Slashdot Mirror


AT&T Moves Toward Mail-Server Whitelist

Gunfighter writes "In an apparent attempt to quelch the amount of incoming spam, AT&T has asked their customers, partners, and business clients to provide them with IP addresses of their mail servers. All other mail will be discarded. To quote the message: "... In order to continue to allow email to AT&T you need to provide the IP addresses of all your outbound email gateways. If you do not respond immediately, your access may not continue.""

73 of 447 comments (clear)

  1. I work for AT&T! by Anonymous Coward · · Score: 4, Interesting

    And it's been blocking email I send to my work account! Now I understand what's going on.

  2. Oh well. by Doktor+Memory · · Score: 2, Insightful

    SMTP email was nice while it lasted.

    Semaphore, anyone? Smoke signals?

    --

    News for Nerds. Stuff that Matters? Like hell.

    1. Re:Oh well. by kryzx · · Score: 2, Insightful

      No, those links you list are to blacklists. What AT&T is doing is exactly the opposite, a whitelist. Rather than making a list of spam servers to block, they make a list of trusted mail servers that are allowed to send to them.

      This is the future of mail, and the only reasonable way to solve the spam problem. In the future you will have the ability to specifically grant email addresses or mail servers the right to send you messages, denying all others.

      --
      "I don't know half of you half as well as I should like, and I like less than half of you half as well as you deserve."
    2. Re:Oh well. by letxa2000 · · Score: 2, Insightful
      This is the future of mail, and the only reasonable way to solve the spam problem. In the future you will have the ability to specifically grant email addresses or mail servers the right to send you messages, denying all others.

      That'd no longer be email. Once email is no longer open to anyone that wants to send you email or once email starts costing money the email we've known for decades is history. It'll be a burned out shell of the useful and powerful thing that has been email to date and which has caused worldwide communication like no other technology.

      I wish more people and companies would start taking approaches to spam that truly target spam rather than saying, "I'd rather not communicate than get spam." We need to get rid of spam, but if we lose the benefits that made email popular and useful in the first place then it's a scorched earth policy.

      In other words, what good is implementing some anti-spam idea if it doesn't just get rid of spam but also gets rid of valid communication? These ideas should be non-starters.

  3. So what's to prevent.. by dr+ttol · · Score: 3, Insightful

    ..the spammers to get AT&T to whitelist their IPs?

    1. Re:So what's to prevent.. by YouHaveSnail · · Score: 4, Insightful

      Well presumably, any gateway that delivers significant amounts of spam to AT&T will be removed from the white list and added to the black one.

      Their whole approach may or may not work, but it's an interesting idea. The PGP "web of trust" concept never really caught on among the general public, but creating a web of trusted mail servers would seem like a simple and effective defense against spam. AT&T's move might be the first step in that direction.

      The next step, of course, would be either a new protocol or an extension to an existing one that would let one mail server ask another "Hey, smtp.xyz.com wants to exchange mail with me, but I've never heard of him. Do you know him? Do you trust him?" If VeriSign really cared about innovating and improving the net, this is the sort of thing they should be working on.

    2. Re:So what's to prevent.. by moonbender · · Score: 2, Interesting

      The vast majority of servers will be caught by the white-list. The very few who are smart/dumb enough to register on it can easily be handled by the blacklist - and, since assumedly the whitelist registration contains contact information, possibly be held responsible for their spamming.

      --
      Switch back to Slashdot's D1 system.
    3. Re:So what's to prevent.. by swordboy · · Score: 2, Funny

      "Hey, smtp.xyz.com wants to exchange mail with me, but I've never heard of him. Do you know him? Do you trust him?"

      Its a mail server... not a male server...

      --

      Life is the leading cause of death in America.
  4. All it takes by lingqi · · Score: 4, Insightful

    is a few span servers to get on the list, and a few legit servers to get hacked and taken off the list (and tries to get on again) before there will be hell and ATT would have to abandon the plan, wasting all these time and resources used to instate this plan in the first place.

    Great shame, really...

    --

    My life in the land of the rising sun.

    1. Re:All it takes by HBI · · Score: 5, Insightful

      The servers will be now identified by customer.

      The incoming spam will then have an owner tied to it, who will be held accountable. It's a very workable system actually and not as prone to failure as you are alluding.

      --
      HBI's Law: Frequency of calling others Nazis is directly correlated with the likelihood of the accuser being Communist.
    2. Re:All it takes by seanadams.com · · Score: 2, Funny

      The solution is pay-per-mail. I set my price at $1 per email. The charge is forgiven if I reply. You spam me at your expense - I'll happily accept the $100 per day.

    3. Re:All it takes by lingqi · · Score: 3, Insightful
      The servers will be now identified by customer.

      and if a popular server is identified by many customers? like, say, hotmail?

      and there ARE cases where somebody might want to send email to a person with no prior contact - the "long-lost HS friend" is overused, but take other examples - say I am active on a mailing list and somebody want to ask me something, or if somebody is replying to my advertisement on ebay. there are TONS of problems with a whitelist-only approach.

      --

      My life in the land of the rising sun.

    4. Re:All it takes by l810c · · Score: 4, Funny
      And what the recourse for the Customer? Call or email the ISP to get xxx.com on their whitelist?

      Here's some samples:
      'I just signed up for fatanalhos.com and they emailed me my password. I didn't get the email. Could you please put fatanalhos.com on your Whitelist?'

