say, speeding fines, with 'spamming fines', how much more aggressive do you think law enforcement would be on spammers? Then how many people would still do it?

      It always about the money, or the budget.

      Vicious circle I'm 'fraid.

      But people will always speed ;-)

      --
      Dan. -- So what if it's spelt wrong, nobody's perfect
  2. Arkansas emphatic by ratbag · · Score: 5, Funny
    Arkansas obviously believe that if you
    • underline something it MUST be obeyed
  3. Techinical solution by Raul654 · · Score: 5, Insightful

    Think of spammers like an infection. How does your body deal with it? It attacks the infections in a bunch of different ways. Why can't we do the same with spam? Rather than working hard for the magic bullet, why not use some combination of: Bayesian filtering, artificial bandwidth scarcity, blacklisting, aggressive collection of fines, targeting of domains that are advertised, etc. If you were to do all of these together, I'd imagine spam would not be a pleasant buisness to be in...

    --


    To make laws that man cannot, and will not obey, serves to bring all law into contempt.
    --E.C. Stanton
    1. Re:Techinical solution by Dan+B. · · Score: 4, Interesting

      How about imposing things like JAIL TERMS on people convicted of 'serial spamming'.

      I read an article once about a guy who lives in a multi-million dollar house in one State and just burns though trial ISP accounts in other states that can't properly prosecute (if that's the right term, since most States don't yet have decent laws against spam).

      Big Karma bonus for the governors of NV though, 41-0 on passing laws to nail the perpetrators AND finig them $500 for each successful plaintif in court.

      Oh yes, I see the day when I no longer need the words 'rape, enlargement, mortgage, lolita, diploma and toner' in my filter list for 'Permanantly delete'.

      --
      Dan. -- So what if it's spelt wrong, nobody's perfect
    2. Re:Techinical solution by frankie · · Score: 4, Funny
      Think of spammers like an infection. How does your body deal with it?

      An interesting proposal. Spews and SBL are probably Leukocytes. SpamCop users might be APCs. But I don't see any Macrophages in our virtual immune system. That must be why spam is so rampant -- we need activists to go eat the spammers! Volunteers, anyone?

    3. Re:Techinical solution by Raul654 · · Score: 4, Funny

      Well when your in the buisness of morgaging out Lolitas for the purposes of rape enlargement, I should think it would

      --


      To make laws that man cannot, and will not obey, serves to bring all law into contempt.
      --E.C. Stanton
    4. Re:Techinical solution by Steve+B · · Score: 4, Insightful
      Once again, Nevada takes the moral high road, leaving the rest of the nation to follow.

      I for one would prefer to live in a country where prostitution was legal and the cops conducted nightly sweeps to round up and jail spammers.

      --
      /. If the government wants us to respect the law, it should set a better example.
  4. Something Smarter Is Needed by chayim · · Score: 5, Interesting

    Creating laws, regulations, and whatnot will come nowhere near solving the problems. Sure, if a spammer lives in the US then maybe this would work; but what about all these scams from Europe, Australia, Britain, etc. Just because laws exist in one jurisdication, it doesn't mean that others will play ball. And even having laws does nothing if they're not enforced. Why not have a group of IT police hunt down spammers? After all, they're already guilty of theft and fraud (think bandwidth people). Why not prosecute under existing laws and treat spammers like the theives they are. Even though you won't catch spammers outside your legal jurisdicition, you'll help. And every country that helps would quickly be eliminating the spam problem we live with.

    1. Re:Something Smarter Is Needed by SerpentMage · · Score: 4, Insightful

      The only reason why the SPAM is coming from the US is because right now there are no legal ramifications. Just like how there was Napster and then Kaaza. Napster was State side, shut down and now Kaaza is NOT state side.

      Once laws start up the SPAMMERS will move offshore. Just like the guy who lives in Detroit. This SPAMMER lives in the US, but does not send the SPAM via the US.

      --

      "You can't make a race horse of a pig"
      "No," said Samuel, "but you can make very fast pig"
  5. Instead of all this, by Omkar · · Score: 4, Funny

    I recommend spammers be designated cyberterrorists. For spammers in uncooperative totalitarian countries, replies with randomly generated subversive messages should be mandated by law.

