Slashdot Mirror


AOL Sued For Over-Zealous Blocking

mik writes "America Online has been sued by CI Host, a Texas-based hosting company for defamation, interference with contractual rights and unfair competition. CI Host has been awarded a temporary restraining order, though AOL has apparently not complied. This may be the first such in a series of suits leading up to, perhaps, to class-action status relating to AOL's recent zealotry in anti-spam policy resulting in the presumption that shared-hosting providers are guilty (of spamming) unless proven innocent."

85 of 546 comments (clear)

  1. Anti-spam zealotry is a good thing by Dancin_Santa · · Score: 2, Insightful

    And we could use more of it.

    Go AOL!

    Enema of my enema is ma friend.

    1. Re:Anti-spam zealotry is a good thing by Rellik66 · · Score: 5, Funny

      wait a sec, I thought we hated AOL on even numbered days.

      --

      Too many zeros, not enough ones

    2. Re:Anti-spam zealotry is a good thing by TroyFoley · · Score: 2, Funny

      So what do you call getting numerous AOL installation CDs over the years if not spam minus the electronic delivery?

      --
      After I have received the wisdom of good teaching, I will untiringly teach all people. - The Teachings of Buddha
    3. Re:Anti-spam zealotry is a good thing by Ravensfire · · Score: 2, Funny

      But this is an odd numbered day, so we like AOL.

      --
      "But we decide which is right, and which is an illusion"
    4. Re:Anti-spam zealotry is a good thing by Gherald · · Score: 4, Funny

      > So what do you call getting numerous AOL installation CDs?

      Untargeted marketing.

    5. Re:Anti-spam zealotry is a good thing by Kaeru+the+Frog · · Score: 2, Insightful

      What timezone are you in? 23 hours a day someone could bash AOL.

    6. Re:Anti-spam zealotry is a good thing by NanoGator · · Score: 2, Funny

      "But this is an odd numbered day, so we like AOL. "

      Wait a sec. Today's Monday. Is Monday a 1 or a 0?

      --
      "Derp de derp."
    7. Re:Anti-spam zealotry is a good thing by Anonymous Coward · · Score: 5, Interesting

      AOL are a bit zealos with their blocking. Worse there is no apparent (from what we could see) removal process or information on *why* you were blocked.

      I maintain a few mail server that a number of customers of ours use to send out mail. We have a non-spam TOS and we check up on our customers. We got blocked. We went on to complain to a mass of different addresses. We got a two replys a few days later, the most notable was one from an address that didn't exsist (at aol.com) scolding us for not providing information that we had actually provided in our barrage. The other was just as worthless (telling us to read the usless help) though a reply to it didn't bounce.
      Then as mysteriously as we went on the RBL we came off it again. To this day we are still cluless as to how we got on this RBL or how we got off it.

      Worse though is Excite. There RBL is entirly hidden. No URLs, no help, no reasons, no nothing. We have had NO reply to our barrage of mails after a week and a bit. We even opened an account and complained as a customer. So we have taken to re-assigning our SMTP sender's IP address. I'm sure they will block that too, but we have a /19.... we can play this game for a while.
      Maybe I should see if we can sue Excite....

      >

    8. Re:Anti-spam zealotry is a good thing by EvilAlien · · Score: 3, Insightful
      Ya, I need another copy of the /.drone handbook. I'm not sure what to do here... we hate spam, but we hate AOL, but we like security, but we hate restrictions on our (ab)use of broadband, but we support the rights of network admins to admin their network, but we like freedom, but we hate government interference, but... *bzzzt*

      > ERROR
      > KERNEL PANIC

      --
      perl -e 'print $i=pack(c5, (41*2), sqrt(7056), (unpack(c,H)-2), oct(115), 10)'
    9. Re:Anti-spam zealotry is a good thing by Zeinfeld · · Score: 5, Interesting
      AOL are a bit zealos with their blocking. Worse there is no apparent (from what we could see) removal process or information on *why* you were blocked.

      There are several separable issues here.

      The first thing to notice is that our only information on this dispute comes from a press release put out by CI-host. I find it somewhat surprising to see it alleged that AOL is in contempt of court. On the other hand one wonders how a judgement from a Texas court affects AOL off in Loudoun county VA. I suspect the AOL/Time lawyers may have a different opinion.

      Another thing missing from the report is any mention of the reply filled by AOL? Was AOL even aware of the hearing? In most cases a court order does not have immediate effect, thus allowing the defendant to file an appeal. It seems unlikely that a court would issue an order with immediate effect given that AOL has had considerable success in preventing spammers gaining orders of this type in the past.

      Another suspicious factor is the rapid escalation to littigation. A legitimate ISP would be unlikely to sue until it was clear that AOL was not going to be reasonable - unless of course they knew AOL was being reasonable.

      At this point it is reasonably settled law that an ISP cannot be forced to accept email from an address that it does not want to service. The defamation claims might work against a third party such as a blacklist but it is hard to see how a company can be prohibited from acting on its own assesment of CI's behavior.

      The other thing that is odd here is that Sudereth is a recent President of the American Judges Association. You would not expect a judge in that situation to be making whacky judgements which suggests strongly that there is something here that we are not being told in the CI PR puff. It is very rare for a court to order an injunction with immediate effect unless the damage done is irreversible. In this case the effect is very obviously only money.

      --
      Looking for an Information Security student project suggestion?
      Try http://dotcrimeManifesto.com/
    10. Re:Anti-spam zealotry is a good thing by PktLoss · · Score: 5, Insightful
      I don't know, I am tired of over zealous spam lists, network admins, strange anti-spam mechanisms.

      Recently, one of our mail servers got listed with a major spam list with a major time lag. It was allowing open relay (but was never used for nefarious purposes) 6 months ago, and this was resolved 3 months ago.

      As a result, all of the mail that was sent to paying Road Runner customers was bounced back, this was mail that was requested, and mail they had just paid to receive. I attempted to forward from my ISP, but lo and behold, my personal ISP (different country than our corporate mail servers) had also been blocked by Road Runner.

      I attempted to email Road Runner to get more information, but got standard auto-responders that didnt answer my question.

      I ended up mailing the paying customers via my webmail account on my personal domain.

      We lost about six accounts to refunds over non-recipt of information, since it took us a week to figgure out what was going on (mails are sent from an unmonitored account).

      Also:
      Most non-technical users don't know how to properly manage opt-in spam blockers (the ones with auto responders pointint you to websites where you can fill out all your personal information, your mothers maiden name, and perhaps the person might deem it acceptable to let your mail in). They sign up for things, dont add the posted address to their list, the mail gets blocked, so they email us complaining, not bothering to add the email address they just messaged to the allowable list. With the current virii going around, spoofing return headers, I just dont have the time to wade through all the mailer daemon/postmaster/spamblocker/virus blocker emails comming in.

      ISP Level Spam blockers MUST:
      • Allow users to turn them on/off
      • Allow users to view blocked mail
      • Provide external groups with EXACT information on why a message was blocked, rather than pawning off responsibility to some Not-For-Profit.
      • Respond to queries from external groups within 1 business day, either with removal from lists, or more detailed information
      • Upon removal from a blocked list, spam cached within the past week from affected senders should be forwarded with an attached apology header.
    11. Re:Anti-spam zealotry is a good thing by Maserati · · Score: 2, Informative

      RoadRunner now has fairly detailed instructions on dealing with the "why are you blocking my email" situation. The linked example is for residential users. Commercial users complaining about blocks are referred to their own ISP and told to have them get in touch with RoadRunner (this may be just for businesses that have been misidentified as being in a residential IP block).

      Having a web-based email account can come in handy, especially if you choose a reputable (no hotguy68734@) handle and a known provider (Yahoo, Fastmail).Besides, this gives you an alternate means of contact if your own mail servers become unavailable (blackout, crash, backhoe).

      Calling a RoadRunner 800# might have helped.

