Slashdot Mirror


Microsoft Wins $3.95 Million from Spammer

LehiNephi writes "A Washington, D.C. judge fined Daniel Khoshnood, a major spammer, for pretending to be Microsoft in order to attract customers. Specifically, he registered windowsupdate.com (not to be confused with windowsupdate.microsoft.com), then sent out mass email encouraging users to download a toolbar from that website. Although the suit was not specifically about spamming, the mass emails (and subsequent complaints) were what caught Microsoft's attention. So far, Microsoft's campaign against spam has netted them $54 million from six judgments, one dismissal, four settlements, and two bankruptcies. The article doesn't mention whether the toolbar actually lived up to its claims of automatically applying security patches."

13 of 169 comments (clear)

  1. I have to say... by xigxag · · Score: 4, Insightful

    It seems rather dumb of MS not to have registered windowsupdate.com in the first place.

    --
    There are two kinds of people: 1) those who start arrays with one and 1) those who start them with zero.
    1. Re:I have to say... by betelgeuse-4 · · Score: 5, Insightful

      Most companies probably don't want to go down the route of registering all the keywords related to their business to stop third parties abusing the fact that the words are well known and recognised. If they did then scammers would use mispellings and 1337 variations, it could cost quite a bit to register all of them. For MS it's possibly easier to take just to take legal action when abuses do occur.

    2. Re:I have to say... by PatHMV · · Score: 3, Insightful

      It would "cost quite a bit"? Do you understand how much money Microsoft has? Do you understand how expensive their lawyers are? They could register 10,000 domain names with a fraction of the interest they make on their money in an hour. I really don't think the expense is why they didn't do it.

    3. Re:I have to say... by NanoGator · · Score: 3, Insightful

      "For MS it's possibly easier to take just to take legal action when abuses do occur."

      At $8 bucks a domain, MS would have been ahead to register those domains compared to the cost of one court case.

      On the other hand, though, they did send a message to other domain squatters out there. Like or hate MS, that was a good move.

      --
      "Derp de derp."
  2. A victory is always a victory... by Reverant · · Score: 1, Insightful

    ...even if its for Microsoft. Personally, I would prefer that the money would go to, say, Spamhaus, for giving us the XBL and the SBL.

  3. Re:"Microsoft Wins $3.95 Million" by vadim_t · · Score: 2, Insightful

    I'd say neither.

    Remember, the enemy of your enemy is not always your friend.

  4. This has very little to do with spam. by ezraekman · · Score: 5, Insightful

    While I think it's great that yet another "identity thief" (sort of) has been busted, this does little to stem the flow of spam. What we truly need are more cases that are strictly based on the sending of unsolicited commercial e-mail. We've got some great and not so great legislation out there to protect us... why aren't we using it? Because it costs too much?

    And yes, I know that there have been a few landmark cases recently, but a few big falls aren't going to convince spammers as a whole to stop spamming. An concerted effort to shut them down via thousands of small lawsuits from you and I would be much more likely to have an effect, in my humble opinion.

    1. Re:This has very little to do with spam. by pilkul · · Score: 2, Insightful
      Internet Explorer. IIS. Exchange Server. The Swiss cheeses of the Internet.

      Sendmail. WU-FTPD. BIND.

      I mean, not that I'm a fan of Microsoft, but aren't you being a little selective in your choices of hole-riddled software?

  5. Re:The secret formula! by the_mad_poster · · Score: 4, Insightful

    What the hell are you talking about? If you'd bothered to open up the article and, you know... READ it, you'd see that 1) they "profited" because this idiot registered a domain name in violation of their trademark and 2) there was no hi-jacking - the moron "victims" had to download the toolbar entirely of their own cognition.

    I don't know what this has to do with any mail client other than the fact that the guy happened to be sending e-mails for his little scam...

    --
    Alito: A vote for Alito is a punch in the eye to put that bitch back in her place!
  6. Re:Well, now we know why they're interested by Anonymous Coward · · Score: 2, Insightful

    Give me a break. $54 million is pocket change to Microsoft, and there's nothing "quick" about our legal system.

    Internally, spam hurts Microsoft as much as it hurts any other company that depends on email for their day-to-day operations. Externally, it makes Hotmail and MSN email accounts much more expensive to provide.

    No doubt Microsoft is not acting solely for the public benefit -- I'm sure they're seeking some good PR from their campaign against spammers. But to ascribe their actions entirely to greed and to say spam doesn't hurt Microsoft is asinine.

  7. when will we take security seriously? by fermion · · Score: 3, Insightful
    This stuff is partially the fault of the big companies. In this case MS has been harking on users for years that they must update computer the minute patches come out. They harangued customers that did not properly update machines, blaming such customers for all problems. However, they have only recently given consumers the tools needed to easily update their machines, and then only if the customer has broadband. This left a wide hole for someone else to exploit the fear. Fear that was created because MS chose to blame customers. This was especially true when update were erratic and most more common that today. The design on Windows led to the exploits. All MS had to do is take a bit more responsibility for their design decisions.

    I have noticed this with bank websites as well. When online banking first grew big, I got an email survey that asked for personal information and led me to a third party site. I asked the bank if the survey was legit and they said it was. More recently the bank started letting users log in from an unsecured home page. Passwords seem to be protected, but we now have introduced a system in which users are accustomed to submitted sensitive information on unsecured pages. This habit can only benefit the crooks. I mean the latest exploit, involving ads on bank pages, should have been identified early as a security risk. I guess the risk to customer was less than the greed of the banks.

    --
    "She's a scientist and a lesbian. She's not going to let it slide." Orphan Black
  8. Vouchers by Beige · · Score: 2, Insightful

    Maybe they should pay the fines in vouchers for spam. That's how microsoft likes things isn't it?

    --
    pandnotpian.org. The untruth will set you free!
  9. No, this and things like it will help by Sycraft-fu · · Score: 2, Insightful

    Remember: Spammers are completely financially motivated. The reason they do what they do is because they can make easy money at it. Well, the biggest way to reduce the amount of SPAM is to make it less profitable. We cannot, unfortunately, stop idiots from bying from spammers. What we can do, however, is raise the cost of spamming through fines and lawsuits.

    If spammers are getting sued and arrested left and right, and loosing all their ill gotten gains from it, makes it much less likely they'll go back in to spamming in the future, and less likely that others will go in to it.

    This is different than drugs, because in the case of drugs, the dealers are providing something that people WANT to get. They want it to the point of paying an obscene amount for it, thus demand stays high. People DON'T want SPAM. Generally even those that buy form it don't want it, they are just gullible. So people will not seek out SPAM or pay obscene amounts for it.

    Thus if SPAM is a risky bussiness where one faces lawsuits, fines, and jail time, it is less likely that people will do it. It won't eliminate it, of course, you never eliminate something by making it illegal, but it can and will reduce it. Combine that with better SPAM filtering technology, which means less e-mail will reach potential buyers and again reduce profitability, a real dent CAN be made.

    The "we can't do anything so we might as well give up" attitude is stupid. Applied to all crime, you have anarchy. You can't PREVENT things by making htem a crime, that is impossible. You can REDUCE them, however, and that is worth doing. Just because murder happens I don't think you'll hear anyone saying we should make killing people legal since the law hasn't stopped it from happening.