      'I just ordered some penis enlargement cream, but I didn't get my email conformation. Could you please Whitelist myphatcock.com?'

      'I'm expecting a large sum of money from Nigeria and I can't get my emails...'

    5. Re:All it takes by rc.loco · · Score: 2, Interesting

      Um, while I'd like to believe you, it doesn't look that way to me.

      dig mx att.com

      then telnet to port 25 for each MX host

      I get no response from any of them.

      It's a crying shame we've gotten to this point, I've been waiting for it for at least a year or so. All because of a bunch of greedy lowlife spam-spewing bastards who decided to capitalize on a resource to which NONE of them likely ever contributed anything of any value.

      The IETF really needs to re-engineer SMTP, a la djb's model or something akin to it. Make these spam bastards pay for their putrid abusive ways!

      --
      --rc
    6. Re:All it takes by platipusrc · · Score: 2, Insightful

      Wow, ok it looks like I was mistaken. I also get no response when I try to telnet there. I also get no response from the University of Georgia computer science department's mail server. Hmm. But how does this work? It looks to me that the only effect this will have will be to anger customers because they can't receive mail from most locations. It would really suck to be a student at UGA and have ATT's service right now during registration and miss some fairly important emails that the registrar's office and others send.

      --
      And the muscular cyborg German dudes dance with sexy French Canadians
    7. Re:All it takes by KindAloysiusX · · Score: 4, Funny

      I don't think this scheme is scalable. What if you and I want to have a conversation? Do we have to exchange mail forever?

    8. Re:All it takes by bobv-pillars-net · · Score: 3, Informative

      dig mx att.com

      then telnet to port 25 for each MX host

      I get no response from any of them.

      Keep trying. According to my logs, about 30% of the time, they DO respond. I don't know if they're overloaded 70% of the time or if their IP-filter breaks 30% of the time, but if you keep trying long enough, you will get through.

      --
      The Web is like Usenet, but
      the elephants are untrained.
    9. Re:All it takes by Schmucky+The+Cat · · Score: 2, Insightful

      Um, you're connecting to a server that uses ATT bandwidth, not an ATT server.

  5. I wish they'd turn this around by Webmoth · · Score: 3, Insightful

    I had an "unpublished" landline phone number, and chose a third-party carrier for my long distance service. AT&T called me every week as long as I had that phone line, trying to sell me long distance service, no matter that every time I called, I said "no" and told them to never call again.

    It seems that AT&T thinks that if you don't want to do business with them, then they automatically deserve to be on your whitelist.

    Voice spam is just as bad as email spam. Even worse, since you can't deal with it on YOUR time.

    --
    Give me my freedom, and I'll take care of my own security, thank you.
  6. Re:I don't care by scrote-ma-hote · · Score: 2, Interesting
    Until they also ask AT&T to whitelist them, spammers work on sheer volume, and could simply ask to be whitelisted en masse. It will either have to be automated and they win, or they'll flood the network with requests and screw it up for everyone else who tries to white list.

    Personally, I can't see this working very well.

  7. Somehow ... by RWarrior(fobw) · · Score: 2, Insightful
    ... this doesn't surprise me.

    On the other hand, there are other approaches just as destructive.

    I run an outbound SMTP server for my own personal use, in part because my ISP's SMTP server sucks.

    At times, it could take 30 or more minutes to relay an email to myself.

    One of the problems with this is that apparently I got listed on some kind of dial-up user block list, and my mother's ISP blocks those users from sending to its users.

    The downside is that my mother's ISP also blocks my ISP's SMTP server.

    Isn't that useful.

    --
    Remove the caps and hold to a mirror.
    1. Re:Somehow ... by Rick+the+Red · · Score: 4, Funny
      You must be a spammer. That's the ONLY way your SMTP server could get blacklisted. Oh, and your ISP must harbor spammers, too, otherwise there's NO WAY they could be on some blacklist by mistake. OH, NO, the spam vigilanties NEVER make mistakes and blacklist an innocent party. NEVER.

      Really, never. Just ask them.

      --
      If all this should have a reason, we would be the last to know.
    2. Re:Somehow ... by CerebusUS · · Score: 2, Insightful

      Slashdot really needs a tag

    3. Re:Somehow ... by AKnightCowboy · · Score: 2, Insightful
      The amount of spam coming out of rr.com is about equal to the amount of spam coming out of korea. At least for me it is. Charter isn't as bad, but it's a major source too.

      The trouble with spam is, we're all complaining about it, but most of the time it isn't illegal! Until spam is illegal than blocking it through technical means and blocking IP address ranges carpet-bomb style to try to prevent it hurts legitimate users more than it hurts the spammers. The spammers will just be moved by their spam-friendly ISP to an unblocked range and resume their activity while leaving a scorched earth of address space behind them. That's the problem with all these god damn blacklists, especially ones like SPEWS who actively seek to punish everyone getting service from an ISP for the sake of hurting a couple of people.

  8. Huh? by Aurix · · Score: 3, Insightful

    This can't be right... Most businesses have no idea what an IP address is, let alone the IP addresses of people who send them email... It sounds like an utterly stupid plan. What's to stop spammers sending them IP addresses of their mail sending boxes or open relays?

  9. Five emails by poptones · · Score: 2, Insightful
    That's how many "spams" I've received in the last three months. And three of them came just today because two days ago I stupidly obliterated my mozilla profile and the (few) mail rules I had set up were lost.