      --
      Veteran, Bermuda Triangle Expeditionary Force, 1992-1951
    12. Re:Anti-spam zealotry is a good thing by nowt · · Score: 2, Interesting
      Well I have roadrunner at home (cable modem) and I can't send e-mail to AOL users due to the parent topic.

      Gotta love how I can't send e-mail from one Time-Warner company to another....
      I guess an example of the left hand breaking a few fingers on the right.

      --
      A strange game. The only winning move is not to play. How about a nice game of chess? - Joshua (Wargames)
    13. Re:Anti-spam zealotry is a good thing by Phil+Karn · · Score: 2, Insightful
      Road Runner's "detailed" instructions are useless if you happen to be on what they consider a "residential" IP address block. Doesn't matter if your address is dynamic or static. Doesn't matter if the customer they're "protecting" really wants to hear from you. Doesn't matter if your machine is clean and secure and you've never spammed or relayed a spam in your life. Doesn't matter if you prefer not to use your ISP's outbound relay because it drops half your mail and delays the other half for a day. You can't send them mail. Period.

      This is one of the many reasons I run my own incoming SMTP server and my own virus and spam blockers. I control them, not the morons who happen to own the only broadband pipes in town.

    14. Re:Anti-spam zealotry is a good thing by bobetov · · Score: 4, Interesting

      My mom, using Earthlink, has been unable for 4 days to email her business partner. Which is wasting her time. Preventing her from getting work done.

      The thing to realize here is that, while punishing an ISP may or may not be a good thing, harming *tens of thousands* of innocent users of that ISP (and Earthlink is a good one, IMHO) is incredibly irresponsible.

      The bounce email said basically "Go whine to your ISP" which was, frankly, insulting. Never having been a fan of AOL, I'm not really surprised by this, but I can tell you it's caused her business partner to drop his account damn quick. Hope other AOL customers are doing the same.

      Email is critical infrastructure. It's a public communication medium just like telephone lines are. How would you like it if all Bell South customers couldn't call you because your regional Baby Bell didn't like dealing with all the telemarketing coming in from Atlanta?

      At a certain point, services become too valuable to play this kind of game with. I think email has passed that threshhold long ago.

      --
      Looking for a Rails developer in Chapel Hill?
    15. Re:Anti-spam zealotry is a good thing by Skapare · · Score: 2, Insightful

      To give the end user full control also means that user is selecting what level of cost their ISP will incur. The technology to do it exists, but the implications of doing it are serious. Blocking spam is substantially a cost saving measure. Letting users turn it off re-incurs those costs. This really only works well when the users are on a pay-per-received-message basis.

      Most of the cost of email, and of spam, is incurred in the receiving end. That's either paid for by the end user/customer, or the ISP, depending on how the service payment plan is arranged (examples being flat rate for all the email and spam you can eat, and pay-per-message). Of course in a pay-per-message case, you really must give the user control. But if the ISP is paying per message and charging the users a flat fee, it's the ISP that needs to be in control of costs.

      Of course, none of this would be an issue if certain ISPs would stop hosting spammers once they know they are spammers.

      --
      now we need to go OSS in diesel cars
  2. Bout Damn Time by Sklein382 · · Score: 5, Funny

    Now we just need to put together some kind of class action suit for them spamming my regular mailbox with those damn CDs

    1. Re:Bout Damn Time by kaltkalt · · Score: 3, Insightful

      They are paying to spam your mailbox with those CDs. They pay for the CDs and the postage. Thus there is a check on how pervasive it can be. Note that you don't get 40 CDs a day from them.

      --

      Stupid people make stupid things profitable.
    2. Re:Bout Damn Time by insecuritiez · · Score: 2, Insightful

      I may not get 40 CDs a day from them but I have more than 40 of their CDs. Most come because I am a former subscriber. Others come from random mailings. Others from purchases that bundle them alongside the product. I don't think there should be a timeframe. I consider constant bombardment from advertisement of the course of a few years harassment and spam.

    3. Re:Bout Damn Time by swordboy · · Score: 4, Interesting

      Now we just need to put together some kind of class action suit for them spamming my regular mailbox with those damn CDs

      I actually called them and asked to be removed from their mailing list and they told me that it wasn't possible because they send the CDs at random. That is, they just pick a few hundred thousand fucking addresses and then spam them with CDs. So I told the representative to whom I was speaking (after I told her that I was not angry with her) what I would do about it.

      Basically, anytime I see a stack of AOL CDs at a supermarket or restaurant, I pick the whole damn thing up and put it in the nearest garbage can.

      Fuck them.

      Oh... and print up some "return to sender" labels and take them to the mail box with you every day. I put them on all postal spam and send it back before I even get it into my house. Junk mail is down about 75% after 6 months or so.

      Good luck!

      --

      Life is the leading cause of death in America.
  3. Mail server by Anonymous Coward · · Score: 5, Interesting

    I manage the web and email account for the church I attend. The pastor has an aol account, so his e-mail from our server simply redirects to his aol account. Just last week, I found that we had been put on aol's blocklist for some reason - all e-mails being redirected through the server to aol were being blocked for 2 weeks by aol. Blocking messages like this results in missed personal communication. This could possibly result in lawsuits from consumers themselves.

    1. Re:Mail server by John+Seminal · · Score: 4, Interesting
      Get a different provider if you do not like it. Or you could call AOL and explain to them who you are and what you are doing and hope they let your email server send mail.

      And I doubt you could sue. The service provider decides what services you get. It you do not like it, you are free to find another company.

      I had AOL for about six months, and it sucked because of all the spam. I left for the opposite reason, that they did little to stop spam.

      I would like to see other internet providers follow, especially broadband ISP's.

      --

      Rosco: "If brains were gunpowder, Enos couldn't blow his nose."

    2. Re:Mail server by BitterOak · · Score: 2, Informative
      The service provider decides what services you get. It you do not like it, you are free to find another company.

      I'm afraid it doesn't work that way. The person suing here is not an AOL customer, but rather someone whose clients had a need to send mail to some AOL subscribers. So, they aren't free to simply choose another company; they never chose AOL in the first place!

      --
      If I can be modded down for being a troll, can I be modded up for being an orc, or a balrog?
    3. Re:Mail server by yamla · · Score: 2, Interesting

      I have my own mail server. I don't use AOL, never have. However, because AOL erroneously filters all incoming mail from my IP address (they claim I am a residential cable-modem customer, I am not), email to one of their customers is never delivered. So I'm paying more than $23 a month. I'm not an AOL customer. It is hurting me.

      --

      Oceania has always been at war with Eastasia.
  4. AOL is going to stomp on CI Host by signe · · Score: 4, Interesting

    And I'm going to enjoy watching.

    CI Host is a lousy company. I had nothing but trouble with them when I was hosting there. They continued to charge me after I cancelled my account, they refused to issue refunds in a timely manner. I very nearly took them to court over it. CI Host has spammers as customers. I told them about a few that were causing problems for me, and they never did anything about them. Doesnt' surprise me, because their customer support is poor, bordering on non-existant.

    AOL is going to turn around and clean them out in court, and I'm going to thoroughly enjoy it. All they have to do is point to a few CI Host customers that spam, and that CI Host has been notified of several times, and it will either be a wash (in which case, AOL wins because they can stand the legal fees better than CI Host), or AOL will be able to counter-sue without a problem and make CI Host feel the hurt. Either way, I say yay AOL, which is something that I don't often say.

    -Todd

    --
    "The details of my life are quite inconsequential..."
    1. Re:AOL is going to stomp on CI Host by Stephen+Samuel · · Score: 3, Insightful
      I very nearly took them to court over it. CI Host has spammers as customers. I told them about a few that were causing problems for me, and they never did anything about them.

      You might want to provide an affidavit to AOL on this. CI appears to have gotten their injunction on the basis of that they've got a really tight anti-spam policy. If they're providing support to commercial spammers, then AOL has (or should have) the right to block them.

