Should You Trust MAPS?
"I spent all weekend long trying to get a hold of the people at MAPS, as they don't bother telling you when they are open. When I finally got a hold of someone on Monday morning (not an easy task, mind you!), they told me that they are not open on the weekend, so it would have been *impossible* to resolve this issue quickly. And because I was only a customer of the company who owns these IPs, they would not unblock my subset of IPs. Despite the problem originating from a handful of IP addresses, MAPS saw it appropriate to block over 180,000 IP addresses just before the weekend! I had already made several phone calls and emails to my co-location facility, and they told me they were doing their best to get a hold of someone there. Several emails had been sent, and just as I first experienced, they could not reach anyone at MAPS by phone. When I finally talked to someone at MAPS, he told me that he would not be proactive in the matter by actually phoning my co-locator to work this out.
These people at MAPS thinks themselves quite high and holy, and in some ways they are: many ISPs and the like will bounce emails just because MAPS tells them to. (I've since removed MAPS from my list of RBL servers to check.) As a small-business owner, MAPS can be very hurtful to a business and very uncooperative in helping resolve the issue. I gave them a couple subnets of mine to unblock, but they would not, even though my IPs were not involved in the original complaint.
This experience has certainly made me think twice about who I trust to decide the fate of my incoming email."
They are a big pain in the ass for us providers to deal with. But they are also a necessary evil too sometimes. Personally I like the Spamhaus lists much better. And Spamhaus isn't a bunch of assholes so that gets them the cookie in my book.
Some are well maintained, and even automatically maintained. spamhaus and spamcop come to mind. One of the less desirable ones that comes to mind is SORBS, where if they list you in one category you've got to donate $50 to charity, per message, to be delisted. You're an ISP providing smtp to your customers, and you're listed again? Tough.
Then your co-lo provider is clueless and you should find another. If they offer 99.9% reliability, you should ask them for a refund for the month.
My ISP follows the rules of the internet just fine. MAPS seems to think they can invent an enforce new rules, even though they are just a private company. If it was Microsoft doing this service the same way, I'm sure you would be singing a different tune. I don't think anyone benefits from private companies inventing rules that everyone is supposed to follow, and punishing hundreds of thousands of innocent customers because one ISP doesn't respond to an email in what they have dictated is a reasonable amount of time.
I in fact did spend my entire weekend talking with the ISP and trying to figure out how I could help the problem, even though I had nothing to do with the cause. But when MAPS activates a blacklist Friday night, after business hours, and then is not open until Monday morning, I hardly think that's fair play. They could have waited until Monday morning when they'd be able to respond to resolution requests, but they didn't. Instead they screwed us all over.
I had a meeting with a bunch of important people at my ISP on Monday afternoon, and I was quite satisfied that they were doing everything they could to resolve the problem with MAPS. It was pretty clear that MAPS was being extremely slow or unresponsive, and it took them half a day to come back with a list of "demands" before they would remove the blacklist. My ISP responded quickly and sufficiently, and it still took MAPS several more hours to remove the blacklist.
something like MAPS can't ever work without the occasional listing of a block that doesn't belong there, and the shittier the management of the list the shittier the service you get from it. being unavailable at some hours, ANY HOURS, and pretending to keep a list(that thousands of emails depend on) current is a joke.
on way to react to this is to not take any action at all - a spam prevention system with high number of false positives is an useless one(you may need to explain it to your customers though and direct them to complain to the appropriate person - the one who decided to use maps on some server). if you can't send email to somebody.. use gmail/hotmail or whatever to mail them posing as a customer and telling that you don't like maps and that they just lost a sale because of it... if you don't like them complaining to their nonexistant support is not likely to help you - complain to the people who use their services and think it's pretty cool, at least then there's a possibility of them dumping maps as a way.
the whole way how an address gets to the list is of suspect anyhow:
***************
"After you have read our Guidelines for Reporting Email Abuse and have completed the research necessary, you are ready to submit a nomination to MAPS to have an IP address included on the MAPS RBL.
Start your message with a brief, one paragraph narrative with the details summarized:
"I am nominating a site for listing on the MAPS RBL. I received this spam... I reported it they ignored my report... I confirmed the relay... I called them, and they said... "
Include in-line, all related phone conversation transcripts, copies of the spam with full headers, the abuse report, the response or auto-ack and any other correspondence you received. Additional information should include further documentation of the spam problem, webpage source code, or other necessary information.