    I wonder how the people on AT&T's ISP networks are going to feel about not being able to communicate with mom and dad in Singapore? And all those folks (or those few folks, I suppose, depending on who you hang with) running personal SMTP services from their homes for the added privacy it buys them.

    Yes, there's a lot of trash spam out there. It's NOT impossible to stop, but solutions like this one are not going to substantially help. If AT&T closes off its mail network to the world outside, those broadband customers running open proxies just become that much more valuable - then ATs own customers become the conduit of the spam they are trying to squash. There are thousands of "questionable" usenet posts that originate from roadrunner and AT&T and pacbell and earthlink usenet servers that are proxied there through their own broadband customers. Even locking those customers down to port 80 access won't stop trojans and backdoors, so logically I guess this is just the first step to AT&T closing off its network from the internet entirely?

    Maybe they'll just firewall all their customers in and dish out the DMCA approved web pages through proxy farms... that'll teach those evil spammers!

    1. Re:Five emails by poptones · · Score: 2, Insightful
      Spam is not free speech. Spam is advertising. Advertising is not covered under the first amendment, there are rules for commercial speech that are separate from private speech.

      And, as I already pointed out (and as we all knew anyway) there are already LAWS regarding the matter. It is not the responsibility of the ISP to determine for me what mail I should receive and what I should not. And, if they should decide to take upon themselves that responsibility without my behest, they still must be held accountable when they fail it.

  10. Users don't know what to do with this . . . by actappan · · Score: 5, Insightful

    I'm oversee an it department. While we're lucky enough to have a highly technical user base there are still users that need a little help. And some of them will have to write at&t.

    "Solutions" like this do little to stem the tide of spam, they only shift the burden to others. Now, in order to ensure that my users can send email to the customers and contacts they need at att&t, I have to keep them up to date with our whereabouts on the net?

    Earlier this year we had to deal with a spat of denied messages cause when a number of large organizations blocked our entire address block because they believed it was a DSL block. This was the only reason. Not that spam originated from any of these addresses,

    The only way to stop spam is to stop the spammers. The only way to stop the spammers is to stop those that pay them or otherwise make money trough the spam.

    --
    \Drew National Data Director, John Edwards for President
  11. This is just wrong in so many ways... by Fnkmaster · · Score: 5, Insightful
    So if each big company decides to do this, they will all end up with slightly different lists of whitelisted SMTP servers. The Internet will degenerate into a fragmented, unreliable system where you never know who will receive your email. In fact, you'll be strong armed into using particular ISPs and using email addresses like shithead@att.net in order to get your email through to anybody. The Internet is thereby de-democratized and rolled back 10 years.


    This is really a lose-lose situation and it's disappointing to see this. If there's going to be a concept of trusted mail servers, we need to use a technological solution that allows easy, open, and transferable trusted participation in the network - maybe for once an application where a web-of-trust would actually function. Even the current system with centralized, subscription-based blackhole lists is far better - at least you only have 5-10 different places to go if you end up on somebody's shit list.


    In the dark world of the future you'll have to fight your way through bureaucracy and stupid sysadmins (and yes, the vast majority of sysadmins are fucking idiots, though I know that's not a popular opinion around here) for each and every company, organization or domain you want to send email to. That sounds like an infeasible, unmaintainable system to me.


    Personally, I find the spam filtering on my fastmail (www.fastmail.fm) account to be incredibly reliable and effective, and I've found that if I bounce back every piece of true spam I get, over a few weeks or months, my rate of incoming spam seems to decrease substantially. We can do better, and we will beat the spammers, but we don't need to throw out the baby with the bathwater.

    1. Re:This is just wrong in so many ways... by bigberk · · Score: 4, Insightful
      So if each big company decides to do this, they will all end up with slightly different lists of whitelisted SMTP servers. The Internet will degenerate into a fragmented, unreliable system where you never know who will receive your email. In fact, you'll be strong armed into using particular ISPs and using email addresses like shithead@att.net in order to get your email through to anybody. The Internet is thereby de-democratized and rolled back 10 years.
      Spot on, mod this guy up. He hit the nail on the head.
      I've found that if I bounce back every piece of true spam I get, over a few weeks or months, my rate of incoming spam seems to decrease substantially
      Except for this bit. Never try to bounce spam, it just goes to the wrong destination and further pollutes the Internet.
    2. Re:This is just wrong in so many ways... by jred · · Score: 2, Funny

      Slashdotted? :)

      --

      jred
      I'm not a mechanic but I play one in my garage...
    3. Re:This is just wrong in so many ways... by Chmarr · · Score: 4, Insightful

      I think you're mistaken. When he says 'bounce spam' he doesn't mean composing a new message and sending it to the 'envelope from'.

      He means ensuring the spam message gets a 550 code, or something similiar, rather than 'accepting' it and trashing it later.