  6. I can see the e-mails now by snitty · · Score: 4, Funny

    IMPORTANT! READ NOW!

    Please sign this bill from your state assembly! I did it and I got my wish! If you don't want to get this e-mail from the state anymore click the sucker link at the bottom!

    --
    Modular Redundancy--Because 4 out of 5 Nodes agree
  7. Not quite by Raul654 · · Score: 4, Insightful

    From the spammer's perspective, if he has to worry about huge fines and/or jail time every time he sends out spam, and if only 1% of the emails are getting through, and after 10 minutes his connection goes dead, how long is he going to be a spammer?

    --


    To make laws that man cannot, and will not obey, serves to bring all law into contempt.
    --E.C. Stanton
  8. Spam loopholes... by SystematicPsycho · · Score: 4, Insightful
    Firstly, they can start by trying to get the following loopholes plugged with the unsubscription methods ..

    o unsubscription method is not feasible. I received an unsubscription method that went like this

    • "To unsubscribe by
    • postal mail, please send a request to P.O Box ..... Florida - quote reference number #blah"

    Who is going to send a snail mail letter long distance to seemingly be unsubscribed from a spam list? Now it's starting to cost _me money to be unsubscribed. The law says to have _an unsubscription method of some sort - this falls within the law no matter how bad it is.

    o unsubscription web page is non-existent - this happens to often
    --
    Analytic & algebraic topology of locally Euclidean meterization of infinitely differentiable Riemmanian manifold
  9. Spam Relies Upon Deceit by zentec · · Score: 4, Insightful


    A large percentage of "junk mail" depends upon some fashion of deceit. Either it's by masking the true identity of the sender, a spam-haus using domain after domain and ISP after ISP in order to avoid the blacklists or simply by lying and saying that "you really indeed did ask for this".

    The answer to the spam problem is to find technical answers that start peeling away at the ways spammers use deceit.

    I've said this before and I'll say it again, the first place is to rewrite RFC-821 and require valid reverse-name lookups before accepting mail. Also permit as an authentication scheme that allows the administrator of the accepting mail system to set permissable trust levels. Example, mail that's verified (through an SSL certificate might be one way) as coming from gm.com is accepted, but mail coming from slashdot.org is set to a lower trust level (because they don't want to spend the money for a certificate). Mail from getyerviagra.com is immediately tossed into a review folder, trashed or denied because they don't reverse properly and they have a forged or self-signed certificate or simply don't have one.

    The LAST thing anyone here wants is ANY government telling us how to manage electronic mail. In the US, it'll be frought with hooks and back-doors so the feds can snoop your mail.

    Let's get it together and fix the problem on our own.

  10. Loophole alert by paiute · · Score: 4, Funny

    Political speech is exempted. Advertising of the "call X and tell him that you are against his position on Y" is protected free speech. So expect emails of the sort: "Call Senator McGuffy and tell him that his penis can be enlarged in only three weeks!"

    --
    If Slashdot were chemistry it would look like this:Cadaverine
  11. Once again by deblau · · Score: 4, Insightful
    Since the attention span here seems to be about 5 minutes, I will reiterate a basic argument about spam (and many other problems plaguing us):
    Just as you can't solve a technology problem with laws, you can't solve a social problem with technology.
    Spam is a social problem. Scam artists have been around for millenia, 'spamming' you with unwanted and unsolicited communications. The Internet is only the latest communication tool that they use to peddle their wares. Previous tools have been faxes, TV, radio, telegraph, snail mail, courier, and shouting at you from the next hill over. Don't think for one second that the 'let's DDoS them out of existence' or 'let's make email expensive to send through some complicated protocol' arguments will work. They won't.