      I think that it may be something different about what AOL support is saying about CI hosting... It's one thing to simply report that AOL gets to much spam from CI customers -- it's another thing to call them spam bags.... (although I really like the term).

      Spamming is illegal in many states, and congress is looking at making it nationally illegal. To say that you have a right to spam is silly.

      Spamming is all about finances, and refusing to route IPs from a hosting company that supports spammers is a way to shift the finances against them allowing spammers on their net.

      --
      Free Software: Like love, it grows best when given away.
    2. Re:AOL is going to stomp on CI Host by signe · · Score: 3, Interesting

      No, this wasn't just auto-renewal. I cancelled within the first month because of the massive downtime and lack of support, so I was supposed to get that month back (by their guarantee). It took me 2 months (during which they did not charge me) to get that refunded back, and the only way I did it was by disputing the charge with my card company.

      The week after they refunded it, they charged 2 months' service to my card. It could only have been to "recoup" the money that the credit card company "took" from them. I started talking to them about that, and the next month they charged my card AGAIN. I had to change the number on my card. I had to dispute it with the card company again. After a couple more months, I finally got my money back again. And I'm sure that if I hadn't changed my card number, they would have continued to charge me again.

      And this doesn't even cover the support issues and downtime. Just the fraudulent billing.

      -Todd

      --
      "The details of my life are quite inconsequential..."
    3. Re:AOL is going to stomp on CI Host by junkdomain · · Score: 4, Interesting

      I agree, CI host seems to be full of hypocrites. I work for a small Texas based ISP. CI Host spammed our customer base and null routed the netblocks that our nameservers were on to keep people from replying. It took months to get the route removed and when we finally got to an engineer, they had no idea why it was there. Obviously a favor by an engineer for a marketing/sales guy.

      The good news, we only lost one customer, who came back a few months later after they realized how bad CI Host actually was.

    4. Re:AOL is going to stomp on CI Host by leviramsey · · Score: 2, Informative
      customers might be entitled to sue AOL for the loss of service (doubt it).

      It's called "tortious interference in a business relationship". In some states, AOL may be forced to pay triple damages plus law fees (note, triple damages would cover lost business).

    5. Re:AOL is going to stomp on CI Host by Pharmboy · · Score: 2, Interesting

      It's called "tortious interference in a business relationship". In some states, AOL may be forced to pay triple damages plus law fees (note, triple damages would cover lost business).

      And you should know that if an hosting provider is sending tons of spam (much illegal) to AOL, then they are interfering with their ability to provice service to their customers. Unless AOL is singling them out for other reasons (put them out of business, etc) or the action is negligent (which its not, its a legal, reasonable but drastic measure) then there is NO damages.

      No ISP can demand that another ISP accept its mail. The internet doesn't work that way, and never has. If AOL decides it will only accept email from other AOL customers, then they have the legal right to do this. If they want to accept only email from "bob@*.com" then they can.

      I am just beside myself because so many people here just don't get that. Any ISP can filter out any content they want. they can block all customers from *.net addresses if they choose. They can not allow images to be transfered on port 80. They can have an interface that allows only Mac users to connect if they want. You can chose to not use their services. But you don't have the RIGHT to cash in every time some company doesn't do what YOU think they should.

      --
      Tequila: It's not just for breakfast anymore!
  5. Stupid by asavage · · Score: 4, Insightful
    If it is your own network and you aren't the government, you can block whatever messages you want.

    At least AOL can defend itself

    1. Re:Stupid by ThatDamnMurphyGuy · · Score: 3, Insightful
      How is choosing what to filter against the law?


      For the same reason Microsoft can't do what they want with their OS to a certain extent: antitrust laws and the fact that AOL IS a monopoly in the ISP market for the most part. Sure, there is Earthlink and the like, but when the Giant in any arena gets as large as AOL's subscriber base, they have to play by a different set of rules.
    2. Re:Stupid by cfradenburg · · Score: 2, Informative

      There are many parts to CI Hosts lawsuit.

      Defamation: If it is shown that CI Host shouldn't have qualified as a spammer AOL has committed defamation by giving CI Host a bad name when they don't deserve it. There are legal precedents for legal reprecussions for defamation.

      Interference with contractual rights: AOL is held to any contracts that they have with CI Host (if any.) There are legal precendents for legal reprecussions for breaking a contract.

      Unfair competition: Suppliers to businesses must provide equal opportunity to all competitors. For (a simple) example, Cisco can't sell their parts to reseller A at a lower cost than they do to reseller B. There are legal precendents for legal reprecussion for interferring with fair competition.

      I can't think of any contracts that AOL would have with CI Host but the point is that AOL can't do whatever it wants just because it isn't the government.

  6. CI Host does indeed suck by SkoZombie · · Score: 5, Informative

    I had the misfortune of having a dedicated server with them for 2 long years. The machine would lock up frequently, and i'd have to make a 30min call from Australia to the US to listen to their on hold crap so i could talk to a tech and then try and convince him to hit the big red button.

    CI Host has a huge marketing and sales department and tiny tech support division. Dont you dare, ever, believe a word of their marketing crap. They suck. Pure and simple. They've cost me thousands because of the clients i've lost because of their incompetence. Some of the people are nice enough but they simply dont have the technical skills of other places.

    I'm now with rackspace.com and they kick arse!

    1. Re:CI Host does indeed suck by Evan · · Score: 2, Informative

      I'm with RackSpace too. They've been great, from a technical standpoint; When I had hardware problems with my server they got it fixed, quickly, on a Sunday. I've *never* had a service outage. Therefore, I'm really sorry that I'll be having to leave them soon due to their utter lack of enforcement of their spam AUP.

  7. Any filtering is too much by localghost · · Score: 3, Insightful

    I'd rather spam filtering be left to myself. Any decent e-mail client has the capability for filtering, and by doing that way, I have control over what gets thrown out and what doesn't. I would not trust AOL to tell my what e-mail I should and shouldn't read. That, of course, is one of the many reasons why I would never be an AOL customer.

    1. Re:Any filtering is too much by TroyFoley · · Score: 2, Informative

      AOL is, needless to say, an over-the-top form of User-Friendly setup for an ISP. Now you may be use to customizing everything that has a plug in it, but for a parent who just wants his kid to get connected for school/after school purposes... it's nice to know that your little one WON'T be getting offers to enlarge his pre-pubescent penis by three inches, increase in girth, etc etc...

      --
      After I have received the wisdom of good teaching, I will untiringly teach all people. - The Teachings of Buddha
    2. Re:Any filtering is too much by Frater+219 · · Score: 5, Interesting
      I'd rather spam filtering be left to myself. Any decent e-mail client has the capability for filtering, and by doing that way, I have control over what gets thrown out and what doesn't.

      There are substantial disadvantages to a client-side filtering only spam defense as opposed to a server-side blocking only defense. It is, of course, fully possible to use both; I merely wish to point out some factors you may not have considered.

      For the definitions of "filtering" and "blocking", please see this Wikipedia article. Roughly, DNSBLs and Sendmail's milter feature are blocking tools -- they take effect during the SMTP transaction. Client-side tools are filtering tools -- they take effect when you check your mail.