    4. Re:This is just wrong in so many ways... by Halo1 · · Score: 2, Informative
      Maybe because their incoming mailservers are:
      att.net. 6H IN MX 5 gateway2.att.net. att.net. 6H IN MX 5 gateway1.att.net.
      Or are you a client of AT&T that must send his mail through their outgoing mailservers?
      --
      Donate free food here
    5. Re:This is just wrong in so many ways... by lardi · · Score: 2, Informative

      Working as the sysadmin for our company I would like to tell you ablout the latest UCE complaint that has hit my inbox.. We run a community website that sends out newsletters to our customers. This newsletter is sent out if the users does not uncheck the box "Yes I want too recieve newsletter......bla bla" A couble of weeks ago mail from our server bounced from AOL due to AOL customer UCE complaints. As it turns out one single UCE complaint from an AOL customer will get the ip of the sending smtp server banned for a period of 12 hours, but if the server has a PTR record the server will need to generate a lot more complaints before being blocked. Apart from the time i spent resolving this issue, not counting waiting to get thru to the postmaster group, this easy step would weed out at least a large portion of the spam. Everybody agrees not to recieve mail from domains without a valid PTR record ? :)

    6. Re:This is just wrong in so many ways... by AKnightCowboy · · Score: 3, Insightful
      In the dark world of the future you'll have to fight your way through bureaucracy and stupid sysadmins (and yes, the vast majority of sysadmins are fucking idiots, though I know that's not a popular opinion around here) for each and every company, organization or domain you want to send email to. That sounds like an infeasible, unmaintainable system to me.

      We're probably all over-reacting a bit since the first time the CEO of AT&T misses an important e-mail message because his ISP blocks the incoming mail, this will go away. I would say by 2pm on Friday at the latest. This is one of those idiotic things to do on the scale of Verisign's Sitefinder "service".

    7. Re:This is just wrong in so many ways... by JuggleGeek · · Score: 2
      We run a community website that sends out newsletters to our customers. This newsletter is sent out if the users does not uncheck the box "Yes I want too recieve newsletter......bla bla"

      So you're tricking people into signing up, and you're surprised that people complain about you sending spam. You could save yourself some trouble by having them check that box if they want the newsletter. That way, only people who realy want the newsletter get signed up. "OptInByTrickery" isn't a good plan - for an honest business, at least.

  12. This might be a dumb question. by DAldredge · · Score: 2, Insightful

    But, if you wish to become an ATT customer, how do you contact them?

    I have no wish to phone them so they can get my phone number, which they will use to call me every 5 days trying to get me to switch my ld to att.

  13. Some much for my mail server by mgarriss · · Score: 5, Insightful

    A week ago I decided that it would be interesting to setup my own mail server, hell, fun even. Interesting yes, fun no. I started with sendmail and ended up with qmail.

    I was so proud of my new server, it was so, well, new. I go to send out a test mail and alas earthlink would not accept it, hmm. Then I sent one to my yahoo account, nope. Hotmail? You guessed it. What's the deal I asked. Googled a bit, found that slashdot discussion (http://yro.slashdot.org/yro/03/04/13/2215207.shtm l?tid=120).

    I started to realize that email is no longer a tool of the little guy. I send my mail through my earthlink server which works but now I must watch my volume (no mailing lists hosted here I'm afraid) because of my 'terms-of-service'. Something about being a little guy or something like that.

    Now the last barrier is up. I wonder if ATT would put me on their list?

  14. SMTP is already "broken" by BeerMilkshake · · Score: 2, Insightful


    I have my own domain and run a MTA on my Linux box that is on DSL and gets its IP via DHCP. The IP almost never changes since the server is always on. I bet this is the same configuration as other /. readers.

    Anyway, I am starting to get bounces from certain organizations (AOL, Primus) that seem to think my messages are spam. Seems to have something to do with coming from an IP that is known DHCP. This kind of sucks; whitelists and spam filters may seem good at first, but they are screening out some legitimate traffic.

  15. RTFA? by fo0bar · · Score: 5, Informative

    FYI, this seems to be from AT&T Business Services, IE backbone and ip operations. So their customers (the people they are asking) in this case are other ISPs, datacenters, etc, and the whitelist is for sending email to AT&T itself. This has nothing to do with other AT&T services (remember, "AT&T" is essentially about a hundred different companies that happen to share the same name), so this should not affect some grandma trying to send to an attbi account. That being said, whether what they're doing is good remains to be seen.

    (Interestingly enough, I *DO* work for a datacenter that has IP and transit services through AT&T, and have not received one of these emails yet...)

  16. Good grief by Micah · · Score: 2, Informative

    I've said it before, and I'll say it again. We need to dump SMTP and switch to something like Internet Mail 2000. The sooner we do it, the better. Some people here have voiced concerns, but I'm convinced that this proposal is well thought out and will work. Any inconvenience (which would be minor, and only for a small fraction of users) would be trumped by its benefits, by a wide margin.

    Anyone know if anyone is actually coding up a sample server and client for IM2000? A google search for "internet mail 2000" comes up with some proposals that go beyond Bernstein's site, but I haven't seen any evidence of code yet. It really shouldn't be that complicated and, yeah, I'd be willing to help!

  17. The original memo by morelife · · Score: 2, Funny

    I read between the lines as:

    Greetings Customers and Partners,

    There is too spam, so we fired everyone in IT. We've got some temps, led by secretaries, who will now rebuild and maintain all AT+T messaging platforms. Please send your IP addresses as we will need to ping you next week to see if you're still a Parntner/Customer.

    Best regards,

    "

  18. Shock and disbelief.... by ComputerSlicer23 · · Score: 3, Interesting
    Uhhh, I do business with people on the AT&T network. At least I'm reasonable sure the 1000's of clients who use e-mail to contact me use it. I wonder what I need to do to get on the list.

    Complete shock and disbelief at the first e-mail (the dreadfully short message at the bottom).