    Here are three easy steps to stop spam:

    1. Don't buy anything you get from spammers. Yes, that 24" penis must be really tempting, and I know you're dying to lose 10^6 pounds, but don't do it.
    2. Encourage other people to restrain themselves. The indiscriminant spam approach only works if the percentage of buyers (a.k.a. suckers, marks) is high enough to justify the cost of spamming (which is very low for email). If you can knock down that percentage, spamming won't be as successful.
    3. Educate people you meet about spam. Let them know that not every email they read is for real. Let them know that responding to spam encourages spammers. Let them know that if you catch them replying to spam, you will give Indian burns to their entire family.
    In short, technology isn't the problem here. The problem is that too many people keep falling for the spam. If you do your part, we can make it more expensive for scammers to use the Internet for their schemes.
    --
    This post expresses my opinion, not that of my employer. And yes, IAAL.
  12. Re:It'll never work... by pclminion · · Score: 4, Funny
    Also, what's stopping a Texan from spamming people in Arkansas? You can't enforce Arkansas laws in Texas. It doesn't work that way.

    Maybe you can't enforce Arkansas law in Texas, but the Texans can sure enforce their law in Arkansas. All it takes is a shotgun and a pickup truck.

  13. How to defeat spam by GnuVince · · Score: 4, Insightful
    Spam is a business. Like all business I know, its fuel is money. When spam stops being profitable, it will probably stop being so much a problem. Most geeks, nerds and hackers know how to recognize spam a mile away and most of us have spam filters installed, but common users do not. We need to help them by explaining them how spam works, by installing them filters (PopFile is an excellent free one on Windows and other platforms).

    Just make sure as much people in your neighborhood never see spam, and after a while spamming will not be as much as a problem as it is right now.

    Informing the common computer users is the first step.

  14. Summary of IETF ASRG discussions by wayne · · Score: 4, Informative
    I've been subscribed to the list since near the beginning and have been following it fairly closely. Much of the discussion has been rehashes of old topics such as "what exactly is spam?", "make the sender pay something, either money or CPU", etc.

    The most interesting discussions that I've seen so far are:

    • Mail transfer programs (MTA) such as sendmail, exim, qmail, etc., should keep track of sender-recipient pairs. The first time the sender-recipient pair shows up, sendmail (or whatever) should issue a "temporary delivery failure". This will force the sending mail transfer program to queue the mail and resend it later.

      Most spam specific programs will not queue and retry, and thus the spam will be dropped.

      Spammers that use real mail transfer programs or open relays will need to be able to hold all their outgoing spam for a while, increasing the spammer's costs and slowing down the delivery of spam. Legitimate email will not be thrown out, it will only be delayed and only for the first time.

      Of course, you don't really want the databases to remember every sender-recipient pair forever, nor do you want to remember pairs that were added by spam so this really isn't a "first time" database, but it is close.

      Apparently the "canit" program already does this, but I had not heard of this technique before.

    • Spam filtering really needs to be done while the email is being received. Sendmail can already do this with the milter filter, but other MTAs should also. Most mail servers are I/O bound, not CPU bound so this really isn't much of a burden on the server. This is completely backwards compatible and doesn't require end users to do anything.

      If you filter during the email receive process, you can make the sending MTA do the bounce. This means that you will not have to deal with spammers forging "from" and "reply-to" headers. You won't have to clean up bounces that never succeed, nor will you be responsible for bouncing spam to another victim that the spammer selected for the "from" or "reply-to" headers.

      Also, false positives will recieve a bounce message instead of just disappearing. This reduces the danger of important email being lost.

    • There are also several proposals to deal with ways of verifying that email being sent from a given IP address and claiming to be from a certain domain is actually authorized to send email claiming it is from that domain.

      Right now, there are DNS records that tell you which IP addresses are valid to try and send email to for a given domain (the MX records), but many ISPs have different machines for sending and recieving email. There are currently no DNS records to tell you which tell you which IP addresses a domain will send email from.

      The problem with this kind of proposal is that there are many people who think they have legitimate reasons to forge "from" or "reply-to" addresses. It also forces ISPs to make sure that every time they add a new outgoing mail server, they need to update the list of valid IP addresses. If they forget to do this, then only bleeding edge spam filters will detect a problem.

    --
    SPF support for most open source mail servers can be found at libspf2.