      Consider:

      • Client-side filtering destroys false positives rather than bouncing them. Any spam defense can have false positives, in which non-spam email is incorrectly classed as spam. When a mail server doing blocking experiences a false positive, it returns an SMTP error to the sending system. Ultimately, the human sender sees a bounce message, which indicates that their message did not make it to the intended recipient. The sender can then attempt to get around the block (by sending from another site) or can try to contact the recipient by other means. However, when a client-side filter has a false positive, the mail is either deleted or filed in a rarely-seen "spam folder". The sender gets no notification that it will not be seen (or not seen promptly). Since false positives do happen, it is better that they not happen silently!
      • Client-side filtering isolates and hides useful information. A mail site, particularly a large one such as AOL, is in a position to gather a great deal of information about spam sources and patterns. Users complain about receiving spam. If a site can cause these complaints to be expressed in a useful way (such as sending full headers to an abuse address) rather than a useless one (such as cussing out the helpdesk), the site can aggregate a huge amount of information about spam offenders, which can be used to the whole site's spam defenses (or to mount litigation or prosecution of spam offenders). In contrast, your client-side filtering is informed chiefly by your own experience, and has no access to the experience of the other bazillion people on your ISP or mail site.
      • Client-side filtering doesn't alleviate large mail sites' resource problems. A site such as AOL dedicates significant amounts of disk space, backup capacity, and network bandwidth to email. Since over half of AOL's incoming email is spam, if AOL did no blocking then it would probably spend over twice as much money on these resources than it would on a spamless Internet. In client-side filtering, mail must be delivered to the user's mailbox on disk, and the user must then check his mail, before any spam is removed from disk. If that spam were blocked at SMTP time, however, it would never have occupied AOL's disk and never consumed those resources.

      However, as I mentioned above, it is possible to combine blocking and filtering in useful ways. A mixed strategy is what I prefer for my own site: we use a number of blocking strategies (such as DNSBLs and regular-expression patterns matching common spam elements), but we also use SpamAssassin and encourage users to filter with its scores or other criteria.

    3. Re:Any filtering is too much by RipCurl808 · · Score: 2, Insightful

      Then you're pretty much out of touch with the big picture.
      In order for you to receive that spam it still hast to go through AOL's servers and SIT there until you decide to log-in to your account to read/delete/foward/answer or leave it there. The whole point of filtering is so that YOU and that extra $3 you pay a month goes to helping AOL maintain its servers for the 1 billion pieces of crap it gets EVERY single day.
      You do realize that $3 out of your monthly payment goes to pay for the filtering of spam on Aol's server. Wouldn't you be happier if that $3 / mo or $36 per year went to something more needy? Like saving up for that vacation you always wanted? or taking that much more off your Mortgage? No, you pay that extra $3/mo to hanlde the spam problem. To have AOL buy bigger servers to handle the deluge of spam; and agian, filtering it on the enduser is doesn't preven the spam from entering their servers and taking up space.

    4. Re:Any filtering is too much by Phil+Karn · · Score: 2
      I think your arguments against client-side filtering are far too strong.

      Client-side filtering does not need to destroy false positives. Nothing keeps a mail filter on a client from generating delivery failure messages just like those produced by a MTA. Of course, I don't know why you'd want to generate such messages in response to every spam and email worm. Besides, there's no real way to know that any message was actually read by its intended recipient (instead of silently ignored) other than for the recipient to manually reply and say so. This is just the end-to-end principle applied to email.

      Nothing in client-side filtering inherently prevents you from aggregating useful information about spam. I perform my own spam filtering, and I forward all my spam to spamcop where it is aggregated with spam reports from many other users. In fact, they get better quality reports from me because I manually review the stuff in my spam folder to make sure it really is spam before I report it. (I don't really have to do that since annoyance-filter, my Bayesian spam detector of choice, has an extremely low false positive rate.)

      Your one good point is about resource wastage. And I'd have no problem with a mechanism that allows users to delegate spam filtering functions to their ISPs provided that the users retain ultimate control.

      The problem is that such control is almost totally lacking in today's ISP spam filtering mechanisms. Filtering is usually imposed (along with IP blacklists) by heavy-handed ISP fiat, and the users get no say over what is or isn't considered spam. If you're lucky, your ISP won't automatically drop what they consider to be spam, but will simply mark it with a header or place it in a separate IMAP folder. But you will probably have no control over their determination except to ignore it and replace it with your own.

      Although most of us would probably agree on what is and isn't spam in the majority of cases, ultimately spam is in the eye of the beholder. There can be no justification for withholding email from someone who really wants to receive it, and no justification (other than ISP laziness) for not giving their users ultimate control over all filtering mechanisms.

  8. They should sue the spammers for $ damages by kaltkalt · · Score: 5, Insightful

    Seriously. I realize AOL has the deep pockets, but the spammers are the cause of AOL's blocking email from the domain. The spammers, not AOL, are responsible for any monetary damages the plaintiff here suffers. Public policy dictates that AOL should be immune and the spammers who spammed from that address should be liable. Does everyone have the right to send email to AOL addresses? I would say no, although AOL should have to say "hey, when you have an account with us there are people who will be unable to email you."

    --

    Stupid people make stupid things profitable.
  9. AOL is free to do whatever they want. by John+Seminal · · Score: 2, Interesting
    People are also free to chose whatever provider they want. The only downside I can see is if someone brings up an "Interstate Commerce" violation- congress has the power to regulate commerce between the states, including internet sales. But as long as AOL does not stop people from pointing their browsers at whatever stores they want, I do not see how anyone can win a lawsuit.

    I personally think it is good that someone is trying to block spam. Now if they could validate forged headers.

    --

    Rosco: "If brains were gunpowder, Enos couldn't blow his nose."

    1. Re:AOL is free to do whatever they want. by kaltkalt · · Score: 2, Insightful

      a private company can't violate the commerce clause.

      --

      Stupid people make stupid things profitable.
  10. In my opinion CI Host are scum by augustz · · Score: 4, Informative

    Don't be to quick to defend them.

    http://www.forumhosts.com/cihost.htm for a taste of what these guys are like.

    http://www.stevemaas.com/selbstbild/archives/000 27 3.html is another link.

    Let's hope to god the EFF's and Timothy don't fall for their lawsuit stuff.

    More of AOL's anti-spam zealotry is a good thing (I speak as someone who has had something like 10,000 emails blocked by them in the past few weeks).

  11. I'm now definitely a proud customer.... by heXXXen · · Score: 5, Interesting

    Been with CI Host for awhile, pretty good network, really like the price too.

    Also, AOL/RR is blocking email from my office (Sprint SHDSL, fiber optic DSL, faster than T1, business only stuff in case you weren't aware). Ever since I got the first bounced message AOL has been #1 on my shit list.

    Bravo, CI Host, Bravo.

  12. Odd.. by WhiteHatDave · · Score: 4, Informative

    Being as I at one time worked in the abuse capacity for a ISP. Although AOL may have over zealous policies as of late they do have a postmaster number which they could call and have the validity of the block checked. I had done this in the past and had resolution in ~24hours.

  13. Oh, the irony. by faedle · · Score: 4, Insightful
    "C I Host is very aggressive about attacking the spam issue," Faulkner said. "C I Host does not spam, and we don't tolerate spamming by our clients," said Faulkner. "In fact, we were one of the first Web hosting companies to install spam filters that our clients cannot turn off. This week alone our spam filters blocked over 16 million spam e-mails.



    Am I the only one that finds this ironic? It's not okay for AOL to filter spam, but it's okay for us to. Uh huh.

    1. Re:Oh, the irony. by kaltkalt · · Score: 2, Insightful

      Well, I'm sure in response, they would say "we're not saying spam filtering is wrong, we're saying blocking huge domains and refusing to narrow it down even when it's been pointed out the spam didn't come from us is wrong."

      People really need to learn what the words "irony" and "hypocrisy" really mean. These two words are used interchangeably for any situation that sounds sorta funny.

      --

      Stupid people make stupid things profitable.
  14. ci host == bad isp by asv108 · · Score: 5, Informative

    Just do a quick /. search to see what people think of ci host. I was a ci host customer back in 99/2000 when their whole accounting database was open to the internet, customer information and credit card numbers. There were $5000 of fraudulent charges on my check card around the turn of millenium from my information being readily available to any idiot with a web browser. The bank took care of everything but it was a pain the in ass.

