Slashdot Mirror


Is the CAN-SPAM Act Working?

DynaSoar writes "Lance Ulanoff of PCMag.com offer his opinion on the success, or lack thereof, of the CAN-SPAM Act. It doesn't appear to be working, though spammers have noticed, in that they try to make their spam look "legit". What might make a real difference, according to US Senator Conrad Burns, co-author of the bill, is international standards and enforcement."

21 of 280 comments (clear)

  1. War on Poverty, War on Drugs by AtariAmarok · · Score: 5, Interesting

    It seems to be working about as well as the War on Poverty and the War on Drugs.

    The only thing I have noticed is that spam to my junk Hotmail accounts has dropped to almost nothing. I think this is due to a change in MSN's filtering, and has nothing to do with the legislation.

    --
    Don't blame Durga. I voted for Centauri.
    1. Re:War on Poverty, War on Drugs by ooby · · Score: 4, Interesting

      You forgot the War on Terrorism and the War on Steriods.

      I've noticed a decline in spam in my Hotmail account as well. Hotmail still gives me false positives. In contrast using Yahoo! mail, I've recieved legitimate emails from real people that I know but haven't added to any address list. These emails have always been marked as legit. I recently have gone so far as to not check my bulk mail for false positives. I've also received one false negative. Right now, I think Yahoo! has an edge over Hotmail.

  2. Usable snailmail addresses? by Igloodude · · Score: 5, Interesting

    My Bayesian filters are starting to pick up on the snailmail addresses the compliant spams contain...
    So maybe there was one minor positive point to the law after all. Unless they're simply fraudulent, it's a lot tougher to change a snailmail address than an email or URL address.

    --
    We now return you to your regularly scheduled thread.
  3. More wasted bandwidth by fembots · · Score: 5, Interesting

    Now I start receiving spams that come with a nice big attached image which tells me that particular email is complied with the Can-Spam ACT.

  4. What will work... by Audent · · Score: 4, Interesting

    is producing legislation that takes the power away from the spammer and puts it in the hands of either the end user or their ISP so we can filter the crap out.
    If it's legit email then they can discuss it. If it's not we should be able to block it. I'm sick of paying for this rubbish.

    --
    I am a leaf on the wind
  5. Filtering out spam and black listing email servers by roman_mir · · Score: 3, Interesting

    There was an article about a new spam filter just a couple of hours ago, they were supposed to remove 50% of spam emails. 50% of spam stopped sounds good, but what if 50% is 350 Billion email messages? Spammers only have to double their messages to go around this 'filter' to produce the same volume tomorrow as they produce today.

    What I would like to see is a spam signature sharing, Spam Detection Servers SDS would collect hash per spam email sent within a time period. An email will have to be stopped on any email server and verified against an SDS to see if it is not spam before sending it further. How would these SDSs collect the signatures? Feedback from email users, black lists, good filters etc. All email servers will have to register with SDSs, or they become black listed.
    But you probably can tell me why this is not going to work, can you?

  6. Faster than ever by OECD · · Score: 4, Interesting

    I recently signed up for an AOL 'free trial.' It took about five minutes before spam started showing up in the mailbox. I was amazed.

    (BTW, if you're on a Mac, don't bother--the Mac software for AOL doesn't appear to have been upgraded for a couple years--commercials be damned.)

    --
    One man's -1 Flamebait is another man's +5 Funny.
  7. Huh? by singularity · · Score: 4, Interesting

    What might make a real difference, according to US Senator Conrad Burns, co-author of the bill, is international standards and enforcement.

    I thought one of the big problems with CAN-SPAM act was that it said that no one could set "standards" for what UCE was required to contain.

    No [ADV] or anything at the beginning of the subject line. Spammers know that requiring them to do that would make it significantly easier to trash Spam at the ISP level. They must have lobbied hard to make sure that the bill says that the FCC is *not* able to set "standards" for that identifying marks Spam must have.

    If you are going to write a law that tries to fight Spam (questionable intentions in the first place), at least give it some power to set "Standards".

    --
    - (c) 2018 Hank Zimmerman
  8. Re:well duh! by leerpm · · Score: 5, Interesting

    In actuality, a lot of spammers are located within the US. They only use remote facilities to mask their identities and cover up what they are doing. No, 'international enforcement' would not likely even have much of an effect either.