    Has anyone actually called and confirmed with the 1-800 number that this truely is AT&T, and it really is what they are saying? I'm not sure I'll believe it until I see the e-mail actually start bouncing. That's clinically insane. Do they seriously believe they'll be able to pull this off? You mean ever time a small company creates a new mail server they'll have to contact AT&T with the outgoing SMTP servers? If this starts a major trend, you mean I'll have to contact lots of major ISP's to send mail to them?

    Assuming this it to stop SPAM (what else could it be?), what's to stop a spammer from just calling up and saying I'm a legit mailer set me up? What do I do when I get assigned the IP from the old spammer? What will there policy be on setting you back up? Will there be an official form? How can they tell the Spammer just isn't dupping them a second time with a fake business?

    This sounds like a terrible idea, and like their security people haven't really thought this through. About the only thing I like about it, is that it is a sign that major ISP's are starting to play hardball. I'm curious if one of their net admins was behind some of the major black lists that just got DDoS'ed off the net. I hope they accept e-mail from anybody with a legitimate MX record at least. At least for a little while. I can't believe they aren't going to do a black list instead of a white list.

    What's the over-under on how long this takes to get pulled the plug on? There's no way this will last. It'll be a world class disaster. My guess is it won't last 15 business days.

    Kirby

  19. This is not going to work by bigberk · · Score: 3, Interesting

    After a few months of operation, it will become obvious that this plan is a disaster. Spam-friendly ISPs (and there are many with legit customers too) will still get on the whitelist, so incoming spam will not cease. But in the meantime, smaller ISPs around the world will get mighty pissed because their mail is rejected.

    However, if you run your own mail server you will get quite annoyed, but all hope is not lost. Here is a brilliant solution for postfix that will let you deliver mail specifically bound for, say, attglobal.net through your ISP's hopefully whitelisted customer-use mail server instead of direct delivery. So AT&T will see your ISP's mail server connecting for this mail, while all your other mail can be delivered direct.

    I'm mighty disappointed in AT&T. This move further commercializes Internet connectivity by giving big business the green light to send any mail while blocking all the small guys. Seriously.

  20. Don't they need to keep doing business? by fatray · · Score: 2, Informative

    Most big corps have an army of salesmen, tech guys, whatever, roaming around the world handing out business cards with an email address printed on them. The idea is that potential customers or potential partners with actually email us and we'll do things with them that make money for the corporation. Cutting off that communication sounds like a very bad idea.

    This seems pretty odd. Is this just a small division somewhere that is trying this or THE AT&T.

  21. A Hoax? by davburns · · Score: 2, Insightful
    It seems to me that, if AT&T wanted a list of mailservers which send them email, they would probably start with their own maillogs. That is going to be much more complete, and they won't sound as stupid to all their contacts.

    Even if they did come up with a complete and accurate list of non-spammer mailservers, they still need a way to continiously update it. What would they want? Everyone in the world sending them email whenever a mailserver comes or goes? (oops, no... because the new server wouldn't be on the list either.)

    AT&T cannot be this stupid. I have to think that this is a hoax. The long message vouching for the credibility of the earlier, terse message supports this idea.

  22. Why not use the MX? by droleary · · Score: 2, Interesting

    AT&T has asked their customers, partners, and business clients to provide them with IP addresses of their mail servers.

    Call me dense, but why not simply accept mail only from registered mail handlers? I would also do the filtering based on the connecting server's domain MX and the From header's domain MX; neither is registered, you give a 550 error. That would stop 99% of the spam (that I get, at least) right there. Especially the virus spam that tries to turn any random Windows box into an SMTP server.

    1. Re:Why not use the MX? by morelife · · Score: 4, Insightful

      Why not use the MX?

      In large mta deployments the mx is hardly ever the sending mta.

  23. Hypocritical--ATT is a major Spam Service Provider by dananderson · · Score: 4, Interesting

    I find this very hypocritical. ATT is a major service provider for spammers, mostly through their broadband service. I know because I have my own blacklist and there are hundreds of Class C blocks with ATT. ATT is very lax with enforcing any AUP they may have.

  24. SMTP blues by ratfynk · · Score: 4, Insightful
    I know this sounds crazy but the protocols are the problem. As long as there is no way to certify return addressing spam will happen. Solicitation lists just do not work for this very reason. I personally do not reply to or even consider spoofed mail. I never use html links that come in mail even if the reply address is authentic. If the person sending me mail cannot give me their real address they can go suck wind. I just wonder, if e-mail dies what will replace it? Ask Bill he has the answer, fascist style computing. Maybe this is why we have the MS worm, virus, software security problem. What a wonderful way to sell secure computing and make so called 'trusted computing' mandatory. Kill of e-mail as we know it first with Windows style security. Na ..no one could be that underhanded. Brilliant idea though and not that far from happening. Either the guy is really that brilliant or just shit lucky. It sure would cement the future of MS computing.

    The best dual boot problem solver is; dd if=/dev/urandom of=/dev/hda1 ..then cfdisk /dev/hda1 etc..

    :-( too bad I have my wife won't switch yet. I have always wanted to use that command!

    --
    OH THE SHAME I fell off the wagon and use sigs again!
  25. Just because... by sillypixie · · Score: 4, Informative
    you whitelist some servers does not have to mean that you have to blacklist all the others. If AT&T really means to do this, they will learn the hard way when their business suffers.

    There are several initiatives underway to use DNS to authenticate SMTP transactions: this seems like a good way to avoid the nastiness described by the parent poster...