  15. Just had to say by Faust7 · · Score: 4, Funny

    C I Host, one of the world leaders in Web hosting and Internet solutions, was awarded a temporary restraining order against America Online

    I can't be the only one that finds the concept of an online restraining order more than a little amusing.

  16. Just like SPEWS and some others? by some1somewhere · · Score: 2, Informative
    But isn't this the same kind of "policy" that some aggressive anti-spam lists have? Some that come to mind are:

    spews.org
    (and indirectly osirusoft.com)
    selwerd.cx
    blars.org
    bl.reynolds.net.au

    Personally I choose to use block lists that have clear open operating policies, including clear adding and removal methods. A small sample include:

    spamcop.net
    ordb.org
    proxies.relays.monkeys.org
    opm.blitzed.org

    This is certainly not a comprehensive list, but it is a good start. A good comprehensive list is at: http://www.declude.com/JunkMail/Support/ip4r.htm

    And most importantly, READ THE POLICIES OF THE BL *BEFORE* USING IT. The last thing you want is to start using a BL, only to find most of Asia, or big ISPs, are among the ones blocked, and you're losing legitimate email.

    --
    **FREE** Track and view your phone's via CellID and/or WIFI and/or GPS :- http://tinyurl.com/la6fhd
  17. For all the "Good for AOL" people by Kostya · · Score: 4, Insightful
    If you don't run a webhosting company or an ISP, shut up. If you run a webhosting company or an ISP, you know how crappy AOL's system is.

    Consider if you have an AOL client who has a site on your hosting server. They forward their site mail to their AOL account. Their site account gets spam. What happens? Well, the spam gets forwarded, the clueless AOLer reports it as SPAM, and AOL's system sees your hosting server as a spam source. There is nothing you can do to protect your hosting server. Nothing.

    This really happens. If you call AOL, they basically say it isn't their problem. If an AOL client thinks a mailing list email they signed up for is spam, then AOL thinks it is spam. They tell you to setup a feedback loop where they send spam reports, but you have no way to respond to AOL. You just get flooded with tons of reports by clueless AOL users with no way to tell AOL, "Hey, this isn't SPAM!"

    Only on two occasions where a client had an exploited formmail script did the AOL system work as it should (i.e. spam was reported, we saw the report and found the problem). Every other day of the week, it is a massive time-sink that you get nothing out of.

    AOL wanted to make up for sucking on the SPAM front. So they become complete asses and made the job that much harder for the rest of us. Bravo!

    I hope the class-action suit makes them stop. I don't expect anyone will see any money, but at least AOL will be held accountable for being such idiots.

    --
    "Doubt your doubts and believe your beliefs." -- Switchfoot, Ode to Chin
    1. Re:For all the "Good for AOL" people by Dimensio · · Score: 3, Insightful

      I understand your desire for AOL to lose. After all, they have a contractual obligation with CI Host to carry their e-mail.

      Oh, wait, they don't. They're a privately owned company and they have the right to drop any mail traffic that they choose, even if the reasoning is completely stupid (though in the case of CI Host, it isn't). I guess that you believe that the government should be dictating how people run their private networks, including accepting the additional costs of spamming just because it makes spam-friendly ISPs feel bad when their packets get dropped.

  18. "Fair use" by batura · · Score: 2, Interesting

    I don't recall there being anything that says an ISP has to accept email from someone. It seems more like the accepted business idea of reserving the right to refuse service to anyone.

  19. am I your enemy? by SHEENmaster · · Score: 5, Interesting

    I am on a small ip block, with losers that catch the latest winshit worm and start spamming every few weeks.

    Because of this, AOL has blocked my mailserver despite 7 requests to whitelist it (3 from myself, 4 from AOL victims^H^H^H^H^H^H^Hconsumers). It gets whitelisted for a few days, then group punishment kicks in and it's blacklisted again.

    I have never spammed, I never intend to spam. Getting accused of sending half a billion unrequested emails in half an hour from a upstream as small as mine is both hilarious and insulting.

    Fighting spam is one thing, blanket bombing to prevent spam is quite another. If anyone at the evil empire's apprentice is reading, "Hope you're glad that my dad left you because of your stunts. See you in court."

    --
    You can't judge a book by the way it wears its hair.
    1. Re:am I your enemy? by Abm0raz · · Score: 2, Insightful

      I feel for you, but is this really AOL's problem? Is it even really your problem with AOL? I see as your problem with the spammers and your ISP.

      Let's use an analogy:
      If I get a bunch of crap marketing calls from an MBNA call center from Sleazy Marketing Company (SMC). I call up the phone company and complain. THey get dozens more complaints and as collective users, we have dictated a policy to them to remain their customers, "Either block the calls from this center or we will goto someone who can." The phone company CAN do this and you see it occasionally in very close night bible thumping communities.
      Now, the charity "Save Everything 'cept SCO" decides to rent the call center for it's fund-drive and can't reach anyone in our phone exchange ... ...who is at fault? The charity is pissed at the end-user? Why? The end-user has a right to not answer the phone. They could just as easily ordered caller-ID and not answered anything from that call-block (or unavailable,not listed, etc ...). This way the end user's phone isn't tied up when real calls come in.
      The charity is pissed at the phone company. Why? The company has a policy in place to keep it's customers. The company's interests lie in itself and it's customers, not some 3rd party.
      Who the charity SHOULD have a problem with is MBNA and the original spammers. It is the actions of these 2 that have prompted the blocking. The charity should've requested and read the policy based on what the call-center could and could not be used for. Now, they may have rented the center before SMC caused the problems. This would be unfortunate, but still not the phone company's or the end-user's fault. The charity needs to go back at MBNA and get refunds because their call-center couldn't reach all clients like advertised. They have the choice of using other call-centers with much better cold-calling and call-type policies.

      In case there are people that had problems with the analogies portion of the SATs ... here's a key:
      - MBNA Call Center is your average ISP that allows it's clients to spam.
      - SMC is a spamhaus.
      - The phone company is any other ISP that doesn't and impliments blacklisting
      - The charity is a good company that got caught in the spam fire. Casualty of war, if you will.

      Now, the end users (such as your dad) definitely have the option to switch providers (As he did) in protest. The Good company's (such as yourself) can switch providers as well. There are others out there. They may not be as cheap, but is the extra money worth the improved reliablity? You also have the power of your almighty dollar. Call and make threats to leave their service. Demand refunds. It works wonders. I got an additional 150 minutes of anytime minutes and a new $100 phone from AT&T today for free cause of a $2 billing discrepancy today. My journal will have the story tomorrow if anyone is interested.

      -Ab

      --
      Nothing fails quite like prayer.
    2. Re:am I your enemy? by Cylix · · Score: 2, Insightful

      Blocking one ip address in a subnet is frivelous and ineffective. In order to be completely sure you have stopped the spammers access you need to ban their whole subnet.

      So, if your neighbors continue to infringe on their network benefits (willing or unwilling), you may need to take some precautions.

      With constant problems such as this it would be wise to limit your upstream smtp traffic through an intelligent proxy.

      Take charge of the network rather then complain about the aftermath.

      Ignorance is a poor excuse.

      --
      "You should always go to other people's funerals; otherwise, they won't come to yours." -- Yogi Berra
    3. Re:am I your enemy? by goodie3shoes · · Score: 2, Insightful

      Here we see the failure of blacklisting in action. Big ISP's such as AOL are under tremendous pressure from their customers to block spam, so they revert to crude methods; like politicians, it's more important to be seen doing something about the problem than to actually do something about it.

      --
      BSA: "Would you like a free Software Audit"? me: "No, thanks. My software is all Free".
  20. You've got mail! by beacher · · Score: 4, Funny

    From: State District Judge Bonnie Sudder jbsudder@state.texas.us
    To: legal@aol.com; abuse@aol.com
    Subject: AOL, Save Thousands in Under One Minute! Quickest Quote!