  9. How about enforcing the fraud laws? by swb · · Score: 4, Interesting

    Follow the money trail. Get the people committing outright theft (ie, no product), selling fraudulent products ("your dick a yard long in 24 hours"), or otherwise illegal products ("valium overnight"). Make a few RICO cases where you can ensare anyone even remotely involved in the business. Send them all to jail for 20 years with millions in fines.

    Why is this so hard? This will put an immediate dent in spam. I'm not naive enough to think it will end it forever, but if enough people get nailed hard enough (including ISPs, banks, and others through a RICO prosecution) it will be damn difficult and daunting to even BE a spammer, let alone make any money at it.

    Instead we'll waste countless hours talking about making spam illegal, when it's the smallest of all the crimes involved in a typical spam message.

  10. How laws can work by RT+Alec · · Score: 4, Interesting

    Follow the cash. How does spam work? It works by getting someone to give the spammer money. Go after the money. Unfortunately, the CAN-SPAM act makes this more difficult, since individuals cannot go after the spammers, only ISPs.

    Here's what we need to have in law:

    • Hold those relaying spam responsible. You have an open relay? You are liable for any spam coming from your server. No more "pink" contracts.
    • ISPs should be held accountable for zombies on their network. Block egress port 25, or else he held responsible for spam spewing from your system. Wake up and administer your system, or pay someone that knows how.
    • If you sell a product or service via spam, even if you hire a third party do do the dirty work you will be held responsible.
    • Allow individuals to file civil suits. Unload the army of american lawyers on spammers, and create a bounty system as suggested by Larry Lessig.
  11. My spam is canned !! Statistics Follow by deathcow · · Score: 3, Interesting


    My spam is canned and put on pallettes now and delivered by semi truck.

    Before CAN SPAM.. my SpamKiller trap had about 3100 spam per month.

    After CAN SPAM... my SpamKiller trap has about 4200 spam per month. Steadily growing, as always.

  12. Most spam is international ... by calmdude · · Score: 4, Interesting

    I don't know anyone from Argentina, Brazil, China, Hong Kong, Malaysia, etc., so I blackhole their addresses (along with ISP's dynamic IPs). This can sometimes cause problems, but as far as a home solution, it's great.

    I block the addresses at my firewall so I automatically eliminate most of my spam as well as most port scans and scripted exploits (since a lot of them are foreign/rooted systems).

    I wouldn't do this at a large company, but you can probably get away with it at a small domestic U.S. business that doesn't need international communication through the Internet.

  13. No. by pla · · Score: 3, Interesting

    Need I say more?



    Grr... Okay, the lameness filter has forced me to say more. Fine.

    I receive roughly one thousand spam messages per day.

    Since the passage of the CAN SPAM act, that has not decreased in the slightest. I have noticed only a single difference, which actually has benefitted me, but won't work for everyone - The proportion of messages coming from "suspicious" foreign domains, like .il, .cz. .ru, .tw, etc, has increased quite a bit. So, since I block all of them, the amount of spam I actually see has dropped. Otherwise, no change in the total volume.

  14. I don't get spam.. by Visaris · · Score: 4, Interesting

    Most people I know say they get tons of spam... I really just don't see how. Are you posting it to the web somewhere? Are you giving it away to pr0n sites? Do you still insist on useing that aol, earthlink, hotmail, etc address for no good reason? I never get any spam. I don't work too hard for it either. I create a new email account when I want to order something online, and then delete it when my order ships. I have an account for ebay, and paypal and the like. To be honest, that one gets 1-4 spams a week. And then I have a personal account that NEVER gets any spam. I don't have a filter, I don't do anything special really. Can someone tell me how they manage to get so much?

    --

    I am a viral sig. Please help me spread.
    1. Re:I don't get spam.. by Anonymous Coward · · Score: 3, Interesting

      i have one account. i created it about five years ago and have never used it. it was originally going to be a work related account.

      one (1) local spammer ran a bot script against the domain name of my isp account and i reported this spam to his isp and to his boss (it was a real estate spam).

      his isp (roadrunner) refused to punish him. he kept his account and had a valid list of addresses to sell the big spammers of the world.

      within four months of that first spam, the junk in that account grew.

      it's now at 20+ spams per day. almost all are hosted on chinese or korean servers and almost all use such bad grammar and spelling that only a moron would do business with them.