    The article really does sound like this request is an emergency response to a specific threat - The intent seems to me to be more of a temporary bandaid solution than an attempt to alter the very fabric of email as we know it (-:

    Pixie

    --
    don't mess with those geekgrrls
  26. SMTP Servers sending from their networks by Anonymous Coward · · Score: 2, Interesting

    Just so that this is absolutely clear. It is my understanding that they are asking customers on their IP networks for this information. That is: they want to know the IP addresses on their IP nets of SMTP servers to whitelist incoming and outgoing mail for. I believe this mail went out to their large (enterprise?) customers which includes many downstream ISPs.

    Could anyone tell me if this letter also went out
    to customers that manage their own IP nets but buy upstream connections from AT&T. For example, ISPs that are LIRs for their own nets.

  27. Re:Why not? by eric76 · · Score: 2, Insightful

    I've been told that some spammers-for-hire get paid by the response.

    If you complain or try to "unsubscribe", that counts as a response and increases their fee.

  28. I nearly did that myself by Greyfox · · Score: 2, Informative

    I was hunting around for some info on how to set procmail up to only allow the 4 domains that I get legitimate mail from when I ran across tmda. I decided to give it a shot instead and I haven't seen a spam since. I know that technically they're still coming in, but I went from 30-40 spams a day in my inbox to 0. Now I can ignore the problem until they start slipping through or they start consuming a significant portion of my bandwidth.

    --

    I'm trying to teach myself to set people on fire with my mind... Is it hot in here?

  29. I've got a great IP they can block by Sir+Haxalot · · Score: 3, Funny

    127.0.0.1

    --
    I have over 70 freaks, do you?
  30. RMX and SPF:Sender by RT+Alec · · Score: 4, Interesting

    The biggest problem is ATT will have to administrate this. If a (legitimate) domain switches IP addresses on their outgoing SMTP server (it happens), ATT will have to deal with it by setting up some kind of structure to accomodate such changes.

    Forcing domains to declare from what SMTP host legitimate mail will come from is actualy a good idea. It has been proposed before, in the form of SPF:Sender and RMX. Either would do the job (technical quibbles aside), and would accomodate the end goal ATT is trying to achieve.

  31. Pah. Spam is here to stay. by philovivero · · Score: 2, Interesting

    This scheme will last as long as it takes for one of the Brand New Spam Viruses to infect a billion computers across the internet that use these whitelisted servers.

    As long as our governments are only willing to enforce the laws that make them money, the problems that plague our society will continue.

    Seriously. Call up your local police office and report the 50 spams you got. Call the FBI. The FCC. The FTC. Call as many government offices as you care to until you're blue in the face. They all have some law that they should be enforcing that Spam breaks, but they're not interested.

    Fix the problem, people, not the symptom. If you elect some leaders that will actually enforce laws that make the average citizen's life better, Spam will go away, along with a litany of other problems just like it.

    That, or just keep voting for the same politicians that are in the pockets of the corporations, and these problems will persist.

  32. RMX is RIP? by Nonesuch · · Score: 2, Interesting
    Autopr0n writes:
    Hopefully RMX will get off the ground soon, so we can all do this automaticaly.

    That's what I was thinking, but it looks like RMX is dead in the water, the link to the memo from the IETF ASRG website goes 404.

    Looks like TLS (SMTP over SSL with client and server certificates) is our only hope. I was at a recent Open Group messaging conference (formerly X.org) where the main topic was spam, and there is definitely interest in this approach.

  33. Gee, sounds like SPF. by Inoshiro · · Score: 2, Interesting

    Sender Permitted From, a handy little concept whereby DNS servers for domains publish lists of what servers are vouched for, so to speak. By only accepting email from servers which implement SPF, you reduce spam a lot. With SPF, if anyone is doing spam, it's very traceable and prosecuteable. You also cut down on people trying to fake identities.

    If everyone implements SPF, it'd solve this problem in a fairer way.

    --
    --
    Internet Explorer (n): Another bug -- that is, a feature that can't be turned off -- in Windows.
  34. Get real by FutureShoks · · Score: 2, Interesting
    It really bugs me when a whole lot of SlashDotters turn around and say: "we need to dump this and switch to this" or some other stupid notion. There is no way we can suplant SMTP - it's too pervasive. We can help cut down a large proportion of spam but actually using what we already have properly:

    [1] Configure your reverse mappings for your Internet-facing machines properly. That way we can start checking on reverse lookups which would stop Joe Lusers Windows box on DSL being turned into an SMTP engine.

    I know that people can trivially configure their own DNS servers and spoof the forward and reverse mappings, but at least there needs to be an administrative contact on the SOA record and on the WHOIS information; which is something

    [2] Get rid of the un-needed use of HTML emails. There is no need for half of the formatting and dross in emails. ASCII does just fine, and provide a link to a website if you need to woo people with eye candy.

    [3] Undo some of the supposed "intelligent" behviour of email clients. They should display text first, and do everything else (play sounds, render HTML) as a user-invoked extra

    [4] Make it a "must manually do" option to allow SMTP servers to allow relaying from anything other than their internal interface and IP range. Too many products come too open out of the box

    [5] Use the TXT record or something similar for SMTP servers to list which domains they serve. That way receiving servers performing a forward/reverse lookup for verification will also be able to see if the domain in the email has been spoofed.

    --
    ___FutureShoks___
  35. Re:What if this was opposite... And voluntary... by vidarh · · Score: 2, Insightful

    So why don't you just block outbound access to port 25 on your routers? Not exactly rocket science...