An Investigator will review your nomination and contact the owner of the IP address to see if we can resolve the issue. If no response is received, or the responsible parties are unwilling or unable to rectify the problem, a nomination to the MAPS RBL is made. The Investigator creates a nomination that documents the entire Investigation and Notification process. The nomination is entered into the MAPS RBL for certification and approval by Management.
This certification process verifies that the information in the nomination is accurate, and that a reasonable effort to contact responsible parties has been made.
"
***********
even if you DO answer to the accusations it's your word against the accusers and they got NO WAY to find out for sure - it's impossible to tell if you're a spammer or just some guy that some idiot is trying to frame, if you are a real spammer who really owns that ip you're likely to deny it anyhow.
world was created 5 seconds before this post as it is.
The real problem though isn't MAPS and their attitude, it's the spammers. Get rid of the spammers and you get rid of the need for MAPS. These lowlife internet-scum are where any ire ought to be directed, again IMHO.
I disagree. The problem with MAPS is they take the "vigilante with a shotgun" approach to eliminating spam. You get a couple of spam vigilantes that want to cause "the most financial harm possible" to spammers and anyone that associates with spammers, and you have the potential for a lot of abuse.
Just to give you an example, I used to host a couple of vanity domains on a webhost in a colocation facility. A customer of a completely different webhost in the same facility decided to webhost some spammers. This is 3 or 4 degrees of separation from my vanity domains. MAPS decided to blacklist the entire freaking colocation facility until the spam stopped.
That is borderline ridiculous, and their admins have some serious attitude problems. They feel like it's better to penalize many just because a few bad eggs are mixed in. Well, they need to tune their blacklists because I don't trust them.
Philosophical question for you:
If MAPS decides to punish everyone in a colocation facility because a few spammers are customers of a customer in the same facility, how is that any different than Al-Qaeda deciding to punish all of the US on 9/11 for the actions of a few people in the US government?
"When the president does it, that means it's not illegal." - Richard M. Nixon
Well, I think it's pretty damn irresponsible for RBLs to be blocking entire subnet, as tempting as that might be. We had RoadRunner do that to our /23 address space, and we couldn't even find anyone who could do anything about it. I eventually said "Screw you" and refused delivery of anything with "rr.com" on the end of it. A few months ago, the block simply disappeared.
The world's burning. Moped Jesus spotted on I50. Details at 11.
This is a myth.
I'm sorry, but the idea that only blocking known offenders is unworkable has been proven wrong over and over.
I use a combination of greylisting, SPF and a small number of blacklists which have strict non-collateral damage policies.
Today, as an example, on a small personal system I've actively rejected 2576 connections, and allowed 228 messages. Of those 228, 75 were then identified as spam by SpamAssassin. A 97% success rate on a VERY low-bandwidth / CPU first-pass is more than acceptable for almost any application, given that you have a second pass (e.g. SA) which further improves your results to about the 99.9+% level.
The trap that people end up in is thinking that they need their first-pass to be as effective as a stand-along spam filter. Not true. You only need it to be effective enough to reduce the burden on your network and hardware by skimming off most of the incoming spam before it has a chance to consume those resources. If you're a VERY large ISP, then you might need to adopt additional measures (and while I despise the way AOL has done it, for example, I understand their reasons). If you're not one of the 10 largest ISPs in the world, then you are kidding yourself.
I have one user who asked me if mail was broken when I first deployed this. He was concerned because he'd come to think of the steady trickle of spam as a sort of heartbeat.
Indeed. Anyone who uses MAPS to blackhole mail is an idiot, and should have their root privs taken away. Seriously. These sorts of lists are GREAT for greylisting -- increase your spamassasin score by a few points, or something like that.
But anyone who uses MAPS to blackhole servers is lazy and incompetant.
So following your reasoning to a rather ridiculous end, I should block any mail originating from the US (and possibly Canada) because that is apparently where the bulk of spam mail (sorry UCE) comes from.
.plus.com were blocked (UK ISP). Ironically my brother's company use MAPS.
...
I don't think so somehow.
I also had my IP plugged by MAPS in this way as a result of an over zealous vigilante. Large parts of
Fine, I thought, I'll just have a look at the web site and find out what I'd done wrong. I had just compiled up a new Exim MTA with Spamassassin and Sophos but perhaps I'd done something wrong (no it isn't open).
A quick check showed all the links to info I really needed pointing to product info for Kelkea. E-mails resulted in automated responses.
In the past I'd thought of MAPS as one of the good guys, oh well
So, my opinion:
I don't think you should go after an entire block of addresses - it's just not fair to the innocent
Don't use address lists that you can't trust - ie those in the hands of a company that seem to try and impress with the size of their lists (I'm male and a Company Managing Director and I'm not impressed by that sort of size 8) )
If you look after anti spam systems, then don't just tick the boxes (especially if you use say Mailsweeper on Win). Evaluate the lists that you use for blacklists and if you do use lists, then consider how you use them. Most of the responsible ones eg SURBL via Spamassassin means that you score spam according to hand sorting, ie people have spent a great deal of time with huge volumes of spam and ham, creating scores that are justifiable.
I'm off to install DSpam now for a really large customer now - no lists, no scores - just opinion from those who count - THE CUSTOMER (they *know* what is spam wrt them)
A while ago, when the MAPS DUL virus first began to spread, my dad began to have problems delivering his mail from his Linux system on a cable modem. So I contacted MAPS and told them about what I naively assumed they would agree was unintentional collateral damage. Not only did they refuse to take his IP address off the list, they were spiteful enough to contact my dad's ISP and register a complaint about his "unauthorized" server!
It goes without saying that my dad is not a spammer. And we both see to it that his system is properly maintained and configured. All we ever wanted was to exchange email email without depending on his ISP's slow and unreliable mail servers.
MAPS and other spam vigilantes are actually far worse than the spammers they claim to be fighting. No spammer has never prevented me from sending or receiving wanted email. MAPS often does so, and they have to go away. Since they're unlikely to do so on their own accord, our only alternative is to educate the ISPs to not use their services. Openly boycot any ISP who subscribes to the MAPS, and tell them we simply don't want their "help" in blocking email. Patronize the more enlightened ISPs that give you a choice as to how or whether your mail will be spam-filtered.
I agree, my first real negative experience with them, was when I was attempting to be proactive. I was setting up an email server and wanted to find out what holes came in the base configuration. I feed it an IP plugged the in-progress server to get back a report, and found my IP address automatically blocked. This address belonged to an active server that was already properly configured but the client didn't have any extra IPs for me to use. There server was down the entire weekend, plus three workdays, before I could get them to remove the ban. Yet, they encourage techs to test a machine and receive a report of security holes. After that, I pretty much put out the word to never use their service to test a machine that's being built.
I hate spam, but their methods pretty much demand a new approach to fighting spam, creating blacklist, and even just testing servers. Their support is horrible and while it guarantees it will hurt a spammer here or there, that's pretty much like shooting in a crowd then stating well at least I killed a bad guy.
The blacklists you need to worry about are the ones that don't tell you that you are on them - the multiple small ones that quietly shut off access to their mail servers, or send email from certain net blocks to /dev/null and never check to see if the spam has stopped. You will never know how many of these your co-lo's spamming customers have annoyed to the extent they just flipped the switch.
Spam has been a big problem for long enough, and the various blackhole lists have been in action long enough, that your ISP or co-lo or whatever should have been aware of the consequences of harboring spammers. One of the " rules of the internet" is that I can refuse to accept email from any domain I don't feel like accepting email from. If I choose to accept the recommendations of MAPS, it's my right to do so ... you and your ISP have no right to tell me I must or must not listen to MAPS or even Fluffy.
RBL's are a terrible idea. I wouldn't say they are outdated though, mostly because they were always a terrible idea.
/. and posted an email address cringes)
There is nothing easier for a spammer to defeat then a RBL; they just set up a server in their closet and run their own SMTP server. Most DSL and cable connections use temporary IP addresses and you can't RBL Verizon. No spammer is going to co-lo a server to send spam from.
Spam complaints are often ridiculous due to user ignorance. I used to work for a company that send a plain text newsletter to a 100% opt-in mailing list once a month. To receive a mailing a user either had to sign up on the website or via a piece of paper on the front desk. They still would get spam complaints both to themselves and to their ISP.
Half the time they were from people that specifically signed up to get mailings. It wasn't as if we were mailing previous customers or anything, you had to say "please send me your newsletter". Evidently these people either forgot or changed their mind and couldn't be bothered to click the opt-out link at the bottom of the email. Somehow, 9 out of 10 of these people were AOL users, Funny.
The other half they were even more crazy. One time the guy was not even in the mailing list database; we weren't sending him mailings. We even checked with him to see if he had a second address that could be forwarding mail to the one in question but he claimed he had no such mailbox. There was simply no way for us to remove him from the list because he wasn't on it in the first place. Another time, we deduced that someone else had signed up the person in question (the person's last name was recorded in the database as "Assface"). Evidently someone didn't like them very much and had signed them up for every mailing list they could find. Kinda a good method of getting back at someone I suppose. (everyone that has ever flamed anyone on
Laws, RBLs, regulations... all these things are both ineffective and erode our freedom. If you don't want spam there are three things to do: 1) Don't post your email address on the web, use a PHP mailer instead. 2) Don't give out your personal address, use a a "spam" address. My Dad once gave his real address to one of those "win a Segway" things at the mall (he must have been drunk or something), he now gets about 200 spams a day, up from zero. 3) Use an email filter. The good ones don't even use blacklists and work great.
And well... 4) Don't piss someone off that knows your email address.
Cool art gallery, if you're into that sort of thing.
I use DNS blocklists for the simple reason that they work, and they work with a lot less CPU time than content analysis filters such as SpamAssassin.
I don't use MAPS, but my experience with the ones I do use, such as SPEWS and Spamhaus is that it blocks around 90% of my incoming spam with very few false positives. While they continue to produce these results, I will continue to use these filters to manage my incoming mail.
I use SpamAssassin on the remaining 10% of the spam, and it catches most of the rest of them. I could use it on all of them, but it would take too long to check my email if I did that.
In this day and age, anyone with any sense who has a legitimate need to run a mail server on a dynamic address also relays through their ISP's mail servers and bypasses blocks like that anyway.
Except that doing that takes away one of the big advantages of running your own mail server, a lack of limits on outgoing attachments. Now, depending on ISP, this may or may not be a big deal, but in 2005, a 2MB attachment limit is rather small.
I personally like running my own e-mail server for several reasons, one IMAP + webmail if I want.
Two, I don't have to change my e-mail address every time I move from college back home for the winter, or when I transferred colleges or go on to Grad School, or change my parents e-mail when we changed ISP's last year or just today to DSL.
Three, buy using my own PC, I can use the free dydns service to have a practically unlimited mailbox size (well 50GB, but...) unlimited e-mail addresses, aliases etc for free as opposed to paying for hosting monthly.
Also, in terms of flat out buying e-mail service, I've found running my own server to be either the equal or better in terms of reliability. For free to me, as I have the PC and net connection regardless of the third party e-mail service.
I personally hate the blocks that spammers and others are forcing on us ligitimate users who want to actually use their PC for stuff. VNC blocks piss me off, because the resnet staff tell me it's a security vulnerability. Well, VNC is free for me to use, I can't afford, nor do I have any desire to pollute my system with the shit of PC Anywhere. I also don't believe PC Anywhere has a Java client you can use from any PC like TightVNC does.
They started blocking things like TOR. FTPS, SSH. I tried to explain to them that SSH is far from unsecure/unauthenticated. I said if they allowed SSH I could then tunnel VNC over that and it wouldn't bother anyone.
They even block IRC Chat! Not just DCC, but you can't even chat. Now DCC has legitmate reasons to be blocked, but chatting? Let me tell you that you can get more info from IRC than you ever could from yahoo (which they allow).
And if you are an astalavista.net member, you can't even use the Java IRC Client.
Anyways, I really get pissed off over the thought that we NEED to have companies being the server to us clients. I think P2P has shown that people are capabile of being PEERS in the internet, like it was designed to be.
And moreso, they(the resnet, or ISPs) consider that users should be second class citizens for whatever reason. Heck, most of the listed "servers" wouldn't touch the bandwidth usage of Kazaa or Bittorrent.
Opera, Proxomitron-Grypen,GPG 0x0A1C6EE3
Why is an IP address not just an IP address? Stop being so elitist. IP didn't have a NOBLEMAN/SERF bit in every header last time I checked.
It's lazy ISPs' faults that spammers aren't shut down quickly, thus these blacklists have to take out whole blocks, causing collatoral damage like the original article describes.
The internet was designed to allow PEERS to talk to ther PEERS. It's an equal-opportunity protocol stack, by design. Too bad some people no longer believe in this principle.
ERROR 144 - REBOOT ?