Spanish Internet Provider's SMTP traffic Blocked
Andrew D Kirch writes "After being barraged by spam and 419 scams from Rima-TDE and telefonica.es [translated], the AHBL has announced that all of Spain's national ISP's e-mail will be blocked by their blacklisting service. One has to ask though, is blocking an entire country like this the future of spamfighting, or has something gone horribly wrong?"
A few other countries that can use this are found here.
Dude, where's my packet?
Yeah, that happens pretty regularly where I work, too. We provide inbound and outbound mail service for corporate clients, but do not allow spamming. Nevertheless, it seems like all it takes is one dimbulb somewhere to decide (usually erroneously) that something is spam, and one of our hosts will wind up on the spamcop list. They've really gone around the bend.
There is one blacklist I trust day in and day out, though: ORDB. That's because ORDB will only list confirmed open relays. This is a conservative approach but it means that if a host is listed, there is no question of whether or not it belongs there. Also, there is an automated retest-and-removal system. I can't use ones like SPEWS because even though I mostly sympathize (although I think they are *way* too quick on the trigger), in my business that would block far too much legit mail and we just can't do that.
We have real life IDs that are difficult to forge and even if you can forge them, you'd get hit by hefty penalties for doing it.
This is a silly argument. Criminals will forge i.d.'s regardless of the law *because - duh! - they're criminals. It's what they do*.
And if you think it's difficult to forge a driver's license or a passport, from *any* country, you've been swallowing too much government bullshit. For $500-$1000 you can get a completely new, legal identity that'll check out if the government investigates it, because it was purchased directly from the folks who control the system that issues i.d.'s in the first place. I could, in 48 hours, get a perfectly valid (and new) SSN, drivers license, and birth record entry which will hold up under government scrutiny *because the folks who control the system will sell them to me, and they aren't forged*. I can get decent forgeries for just a few hundred bucks, if I don't need to pass a serious security check.
Internet i.d.'s will be no different, and no harder to forge. Or to buy, from the right people.
Max
My god carries a hammer. Your god died nailed to a tree. Any questions?
Telefonica.es is the ISP, as RIMA-TDE (another hat it wears) it has been responsible for the continuing incredible 419 spams out of Spain, though they're a BIG ISP, and they are, this does not excuse them from policing their network and ensuring that such things are kept to a minimum, and terminations occur when appropriate. The issue here was they refused to identify corrective actions, refused to terminate abusive customers, and refused to return contact after they initiated contact.
The AHBL is the redesign of the older blackholes.2mbit.com DNSbl from years ago. We've just changed its main focus on abuse in general - which includes e-mail, DoS attacks, etc.
We are apparently in wide enough use that we deal with TDE customers on a daily basis that are complaining that they are blocked.
Its not our primary focus to be the biggest.
Our primary focus is to protect our systems, and the systems we manage, from spam and abuse. We make our data available to anyone and everyone, because we know that our data will improve on the feedback of our users.
So far, we have had zero complaints from our users as to our blocking methods, even if they are extreme at times.
Brielle
The AHBL is very open to working with providers to solve their problems. On a daily basis, I can be working with several ISPs to figure out how to better tune our listings, or help them track down a spamming customer.
We only resort to this wide range listings when we're run out of options. In the case of TDE, we just do not have any more patience.
We gave them time. We sent them abuse reports. We even asked them to provide us with accurate information on their netblocks so we can tune our listings down to only their dynamic customers.
However, they ignored our requests.
The AHBL has very strict policies on what we will and will not do.
We are taking a strong stance on 419 and phishers right now - just take a look at our ongoing fight with megamailservers.com - we caught them in a lie with their phishing customers, and we are holding them responsible.
If we are having an effect or not, it doesn't really matter to me. All I do know is that we are taking a stance and asking others to support us.
The hope being that with enough people working with us, we will be able to force providers to do something about their problems.
Feel free to flame me all you want.
Brielle
A 419 e-mail refers to a particular kind of Nigerian fraud e-mail, not the number of e-mails sent.
I think it is interesting that you call them arrogant fucksticks, when you have no clue at all how this stuff works. Hint: a block only becomes this big when the ISP has repeatedly ignored abuse reports over a long period of time. The only way to get their attention is to block them.
And, in fact, now that they have been blocked, they suddenly have shown an interest in dealing with their spam, and have contacted AHBL.
Note also that AHBL asked for details on address ranges, so they could tune the fine-tune the blocks to just catch the dynamic addresses (the ISP claims that most of the problems are from users at Internet cafes), and was ignored. Note also that the ISP could solve this problem with a simple block on outgoing port 25 from their Internet cafe customers.
China's another popular place to block, not because of badly administered machines, but because of policies of tolerance of spammers and scammers and lack of useful response to abuse complaints. I haven't gotten much spam in Chinese in a while, but I still get lots with either the email origin or the web site located in China. And China's Internet access is controlled by the government telecom monopoly, who obviously don't mind spammers if they pay their bills.
So blocking a whole country isn't a new thing. But this isn't a whole country, it's just one of the major providers there. Spain doesn't censor their users' internet service - if you're blocking their mail, they can get themselves a Hotmail or Yahoo account to reach you.
Bill Stewart
New Fast-Compression-only CPR http://preview.tinyurl.com/dy575ks
As Spaniard...
It's true that the announcement does'nt say that they'll block the whole country, but telefonica rents his lines to other companies, so they will be blocking a lot of people, a lot more than the 50%.
Its incorrect that telefonica is the gov's isp, it was few years ago, but the previus government privatized it so the new government (we have elections a month ago) doesn't have any control over the company.
The process of privatizacion was very obscure, a lot of directives getting a large amount of money, the new president that was designed was a friend from school of the old government president, etc etc.
We've got only a pair of alternatives and isn't as easy as it seems to change provider, for example you can't change company in the first year whithout paying a large amount of money.
We're paying what the previous government do, they do their worst in exterior relationships, they had a very bad plan about new technologies, education, etc. For example Spain got the worst number of internet connections, internet services and the most expensive connections of Europe.
Telefonica got the worst client hot line you can imagine and they don't pay any attention to what the users says, but you've got no alternatives in the most of the cases.
So as a Spaniard and as a Telefonica user i thought that it isn't fair to ban the whole company ips but it's fair to make telefonica pay a large amount of money or punish it other way.
PD: sorry for my english
Hi all,
:)
My family actually lives in Spain, and uses Telefonica as their ISP. During my last visit, I discovered a wonderful surprise: Slashdot already blacklists the entire Telefonica data block. Whenever you select a link to read a story's comments, etc., it comes up with some message about not allowing that operation due to abuse from the netblock. It was pretty cool, really.
In any event, Telefonica is a big, monolithic telephone operator. They used to be the official, national telephone monopoly company before the market was opened up to other operators. Telefonica is still huge, nonetheless. They have voice, data, and cell phones in Spain; I think they also own a good chuck of media there. They run a pretty sizeable percentage of the telco business in South America (possibly the largest telco in the region). They bought our Terra back in the 90's, which bought out the Lycos networks for those that actually care.
Telefonica could probably have worse service, but they would need to train their personnel for it. As with most old monopolies there's this pervasive company culture that they are the center of the universe and if you don't like it you can go jump off a cliff or something. So I'd suggest not holding your breath for this situtation to be resolved. Although, as with every bureaucracy, every once in a while messages accidentally make it to the desk of the one guy who has a clue...
-Jack Ash