  36. Balkanization? by gothicpoet · · Score: 2, Interesting
    I'll admit to being a little surprised that there aren't more people who are concerned that this could be a big step toward the much vaunted "balkanization of the Internet"...

    A lot of sort of unrelated things have been happening lately that indicate an instability in the philosophical underpinnings of the Internet. It used to be that the idea of sealing off access to areas of it would be completely anathema, as much as the idea of someone doing something like Verisign's recent Sitefinder profit-play.

    We're reaching the point where it's no longer considered completely out of the question to discuss blocking access to non-offenders. It's gone from being okay to block SMTP traffic from "non-static IPs" to being okay to block traffic from "anyone who's not on our exclusive list" within a period of months.

    Verisign has done the previously unthinkable by modifying major functions of the DNS system without so much as a "by your leave". And having gotten their hand smacked, rather than admit any wrong doing, they are politicking in the media to lay the ground work for efforts to wrest complete control of the process. What will they decide they have a right to do next? And if they get away with it, what are other (backbone providers/ISPs/you name it) going to try to see how much they in turn can get away with?

    And it doesn't look like too many people are thinking ahead to where these trends will go if not arrested. The Internet has functioned as well as it has for as long as it has because by and large the big players have all followed the rules, customs, and generally accepted way of doing things. If they all start to do whatever they please at the moment, will there still be an Internet?

    --
    Quoth he ::
    "It's all academic anyway..."
  37. Fscking hypocrites... by Eggplant62 · · Score: 3, Interesting

    AT&T three years ago were caught out when a "pink contract" they held with Ronnie Scelson's Cajun Hosting was brought to light by anti-spammers on news.admin.net-abuse.email. Now they're going to do something about the spam hitting their user's inboxes.

    Less spam would hit their user's inboxes if they were to sever all ties with their pet spammers. It's my own hog-fucking opinion that AT&T still has plenty of pink paper over there and are still helping spammers to stay in business. However, money still talks the loudest. Those spam contracts usually bring double or triple the going rate to ignore complaints.

  38. Re:Bah, obviously there is a better approach by CowboyMeal · · Score: 2, Funny

    Alright "sql rob", how about hooking them up to a third um... "DB" machine of some sort?

    --
    Your credit card information wants to be free.
  39. The dinosaur is about dead by Nerd4News · · Score: 2, Insightful

    Couldn't ATT scan their current email base for this same info? Sure it's going to take 1+ sets of human eyes to make sure an IP is legit but that's going to be needed anyhow to review the incoming requests to be added to the whitelist.

    Lets take this one step further. Six months down the road I, a future customer, business partner or supplier to ATT whom has never heard of this policy, send them some email wanting LD service for Humongous Corp, to supply widgets at half their current cost or whatever and has its mail bounce or go unanswered. ATT is the big loser. Must be nice to be a company that has no need for additional customers or suppliers.

    More info on the deep thinkers at ATT and other big businesses can be found in the book "The Innovator's Solution: Creating and Sustaining Successful Growth," by Clayton Christensen and
    Michael Raynor. A review can be found at the Washington Post here (some non-personal info may be required before reading) (Remove obligtory Slashdot Extra Space(TM)):

    http://www.washingtonpost.com/wp-dyn/articles/A3 21 78-2003Oct15.html

    A small excerpt:

    (The book) offers a funny look back at how AT&T threw away $50 billion in just over a decade on doomed identity changes.

    After exiting the local phone market in 1984, AT&T first tried to become a computer company, buying NCR for $7.4 billion only to sell it five years later at roughly half price. Next it entered the cell-phone market by acquiring McCaw Cellular for $11.6 billion and sinking $15 billion more into improvements. But when AT&T spun off its wireless business in 2000, the new wireless entity was valued at a mere two-thirds of its investment. Then came the disastrous cable bet: A few years after forking over $112 billion to buy TCI and Media One, AT&T unloaded those assets to Comcast for $72 billion.

    Yup, the dinosaur is about dead.

  40. Yeah.. that'll work... by iceT · · Score: 2, Insightful

    The adminsitrative overhead along of customers/partners/suppliers changing ISPs, moving mail servers, and etc.. will pretty much insure that AT&T mail will NOT be reliable.

    --
    -- You can't idiot-proof anything, because they're always coming out with better idiots.
  41. Back to UUCP by Avardan · · Score: 2, Funny

    Heh, glad I still remember how to configure uucp. I'll just teach my mom and close friends how to use it and we'll have spam-free email courtesy of Ma Bell! /flex

    --
    Ma gavte la nata
  42. ATT says: by Chatmag · · Score: 2, Informative

    According to the recording at the 800 number supplied, this was a draft email that was sent out prematurely.

    --
    Pete Carr Owner Chatmag.com
  43. I think that this is only for *outbound* traffic by A.Gideon · · Score: 2, Insightful

    In reading the original message (included at the bottom of the later message), I think that this has nothing to do with inbound spam. Instead, I believe that AT&T is about to block its clients from accessing port 25 on servers other than those in a defined list.

    This doesn't address the problem of AT&T users receiving spam (except indirectly). Instead, it is addressing the problem of AT&T users sending spam. More likely, this is addressing the problem of poorly configured and virus-infected machines belonging to AT&T clients being used as relays of spam.