  15. weakened bill by MrChuck · · Score: 4, Interesting
    California had a decent (first pass) bill with some guts to it. It was to go into effect Jan 1.

    This bill, as federal, superceded it. Lamely.

    Which is pathetic and sad. /me wants to see a spammer get REAL jail time for
    stealing computer resources on high-jacked machine
    pushing scams that are ALREADY illegal

    Real jail time in a real jail with real property seizure. Loudly.

  16. Use the law as our weapon of choice by fudgefactor7 · · Score: 4, Interesting

    What we need are a bunch of lawyers who are techy/geeks (like us). They form an LLC partnership. All of us submit to them our spam, they prosecute under the law for us. We give them a cut of the money once it rolls in. A legal lawfirm with lots of good lawyers, adept at what they do, can make the spammers pay. If they don't pay get an injunction on the spammer's assets--which we sell at auction--splitting the proceeds with the lawyers. Since spam isn't going to get better, this would be a perpetual motion machine...and just might make a couple of bucks at the same time.

    Hell, it's never been tried, so it has a chance, although I still predict failure.

  17. Getting rid of spam by panda · · Score: 5, Interesting

    It's very simple, really. Make the sender pay for every message they send. How?

    Simply reverse the email architecture on the 'net. Turn the current method of sending and receiving mail around. Instead of messages being immediately sent to the recipient's server, send the recipient a very tiny message saying that a message with this subject is waiting on the sender's computer for the recipient to pick up.

    It would require a change in all the email software currently in use, and the only real hurdle that it provides is that people who are no longer on the Internet all the time can't send mail, but I'm sure someone would be willing to provide that service for a fee.

    This would also make it much more difficult to forge headers on a mail, since you would need a valid IP address and/or domain name in order for anyone to get the actual mail that you wanted to send them.

    Now, if you spam millions of people peddling whatever it is you're peddling, you'll be using very little bandwidth, a hundred or so bytes compared with several K, until those people come to pick up your message.

    Furthermore, you won't be able to hide the originator of the mail nor would you have the problem of open relays spewing a constant stream of junk.

    Couple this with PKI and you have a very flexible and very fair system.

    The problem that I have with spam is that the current email architecture places 99% of the costs of email on the recipient. If you swing that around and make the spammers have their own, high end servers for handling the millions of mails that they want to send, then spamming will vanish in a hurry.

    --
    Just be sure to wear the gold uniform when you beam down -- you know what happens when you wear the red one.
  18. Re:Better than real junk mail by Aidtopia · · Score: 3, Interesting

    Regular junk mail is a problem to. I discovered this when I moved to a new house. The previous owners were catalog shoppers. I was receiving 110 catalogs a week to the former occupants. I sometimes had to put some of them in my neighbors' recycling bins since mine were always full. Often important mail (e.g., bills) would be jammed in between the pages of the catalogs.

    In the past four years, I've sent 450 letters and made more than 100 phone calls to catalog companies to make them stop. I've made a big dent, but I still get a dozen or so catalogs addressed to the previous owners each week.

    Opt-out is not an option.

  19. It's only forcing changes on the surface... by cmowire · · Score: 4, Interesting

    They continue to spam you after you "remove" yourself from the list. I've been doing controlled experiments on these sort of things.

    Somebody spidered an autogenerated e-mail address *once* from my webpage (the address encodes the time and IP address of the requester) in violation of the robots.txt file.

    This has proven most instructive. I've written up some of my experiences on my weblog. That single address has since been sold, resold, and resold again to a variety of folks. At one point, it was sent an e-mail trojan. It's received all kinds of different spam. Interestingly enough, it has not received any Nigerian advance-fee fraud scams.

    Lately, there was a removal form with a JavaScript script included that would prevent you from typing in an address to be removed.

    One really funny spam is a dating site that said that one of my friends has set me up on a blind date. To an address only known by spammers.