    Dear AOL,
    This is your chance to opt-out of a completely unique program! You May Be Closer (Maybe Hours Away) To Financial Punishments than you think...
    * 100% Safe To Take, With Abosultely No Side Effects
    * Totally confidential, no one needs to know!

  21. Bullshit by GojiraDeMonstah · · Score: 3, Insightful

    Anti-spam zealotry is a good thing

    A good friend of mine is no longer able to send her regular op-ed piece to AOLers due to anti-spam zealotry. She can't reply to her subscribers when they write and ask why she's stopped sending it. She's even blocked from emailing AOL tech support to ask why she's blocked in the first place.

    Arbitrarily cutting off an entire ISP with the inexplicable finality AOL has shown towards several ISPs isn't making the world a better or more spam-free place.

    Repeat after me: arrogant zealotry is a bad thing, and we could use less of it.

    --
    "Stop throwing the Constitution in my face, it's just a goddamned piece of paper!" - George W. Bush Nov. 2005
  22. Uh, since when you HAVE to provide service? by PierceLabs · · Score: 2, Interesting

    I mean really, this could easily be levied against anyone blocking spam in that case. If its their servers and their bandwidth and you're violating their terms of service, I don't see why they HAVE to deliver email or anything else. Heck MSN is effectively blocking linux with the way they respond to search results through their search engines and you couldn't bring a court case against them about that. If CI Host (which really DOES suck and consists of mostly spam and porn hosts)) can't contain their customers - why would AOL be liable if they choose to protect their systems? Last I heard the laws about Cybertresspass (the very laws AOL used to sue spammers - denial of chattel) were in AOL's favor - not CI Hosts'.

  23. AOL Spam blocking not that bad... by LloydSeve · · Score: 2, Interesting

    Honestly guys.. I worked as an Assistant Administrator for an ISP in Michigan. AOL's block list is not that bad. I had a very aggressive list of spam. We actively sent letters to our users telling them to forward us spam, and if legit spam, we added the address to our spam filter. The ONLY ISP that ever affected us by blocking us, was MSN, when MSN.com and Hotmail.com blocked our ISP when their software was messing up. We got our domain unblocked and everything was fine. I support Aggressive blocklists.

  24. Good! AOL is non-compliant anyway... by bourne · · Score: 4, Informative

    Among other petty annoyances, AOL is incorrectly refusing connections from blacklisted hosts, as follows:

    $ telnet mailin-01.mx.aol.com 25
    554- (RTR:BB) The IP address you are using to connect to AOL is a dynamic
    554- (residential) IP address. AOL will not accept future e-mail transactions
    554- from this IP address until your ISP removes this IP address from its list
    554- of dynamic (residential) IP addresses. For additional information,
    554 please visit http://postmaster.info.aol.com.

    According to RFC 821 (sections 4.3 and 4.2.2), the server can respond to new connections in with a 220 ("let's dance") or a 421 ("go away, I have a headache") response. Not a 554 ("you're lousy in bed") code. Among other things, the manner in which they reject mail from residential IPs causes it to languish in the queue, rather than bouncing as it should if they intend to permanently refuse delivery.

    I'm sure they do this intentionally so that it will look like your mail server is at fault ("sorry, couldn't get through") rather than theirs ("buzz off, I don't like your IP address").

  25. CI Host by suwain_2 · · Score: 3, Informative

    For those thinking that CIHost sounds like some insane overlitigous company that tries to use lawsuits to make its profit... You're right. :)

    I spend some time at WebHostingTalk.com (a huge forum site for web hosting), and they have a horrible reputation. Actually, you can't search for "CIHost" -- it's banned, apparently due to WHT itself being threatened with legal actions because of posts about CIHost in the forums. But I've read some posts about "See Eye Host" and such. :) You can play with the search and creative misspellings, and you'll find a lot of posts about them.

    --
    ________________________________________________
    suwain_2 :: quality slashdot p
  26. Much as I hate AOL... by petard · · Score: 2, Interesting

    I hope they win this one. First of all, CI Host are a bunch of f$cking spambags. Second of all, it'll be a dark day when a court forces someone to carry unwanted traffic. AOL owns their own network. AOL can decide who they want or don't want to accept mail from, for whatever reason AOL wants. If AOL customers don't like AOL's decision, they'll leave, and AOL will lose in the market. Oddly enough, only spammers seem to have any trouble grasping the fact that a network owner can restrict what flows over said network for any reason at all.

    Free advice to CI Host: Your legal action has just landed you permanently on hundreds of private blocklists. I know of at least 5. You and your customers now going to have a lot more trouble getting your mail deliverd to many more places than AOL. Find a new line of work because no netblock you are associated with will ever be useful for email, which you indicate to be your main line of business in your lawsuit. Cut your losses and get off the net now. Sell your equipment on eBay. Sell your netblocks back to ARIN. Do something productive. You'll be happier if you avoid the world of frustration you just entered. Just unplug instead.

    --
    .sig: file not found
  27. About time... by smash · · Score: 3, Informative
    As I see it, AOL should be able to do what they like with regards to data entering/exiting their network, and in fact, I'm willing to bet dollars to donuts that they have words to that effect in their customer contract.

    So, given that their users have signed up consenting to this, the only people who can legitimately be pissed, are third parties - who have no right to use AOL's network at all.

    nutter.

    --
    I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
  28. AOL mail filtering to the extreme by japorms · · Score: 5, Informative

    I work for an ISP (holding the name for obvious reasons). We recently had a customer abuse our AUP by sending 3,000+ unsolicited emails with attachments to AOL customers in just one week (total emails reached ~18,000). AOL in turn blocked any and every email with attachments from our domain indefinitely. Our legal team is now trying to resolve this issue with them. Even though emails without attachments go through fine, it has become a huge inconvience for many our customers. I don't understand why they did not block the specific account only instead of our domain. The following is the rejection notice we receive when sending emails with attachments to *@aol.com: > ----- The following addresses had permanent fatal errors ----- > > > ----- Transcript of session follows ----- > ... while talking to mailin-02.mx.aol.com.: > ... while talking to mailin-03.mx.aol.com.: > >>> QUIT

    1. Re:AOL mail filtering to the extreme by RipCurl808 · · Score: 5, Interesting

      Its their servers and if you still kept the person on your server ( as a customer ) after the the first day of the abuse ( says you took 1 week to notice; that's far too long to notice an abuse ). Did you not read your Abuse@ when the first spam message was reported? Why'd it take you so long to act?

      A spam run doesn't just happen for a week long without going unnoticed. Your server logs would have shown the unusual amt of traffic being sent from your space.

      Just playing devi's advocate. Again, AOL can run their servers as they like. Dont like it? Set up a smart-host so you can send attachment from that ip unti lits resolved.

      Oh and is that customer still with you? The one that spammed? Why not collect damage fees from them?

  29. Frivolous at best.. by RipCurl808 · · Score: 2, Insightful

    It was already tried with CompuServe vs Cyberpromotions where the judge ruled that a server/admin has the right to block any traffic or spam/email/connections from accessing theirs.

    CI HOST is a notorious spamhaven and I would love to show that CI HOST is indeed tolerant of their spamming customers and do jack about booting or disconnecting them. They have /dev/null who works at abuse@ . No morals whatsoever.

    IF they dont' want to play nice on the net, then they will be delgated to the corner until they do. Or suffer the interne equivalent of a death sentence; be happy in your intranet CI Host. You haven't been allowed on my networks for the last 2 years; think this lawsuit is gonna help ya much?

  30. CI Host has been good to me by budcub · · Score: 3, Informative

    I've been a happy CI Host customer for almost two years. My domain gets very little traffic, but the few times I've had to call for support, they've been quick and very helpful.

  31. OK, I have a question about AOL spammers by annielaurie · · Score: 2, Interesting

    I know it's supposed to be easy to forge a "from" address in the header of an e-mail. This is a favorite spammer trick.

    Would one of you folks enlighten me on whether it's possible to easily forge or otherwise disguise a "bcc" or other portion of the "to" section?

    I operate a website (hosted by a third party provider) that's been hammered this past week by someone who vainly hopes to exploit Formmail. He takes an unseemly interest in the cgi-bin and cgi-sys directories and is cheeky enough to blind-copy an e-mail address at AOL with the results.

    He won't get anywhere because I haven't got Formmail installed, but he is as aggravating as hell, and not a little scary.

    AOL's attitude is that if he is indeed one of their subscribers, he's entitled to their protection, and they won't lift a finger no matter what he's doing or who he's injuring. In other words, if you've got a commercial site and it's third-party hosted, you're fair game for any of their bad kids who wish to harm you, forge your domain name, or whatever, under the guise and protection of AOL. I was told this at about 5:30 p.m. today by one of their "customer service" representatives.

    Before I talked to them, I was primarily annoyed. Now I'm really angry. I'd like to enhance my knowledge about this as I consider what to do. Knowledge is power; it's just sometimes difficult to acquire adequate knowledge while you've got so much else to do.

    Thanks!
    Anne

    --
    DUCT TAPE: The Election Supervisors' Secret Weapon
  32. AOL is RFC-compliant; you have an archaic RFC! by Frater+219 · · Score: 4, Informative
    According to RFC 821 (sections 4.3 and 4.2.2), the server can respond to new connections in with a 220 ("let's dance") or a 421 ("go away, I have a headache") response. Not a 554 ("you're lousy in bed") code.

    You're citing an out-of-date RFC. 821 was superseded by RFC 2821, which makes it clear that 554 is a valid connection-opening response, to indicate that mail service is not available. (Indeed, 2821 spells out two codes for use at connection establishment -- 220 to accept, or 554 to reject access.) AOL is correctly using 554 to indicate that it will not provide mail service to your IP address.

    A 4xx code would be improper in this case. 4xx codes indicate temporary failures. They mean that the client should queue its messages and retry them later, rather than returning a bounce message to the sender. That's not what is intended here -- the server doesn't want you to retry, it wants you to not try. A 5xx error code is correct.

  33. You're totally right by Raul654 · · Score: 2, Interesting

    The FTC brought an antitrust complaint against a company (can't remember which one at the moment) in the 70's (I think). In that case, the target company had around 65% of the market, and it was ruled that that was insuffecient to be a monopoly. In this case, I don't think AOL has anywhere near 65%. 30 million customers (what AOL claims to have, but they were recently accused of inflating that) is small compared to the number of ISP subscribers; laughably so to be called a monopoly

    --


    To make laws that man cannot, and will not obey, serves to bring all law into contempt.
    --E.C. Stanton
  34. From Rutgers University by mikeage · · Score: 4, Interesting

    One of our TD guys posted the following:

    We just finished a conversation with staff from AOL's postmaster team. We have an agreement, but it may or may not be satisfactory to users.

    First, let me say what they are doing. They have a button on their mail software that lets users report email as spam. They check to see the host
    from which AOL got the mail, i.e. the previous hop. In principle, if they get a significant number of complaints for any given host, they refuse to accept mail from it. In practice, there is sometimes human review, although they don't guarantee to do that. In practice, they will often alert abuse@rutgers.edu before cutting off mail, although they don't promise to do that either. They will, however, allow us to give them a list of our major MTA's, and exempt that list. What we believe they will do reliably is notify us after the fact when they have cut an IP address off. We will dispatch those reports to the liaison.

    They should have most of the major MTA's by now. However we don't have a complete list of all MTA's on campus, so it is certainly possible that in
    the future some might be cut off. If that happens, we will find out about it after the fact. In some cases, the abuse staff may recognize it as an
    MTA, and ask them to add it to the list. However we won't always know the way departments use systems, and thus cases might occur where we would have to depend upon responses from the system administrator.

    Note that in principle they could remove systems that send announcements to the user community, if users report the messages from the President or
    other official email as spam. They regard the customers as right, and accept their definition of spam. In practice, that system will be on the
    list of MTA's. For the moment they look OK.

    There are some systems that were on earlier lists that we have been unable to understand. In one case we verified that they had no forwarding entries pointing to AOL. The system itself is not an open relay, and being Solaris, would not have been contaminated by Sobig. In the discussion today, it didn't seem possible to develop an understanding of what had led to these systems being considered problematical. However those systems are MTA's, and should not be cut off in the future.

    They have offered to send us all email from any Rutgers host that users report as spam, so we can review it and try to forestall any problems.
    Since this is in the thousands per day during periods when problems are occuring, we are not currently taking them up on this. In the opinion of our staff, if AOL can't afford the staff time to do intelligent review of their own users' reports, we can't do that job for them.

    In this situation, I recommend that no system administrator use AOL for email, since we need to make sure we can contact sysadmins no matter what
    decisions AOL might have made. Other uses with critical need for mail connectivity might want to do the same. Also, it might be useful for users
    to understand that they should be careful about reporting as spam mail that comes through Rutgers.

    --
    -- Is "Sig" copyrighted by www.sig.com?
  35. Do you have to ask? by YrWrstNtmr · · Score: 3, Funny

    Today's Monday. Is Monday a 1 or a 0?

    Monday is definately a zero.

    1. Re:Do you have to ask? by quantum+bit · · Score: 2

      Monday is definately a zero.

      Then is 0 odd or even?

  36. Wait for the audible groans... by EverDense · · Score: 2, Funny

    Your days are numbered? ;-)

    --
    http://jesus.everdense.com/
  37. i have been affected by FinalCut · · Score: 2, Interesting

    I have a personal blog domain that I use to keep my family and friends updated about my life. Since I have moved alot it has been a great way of keeping open the lines of communication. However, recently, AOL has stopped letting my updates reach my 2 Aunts in Mass. And it is pretty annoying. I appreciate the fact that AOL is trying to cut down on SPAM - but damn! Gimme a break - let me SPAM their server first before they ban my domain. I only send about 2 emails a month (one to each aunt) to their servers.. Seems like AOL spent more effort blocking me than I did emailing their pop servers.

  38. Re:Bullshit (arrogant zealotry is a bad thing) by obiwan2u · · Score: 3, Interesting
    AOL was definitely guilty of arrogance in many things, but I think that with respect to email and spam, they're probably more guilty of ignorance. Some background... (actually, lots of background)

    Historically, AOL has viewed itself as an entertainment company. The AOL muckity mucks cared about the big business deals, the marketing drive that will change the world, etc. The media mogul in Barton Fink is an example of the style of executive that ran the show during the height of the dot.com bubble.

    But AOL Email Operations was just another overworked technical dept. The email application didn't bring in any revenue directly. Also, it was an overhead application that couldn't be cleanly assigned into one of the Balkanized divisions at AOL. For years, it had little marketing and little development effort applied to it. Buying Netscape for $4 billion dollars got lots of attention, upgrading the pre-internet AOL email infrastructure didn't.

    The top level AOL exec's heard about spam complaints, but they heard lots of complaints about lots of things. Nothing was catching on fire and exploding in email so they assumed it must not have been that bad.

    Another reason why AOL business exec's tended to ignore the techies. Keep in mind that hardcore techies had spent years vehemently ragging on AOL. Inspite of that, AOL became a major business success (well, at least for a few years). So whenever an internet purist gave a lecture on how things were supposed to be done, it triggered a gut level hostile response with many exec's at AOL.

    So the result of all of this is, for the past several years, there were only background projects for fighting spam (and handling ISP complaints). Current problems are a result of that legacy.

    But I think things might be changing. Remember AOL tried to takeover Time Warner? Well Time Warner has essentially staged a reverse coup and kicked out all the "deal junkies" at AOL. I think the Time Warner folks are pushing a much more back to basics approach for business deals, financial accounting, and for the AOL online service.

    The upcoming AOL 9.0 release is supposed to be a lot better at spam fighting (although I haven't tried it much yet).

    I hope that the new exec's really are making spam fighting a strategic priority (which I think they might be). If so, you should see real results in a year or two. Including, hopefully, a lot less false positives for spam (where positive really means negative delivery of mail, whatever) and much higher levels of support for email delivery complaints.

    --
    Ben in DC
    "It's the mark of an educated mind to be moved by statistics" Oscar Wilde
  39. All I know... by mod_critical · · Score: 2, Interesting

    All I know is that CI Host is a worthless hate spreading worm garden. My host, OC Hosting (ochosting.com), bless their souls they are such wonderfull people to be a client of, has had trouble with CI Host in the past.

    About a year ago when OC Hosting pulled out of renting space at CI's data centers, CI told them that they couldn't get in the building even to take their machines out without signing a year contract for the space they used. Because of this I (foreverdreaming.net) and other OC customers could not get our files because CI was holding the servers.

    After this I have had a constantly living anamosity for CI that ignighted like a torch when I read this article. I hope AOL wins and finds a way to file a counter-claim and hopefully wipe the worthless hate spreading scum that is CI off the face of this beautiful planet.

    haha - for a year I've hated you and now I get a chance to express it in public forum, yay!

  40. Re:No, we DON'T always have a choice of provider! by RipCurl808 · · Score: 2

    This is what you blacklist zealots (read: SPEWS junkies) just don't get -- many of us do NOT have a choice to move from our current service provider, for all intents and purposes.

    No its net scum like you who dont understand. That's why you get lawyers to help you out. Pass the cost onto those who costed you business. I have every right to block traffic from space that are only there to serve as abuse breeding grounds. Go look up what happened to AGLX when they decided to only do business with spammers.

    If you have more than just an extremely simple network, moving from one colo to another is a hugely expensive project, both in terms of time AND money.

    haha, like spews listens or reads slashdot. Good thing your belief is in the minority as more isp's adopt SPEWS's methods to blocking spam. BOO whooping HOO. I've been in your position. Guess what? i lost more money because My isp refused to deal with a freaking spammer than I did in the 2 days i was down.

    You are shifting the burden of spam from you to me, when we should be shifting the burden to the spammer by blocking THE SPAMMER. Not LEGITIMATE COMPANIES.

    been there doen that. Blocking only the spamemrs caused teh ISP to only move the spamemr within their own netspace to get around BLOCKS.
    Ever set out a mouse trap. The first day its out with the bait, the mouse gets the chees but didn't get trapped. Set it the next day in the same spot, mouse learned his lesson and didn't go after the cheese. Same thing. ISP's dont care if they get blocked as long as their paying customer is still able to pay. So, if the isp is only going to move when that cusomter is blocked, to a new space, then we aren't going to play their games anymore. We block the entire range until they get a clue. Move the spammer, the blocks get bigger. BOOT the spammer, the blocks go away. How simple can it get? It is one thing to block IP addresses that spammers are using. It is quite another to block an entire class C just because one /28 is being used for spamming.

    The collateral damage argument is bullshit. If you sign a colo agreement with a company, even if you wanted to expend the time and money to move your (otherwise working) network to a different provider, YOU WILL GET SCREWED OUT OF MONEY by the contract.

    BULLSHIT. If you dont go over any contract with a fine toothed comb or with A damn lawyer, you reap what ever disasters come of it. Dont blame your incompetence over signing a contract blindly because you didn't do your homework.

    Sorry for the rant, but you pathetic assholes at SPEWS and similar blacklists deserve a taste of your own medicine. I eagerly await the day you get your just desserts!

  41. Not just email; hypertext links too! by AdrianZ · · Score: 2, Interesting

    The problem is that it's other people deciding what data comes through.

    For instance, LiveJournal. Users have found that AOL is blocking HTTP requests through REFERRERs too . Nothing like having a Journal, and then putting a link to your AOL homepage (AOL Journal, etc) on your LJ profile, only to have people blocked when trying to click through (to see it in action, and you don't have referers disabled, go to fadedsanity's profile and click on the website link "p r i n c e s s". You'll get a 404. Now alter the URL (or whatever you have to do to clear the referrer) and reload the page... it works!). Sure, it's understandable to prevent image embedding (though they appear to only be doing it selectively, like with www.livejournal.com, but not ziemkowski.livejournal.com for instance), but hypertext links as well? That's just too much!

    The annoying issue is that this will undoubtedly lead to hacks (or even features) to stop sending referers, which will affect website statistics, etc.

    Why should the above AOL subscriber not be able to link to her own site? Because other users have marked LiveJournal.com emails as spam? So it isn't just third parties than can be upset; she should be, anybody who wants to access her site through her journal should be, and the third party (LJ) should be.

    Wouldn't it have been a lot less problematic to add a custom bayesian filtering system with spam ratings, that runs on the subscriber's system? I'm sure AOL could have designed an interface and methodology for such a system that would be extremely straightforward to users yet much more effective, all without relying on one subscriber to know what another subscriber thinks of another person's messages? Heck, they could have advertised that they have "Smart" email filtering, yadda yadda yadda.

    You'd think that a company that has acquired sources of programming creativity like Netscape and WinAmp, would be able to meet the interests of their subscribers and investors much better than they have with this.

    How much longer until AOL blocks referers from slashdot?

  42. CI Host must die! by shplorb · · Score: 2, Informative

    CI Host is an evil company. I can't stress that enough. How a company that operates in the manner in which they do is allowed to continue is beyond me.

    Last year I had an account with HostDepartment, which was working very well for me. One day I was told by a friend that something bad had happened to my site. I looked at it and panicked, CI Host had hijacked HostDepartment's domains or something and were telling everyone that they owed them money and had gone out of business.

    HostDepartment are an equally bad company too, steer clear of them. For more information, see the very first news & views article on my website.

  43. Re:I blocked rutgers.edu this week by hedrick · · Score: 2, Interesting

    The Rutgers central systems are in the process of moving antivirus processing from "appliances" made by a major AV vendor to our own Linux systems using Amavis. Amavis is smart enough not to send notifications to users in response to Sobig. The appliances do not appear to have an option to disable this. The move isn't quite finished, but the high-volume systems should now be on Amavis. That change is quite recent.

  44. Is this the big one? by lynx_user_abroad · · Score: 3, Insightful
    This case could be bigger than any of us here and now expect.

    I expect the two litigants will need to sort out the issue of who own's AOL's network? and that depending on the outcome, things could change direction radically.

    There seem to be a lot of people on /. (and on the Internet in general) who are opposed to SPAM and ready to support any cause which makes it more difficult for SPAMMers to operate. As such, they applaud AOL's efforts to keep undesirable content out of it's network.

    But there also seem to be a lot of people on /. (and on the Internet in general) who support Free Speech, and are appalled when a single company (like AOL) uses the network of computers it owns to build a "gated community"; an Internet where you or I must pay to play.

    These two positions are incompatible as currently conceived. Anyone who agrees with both of the above needs to do some soul searching.

    If we acknowledge the right of AOL to control how it uses it's own network, then we can applaud when AOL blocks SPAM, but we cannot complain when they start blocking mailing lists, or shutting down p2p sharing, or refusing to allow their subscribers VOIP capability, or block access to web sites. We may eventually find that the only sites with any reasonable connectivity are the ones which can only be accessed through AOL.

    Alternately, we could decide that AOL's network services are a type of Common Carrier network, like the airlines and the telephone system. This would mean that AOL could not prevent an AOL customer from subscribing to mailing lists, visiting web sites, or setting up their own web server. But it would also mean that SPAMMers would be guaranted a equal access to your inbox, and your neighbors worm-pool box cannot be legally blocked, so long as the worm abides by the Common Carriage rules.

    --

    The thing about things we don't know is we often don't know we don't know them.