SendMail CTO Sounds Off On Spam and FTC
CowboyRobot writes "Eric Allman takes his well-deserved turn in commenting on the state of spam, the dark future, and the need for intervention.
He calls spam an "arms race" where "in the long run everyone loses (except the arms dealers)."
As you might imagine, he's on our side, and he does a good job of clearly describing the current state of spam, and the possible solutions."
....the more I realize that no amount of technology or legislation is ever going to completely eradicate spam from our lives. More and more it seems to me that the only way we can get rid of spam is through educating the next generation of Internet users to ignore it.
Spammers spam because they make money. Educate people to ignore spam, and the spammers don't make money. Bingo, no more spam!
I know it sounds like a pipe dream, but what other options are there?
SCREW THE ADS! http://adblock.mozdev.org/ Proud user of teh Fox of Fire - Registered Linux User #289618
The do-not-spam registry will not work primarily because A. spammers are already breaking the law to spam, and B. it's easy to set up an offshore spam factory outside the US to send spams. Unlike telemarketing, where making phone calls to other countries is too expensive, it's fairly cheap to bypass legislation and spam outside the US...not to mention a do-not-spam registry is stupid in the sole fact that it gives spammers a huge list of millions of VALID email addresses - doing their job FOR them.
Why can't certain specified mail servers be something like the look outs. If a certain percentage of them recieve the same email in a specified amount of time then they can designate it as spam and delete it from all the mail servers. then ISP's could subscribe to the "lookout server" list and delete any messages that have been designated as spam?
http://Lenny.com
Spammer ahoy! Lock up your open relays! Ready your blocklists!
In case you didn't bother reading the article, it mentioned that the volume of spam was doubling every 10 weeks. This is nothing short of a threat to the viability of email itself. Would you even bother opening your inbox, if you knew that you would have to delete several thousand irrelevant, unwanted and (in many cases) fraudulent emails just to get to the 10 or 20 useful ones from friends and family? Spammers are intensely selfish - being quite happy to abuse the network infrastructure provided and paid for by others for their own gain.
Your statement about the meaninglessness of the internet shows that you haven't a clue (outside of those spam-rimmed spectacles) what the Internet is about. People do not wish to be deluged with unsolicited junk any more than the likes of Alan Ralsky likes receiving tons of junk snail mail.
Of course, you can try to prove me wrong - post your email and real address and let's see if you can swallow your own medicine.
It sounds like a good idea on the surface, but it won't work.
I got hit by a spammer last week who was changing his host names every couple of messages. And not just on the envelope - he was changing 'em in DNS because he had his own nameserver! He got shut down by the mid-level carrier after about 12 hours, during which my servers received thousands of messages that I had to block by IP. Today, though, I am getting the same stuff, now coming from a cracked cable-modem user.
Hundreds of the spams that hit here every day are sent from cracked systems connected to Comcast, RoadRunner, and Verizon DSL.
If you allow anyone to send mail, regardless of how that mail is encrypted or secured, the spammers will find a way to illegally take advantage of that legitimate mailserver and send their trash.
This is because they are criminals. Not "legitimate businessmen" and not "entrepreneurs exercising their freedom of speech". Criminals who purchase accounts with stolen credit card numbers and move on as soon as an ISP shuts them down.
The spam problem has to do with the whole future of person to person communication, as well as the whole future of adverticement. Whichever way it will be solved, a very likely outcome is that in 10 years it will no longer be possible in any way to get in touch with someone you don't already know from outside the Internet, and the first decade of Internet will be looked back upon with nostalgia as the only decade of totally free communication. This is because the real problem lies in the initial contact.
You might argue that we can still communicate via boards, chat channels and similar things, where you can give out crypt-keys to those you wish to continue communicating with, but remember that these will be the next target for adverticing after open email collapses. I'm sure adverticers will even write AI's to simulate people so that they can lure the crypt-keys from innocents.
Seriously though. The bulk of spam originates in America.
Personally, I don't buy that that is true, but it's completely irrelevant to my point. Even if most spam does currently originate in America, if the U.S. somehow passes and enforces an effective anti-spam law, there is effectively zero cost involved in these spammers moving there business out of the States and still spamming Americans.
The same is true for any country that illegalizes unsolicited e-mail.
This is one reason (among many), why spam is much harder to control than telemarketing, the fact that telemarketing from another country is expensive.
lysergically yours
As much as I find balkanizing the network to be philosophically repugnant, there is a second step that is not often discussed in the context of US legislation against spam.
Once spam is banned in the US, we (the network operators) have to block traffic from netblocks assigned to countries that are friendly to spam. The legitimate business and communications needs of those countries will then drive them to enact their own anti-spam policies to get off the block lists. If their only need for the network is to send spam, then they will soon find themselves isolated and ineffective.
I don't like it, but to me it looks more and more like the lesser of evils...
Trouble making decisions? Just flip for it.
The do-not-spam registry will not work primarily because A. spammers are already breaking the law to spam, and B. it's easy to set up an offshore spam factory outside the US to send spams.
If the do not spam registery, as proposed by at least some lawmakers, penalizes the beneficiaries of the spam, then the true source will still be subject to the regulations. Sure, some offshore businesses will continue to spam, and some big guys may move off shore, but it really will nullify many of the cost advantages of spam. Few people are going to refinance their mortgage with some stranger in Costa Rica (then again, I never thought people would do that with a stranger who randomly spammed them either).
not to mention a do-not-spam registry is stupid in the sole fact that it gives spammers a huge list of millions of VALID email addresses - doing their job FOR them
This is the hard part. How can you make it a crime to traffic or abuse a list of email addresses? I don't think it would hold up well in court. If it did, the validity of the lists would be come problematic - how do you prove the citizenship or residency of someone just by an email address? This is where it completely falls apart. If there were a DNS (do not spam) list, I think I would first sign up with a fresh new email address, say dnc@mydomain.com, just to see how it worked. I'd be surprised if it did not result in more spam.
I think the thing that will kill spam is the success of email marketing. I work at a company that does email marketing - i.e. - VERY targetted campaigns (usually under 1,000 recipients, most of whom have some sort of business relationship with the client), easy ways to unsubscribe, always a valid reply-to address, etc. The results are great - we usually get about 80% opens and 10-30% click-throughs. We have one list/service that has 1,000 emails and gets 500 click-throughs when we send to it!
I get frustrated when I hear about ClickZ calling an email campaign to 800,000 people, where many people got the email up to six times, and they got a 4% open rate with a 4% click-through rate OF THE OPENS (i.e. - a 0.16% click-through rate), and called it a great success. Email marketing is a great tool, but spam really hurts it.
For example, I _love_ getting my email at half.com telling me that a book I want is available at the price I was looking for it. It doesn't even seem like marketing. It's cheap, trackable, targetted, and they can load it with whatever other marketing message they want, too.
Anyway, one thing that annoys me about slashdot is that everyone seems to think that all email-marketing is spam, when there are at least some of us that are trying to do the right thing.
We actually have customers that we tell them _not_ to use our service because they don't have a legitimate list. We tell them to start right now and get everyone's email address they can - have places on every form for people to get their email address, have a "newsletter sign-up" link on their website, etc., and then call us in a year with the list they put together and we'll help them with a campaign.
Engineering and the Ultimate