    This is likely in response to the "stealth spamming" that's becoming more popular: hijacking machines via virus for use as SMTP relay, DNS server, and web server. [For those interested, there's been a fair bit of NANOG discussion of this recently under the subject of "Wired mag article on spammers playing traceroute games with trojanedboxes".]

  44. The true cost of spam by KMSelf · · Score: 2, Interesting

    Ain't that the truth.

    There are a few "true costs of spam" I'm seeing. One is as you point out, Balkanization (and I'm still stuck by the AOL issue, though at least I can mail by a secondary route). One is people cut off from other groups by arbitrary blacklisting policies. And yes, many of us (/me raises hand) cheered the same action when used against foreign ISPs with large spam volumes, though I still maintain that there's an important distinction between strongly prodding ISPs to clean up their act, and arbitrarially shutting out large portions of the 'Net.

    Another is that the typical user is rapidly getting chased off the 'Net. Exposing your address anywhere is an instant invitation to not only spam, but viral spew, which in my experience is many times worse. Even on bad days, spam is ~150 messages. I've had 2000+ viruses at peak of Swen and SoBig, friends report far more. POP mail over dialup is simply impossible in this situation. Most of your inbound mail bounces because your inbox is full, and you spend all day downloading crap. SMTP-time, user-controlled, accountable, accurate, and effective spam and virus filtering is no longer optional. I've been trying to drill this point in to my brain-dead ISP. Usenet discussions in their forums have been obsessed with Swen.

    This also means that the likelihood for people to engage in open discussions, under their real identities, is being harmed. On the debian-user and other mailing lists we've seen endless discussions over the past several weeks by people who participate and then get flooded by spam. The lesson: don't participate.

    And anyone with well-advertised, long-established email addresses.... Peter G. Neuman of the comp.risks archive runs SpamAssassin over list mail and still has 90% spam in the list mail, after filtering.

    I still have hopes that we can dig out of the situation. As others note: when high-up execs start losing messages, I suspect AT&T's policy will slacken. AOL, as I've said, hasn't budged, however. Filtering is still largely effective, it just needs to be pushed further out to the SMTP transaction level. And I suspect that AT&T has a good idea, poorly implemented: MTAs themselves can keep track of spam and ham (non-spam) mail, and determine what mailservers they do and don't want to deal with. Current work with exim4+spamassassin integration is a long way toward this.

    And yes, I'm the submitter of the AOL Bans Mail From DSL-Hosted Servers story.

    --

    What part of "gestalt" don't you understand?

  45. AT&T is pathetic by gwhalin · · Score: 2, Funny

    Yeah, this sounds like a great idea. I am beginning to believe that AT&T's net ops dept is filled with idiots. My office is subletting space off of another company and using their AT&T business DSL. Roughly 2-3 months ago, all ICMP out of our network stopped. So, I get on the phone with AT&T. After a lot of getting bounced around to higher and higher support people, I finally get a hold of someone who tells me that AT&T is now blocking all ICMP across their network "for security purposes". Brilliant. It is not as if ICMP is a useful protocol or anything. So much for any remote monitoring of our servers with a simple ping. So much for using traceroute or ping to debug simple network problems. Now they are intending to break SMTP. Seems that by 2006 AT&T will have blocked most all Internet protocols because they are "insecure". Can't wait until the brains at AT&T decide to block TCP/IP!

    --
    Greg Whalin
    greg@whalin.com
  46. ATT has admitted they screwed up. by JuggleGeek · · Score: 2, Informative
    Quote from the article, link shown below for the whole thing.
    Human Error Leads to AT&T's Anti-Spam Gaffe

    Telco giant AT&T (Quote, Chart) on Wednesday rushed to withdraw two notices sent to business partners and customers asking for the IP addresses of all outbound SMTP (define) servers because of a "human error" gaffe.

    With a significant increase in incoming spam over the past few days, AT&T sent out the notices demanding the IP addresses, presumably to create a white list of gateways from which e-mail will be accepted. But a company spokesman now says customers should ignore the requests.

    "Those e-mails went out in error. They never should have been sent. We have apologized and we're requesting that customers disregard them," AT&T spokesman Dave Johnson told internetnews.com.

    "It was an honest human error. Sometimes, folks makes mistakes," Johnson said.

    Details here.

  47. Didn't Affect ISPs, just mail to ATT Employees by billstewart · · Score: 2, Insightful
    While they decided not to implement this, and the message was only a draft (badly written, at that), it didn't affect inbound or outbound AT&T ISP mail. It only affected mail to AT&T employees and other addresses on AT&T's internal mail servers. If you're a business or consumer customer of AT&T internet service, it wouldn't have affected whether you could send or receive mail to other companies.

    What it did was affect whether or not mail you sent to joe.random.employee@att.com got heavy spam filtering (on the mail servers that were getting pounded to death and might lose mail) or whether you got sent to one of the servers that did less spam filtering and wasn't getting pounded.

    So even if a few spammers got themselves whitelisted, that wouldn't be a big problem because the filtering can handle them (plus they'd be coming from known IP addresses which could be blocked or de-whitelisted). But for some customers who are ISPs or email providers, it's a lot tougher to do the job right - they'd really want to

    • permit email from sysadmin@bigisp.example.net to wholesale-fiber-sales@att.com
    • deny forged email pretending to be from got.viagra@bigisp.example.net that really came from some hijacked Korean relay
    • do some filtering on email from joe-random-user@bigisp.example.net to random-employee@att.com
    and it's hard to do that really well.
    --

    Bill Stewart
    New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks