Slashdot Mirror


Microsoft Researchers on Stopping Spam

TheBackBencher writes "Scientific American today has a very interesting article about "Stopping Spam" by Joshua Goodman, David Hackerman and Robert Rounthwaite from Microsoft Research. They talk about different types of spam -- spam with emails, spam on IMs, spamlinks on web pages and image based spam. They mention different techniques for spam filtering mainly fingerprinting matching techniques, n grams model, naive bayesian approach, optical character recognition, challenge/response systems and Human Interacted Proofs (HIP) in a very lucid style. They however do not mention fingerprinting approach of using Nilsimsa Hash to tackle addition of random words by spammers in emails or hypertextus interruptus technique used by spammers of splitting words using HTML comments, pairs of zero width tags, or bogus tags. Also, Spam-Research is reporting the SplitFit Technique that Spammers are using to fool Yahoo! Mail SpamGuard."

294 comments

  1. The Microsoft way by Anonymous Coward · · Score: 4, Funny

    Creating your own spamming division, use illegal tactics to undercut your spamming competition, put them out of business, then stop spamming.

    1. Re:The Microsoft way by Anonymous Coward · · Score: 0

      Ah yes, that might explain the acronym for the division looking into this... MiRe.

    2. Re:The Microsoft way by vwjeff · · Score: 4, Funny

      They talk about different types of spam -- spam with emails, spam on IMs, spamlinks on web pages and image based spam.

      Well, there's egg and bacon; egg sausage and bacon; egg and spam; egg bacon and spam; egg bacon sausage and spam; spam bacon sausage and spam; spam egg spam spam bacon and spam; spam sausage spam spam bacon spam tomato and spam;

      (punches self in face face hits keyboardadsfjlk;sjdafkldsajflsdak;fjsad;lfkjas;ldk fjas)

    3. Re:The Microsoft way by Anonymous Coward · · Score: 0
      (punches self in face face hits keyboardadsfjlk;sjdafkldsajflsdak;fjsad;lfkjas;ldk fjas )
      Wow. I'm impressed. You even managed to balance the parentheses while doing the face-to-keyboard routine.
    4. Re:The Microsoft way by Gentlewhisper · · Score: 0, Troll

      Wow. I'm impressed. You even managed to balance the parentheses while doing the face-to-keyboard routine.

      If you are a Windows developer you would have long gotten used to it by now...

    5. Re:The Microsoft way by smallguy78 · · Score: 1

      Then pay $2 billion in lawsuits

      --
      Nothing costs nothing
  2. I have an idea by Sonar · · Score: 1, Interesting

    I have an idea for stopping spam. How about sent mail is not flagged as recieved until it is viewed by the user. Once it is viewed, it can be flagged as good or flagged as spam. If the mail is flagged as spam, the mail could be sent back to the orignal host as unreturned mail.

    So for every mail that is sent out, once flagged as spam, could be sent back. Of course, normal spam filters would also flag the data as spam. If the e-mail is returned to the host, maybe they will remove the e-mail from thier list. Otherwise they will just recieve a bunch of spam as well as sending it. It could clog up bandwith pretty good.

    However this probabally wouldn't work if they somehow spoofed the sent address.

    1. Re:I have an idea by datafr0g · · Score: 1, Redundant

      Also, if you reply, the spammer will know your address is active and send more crap.

      --
      "Who says nothing is impossible? Some people do it every day!" - Alfred E. Neuman
    2. Re:I have an idea by Yolegoman · · Score: 1

      However this probabally wouldn't work if they somehow spoofed the sent address.

      No, it wouldn't. Spam that has the sent address spoofed is stupid, though - how are your "customers" going to buy your 1337 \/!@8r@ p!|_|_$?

    3. Re:I have an idea by Aeiri · · Score: 3, Insightful

      Interesting idea, however invalid address responses are sent within 5 minutes of the original mail. If the response is sent over a day after the original mail is sent, the spammer could just discard it.

      If we respond instantly to all email with invalid address mails, it will be overused and spammers will ignore ALL of them. This is much like antibiotics, we use them too much, the bacteria accommodates for it, and antibiotics become obsolete.

      So far, bayesion filtering and/or whitelisting email are the only good systems of blocking spam at the moment.

    4. Re:I have an idea by xQx · · Score: 5, Insightful

      Here's a more interesting idea...

      Authenticate SMTP with public key signing. -- Then use a trust network to only accept email from trusted companies.

      Why it won't work:
      It involves effort and cost.

      Baah, the internet should be unregulated, if they can get rid of SPAM then whats to stop them getting rid of porn, anti-government information etc. There's a road we all want to go down.

      Don't buy it and Get over it(tm).

    5. Re:I have an idea by ConceptJunkie · · Score: 2, Interesting

      I assume you're being facetious. Why does stopping someone from sending you garbage equate to not being able to find something. That argument sounds like those nitwit "censorship" whiners who think Freedom of Speech means Freedom to be Heard and that all content must be available at all times in all places.

      Anarchy never worked in the real world, how could it work in the electronic world?

      --
      You are in a maze of twisty little passages, all alike.
    6. Re:I have an idea by damiangerous · · Score: 1

      Usually through instructions in the spam itself, such as a link.

    7. Re:I have an idea by Anonymous Coward · · Score: 0

      Then go after the owner of the site.

    8. Re:I have an idea by damiangerous · · Score: 1

      And when it's based in China or some third world country? Or when it's a joe job?

    9. Re:I have an idea by ChuckSchwab · · Score: 0, Troll

      What's the point of your idea? To stop spam? If so, I don't see the point. What you call "spam", I call "emails that help me learn about the latest products, websites, and business models". You want less of it? I want MORE of it. "Spam" keeps me informed about the world. And the fact is, consumers LIKE spam. Why do you think spam is profitable? Because people buy the products advertised! Studies show that 3 in 5 people who dislike "spam" have actually bought something online. So frankly, you need to be real careful about how you define "spam" because you could be targeting something you LIKE.

    10. Re:I have an idea by menace3society · · Score: 1

      Actually, if this became widespread, it would exacerbate the spam problem. Currently, if a spam mail server gets a bounced message, it has no reason to believe that the bounce is fake, then it may actually remove the address from its list in order to conserve resources. On the other hand, if programmers know that spam is being bounced even if it is sent to a valid address, they will just keep sending to that address. Hence spam-related traffic will nearly double (original message + bounce), but it won't go down in the future either.

    11. Re:I have an idea by Anonymous Coward · · Score: 0

      How much spam is acceptable? 70% of all Internet traffic? 80% 90%? 99%?

    12. Re:I have an idea by Anonymous Coward · · Score: 0
      Don't buy it and Get over it(tm).
      I know you're probably anti-spam, but that is probably the exact same rationalization spammers use.
    13. Re:I have an idea by killjoe · · Score: 1

      Doesn't bernstein have a scheme where the sender stores the email until it's accepted? Is seems like that would make spamming a little more expensive at least.

      --
      evil is as evil does
    14. Re:I have an idea by Anonymous Coward · · Score: 0

      Get over it

      I did. I've gotten over several email accounts already. I haven't looked at my main inbox for months now, I just get the less than 1% of emails that are on the whitelist. I only bother to check my new account, which hasn't made the spam lists yet. I have yet another waiting in the wings for when my current account becomes useless.

      Have you ever had to move out of a house because you could no longer communicate with the world, simply because of the huge volume of solicitors? An email account should last forever, not be a disposable thing to be dropped as soon as it becomes public.

    15. Re:I have an idea by Anonymous Coward · · Score: 0

      It depends on where you place control. I suggest placing control with the end-user. If they don't want to receive spam, they can avoid it. If they want porn and anti-government information, they can still get it.

      Your idea is fine with a few tweaks: First, allow "unauthenticated" mail, and let the end-user choose how to handle this. Initially all mail is unauthenticated (and looks just like the mail we have now). As more people use authentication, it becomes a factor in our bayesian filters. Eventually we can start blocking unauthenticated mail by default.

    16. Re:I have an idea by geekboy642 · · Score: 1

      I have a better idea for stopping spam:

      Arm the geeks.
      Get some buddies together, take paypal donations to buy some BFGs, and do some vigilante justice.

      Seriously, what jury would convict the guy that shot up a spammer?

      --
      Just another "DOJ fascist authoritarian totalitarian bootlicker" -- Zeio
    17. Re:I have an idea by sfe_software · · Score: 5, Insightful

      Interesting idea, however invalid address responses are sent within 5 minutes of the original mail. If the response is sent over a day after the original mail is sent, the spammer could just discard it.

      The thing is, I don't belive spammers ever remove an address due to an error. I had a domain that received a ton of spam, and that domain expired. Two years later (fighting with Network Solutions) I got the domain back, and immediately started receiving a ton of spam. Two years of spammers sending spam to invalid addresses (no DNS on the domain) and they still continued.

      Why?

      Simple: the spammers don't receive bounce messages, and the spam-servers (which could be static servers, or compromised zombie machines) don't provide accurate return information. Much like how telemarketers often show invalid or "Unknown" caller-ID info. It costs nearly nothing to send a spam message to an address, whether that address is valid or not. It costs much more to weed out invalid or unreachable addresses from your list by intercepting bounce messages etc.

      And spammers don't give a shit. Most of the time, they are using someone else's machine (a zombie'd Windows box, or an open relay) so they don't need to care. So this trick simply doesn't work. It's cheaper to just continue sending to invalid addresses. Not to mention, many newbie spammers get their lists from less-than-legit sources who are selling large lists; they don't care (and are usually fully aware) that many of the addresses they are selling are bogus or no longer valid...

      In short, simple tricks like this don't work, when dealing with an "industry" that doesn't give a shit...

      --
      NGWave - Fast Sound Editor for Windows
    18. Re:I have an idea by Anonymous+Luddite · · Score: 1

      >>Usually through instructions in the spam itself, such as a link.

      That's exactly how it happens. The spammer places an innocent domain name in the "reply-to:" field and HREFs in the message-body to reply through.

      It has been happening lately with one of my domains - I get bounce emails explaining that the spam filter at wherever.com can't deliver my adverts for full-length adult DVDs...

      So please, if you get this crap and need to respond, don't use the "reply-to:" field - it's fake

    19. Re:I have an idea by Keeper · · Score: 1

      All spam spoofs the sent-by address. As evidenced by the eighty thousand bounce mails I've gotten in my inbox the last 2 months (some spammer kindly used MY email address as the sent-by address ... if I ever meet the responsible party, they won't live to tell about it).

    20. Re:I have an idea by Threni · · Score: 1

      > It could clog up bandwith pretty good.

      Don't you think enough internet bandwidth is used up by spam in the first place, without devising methods to instantly double it?

    21. Re:I have an idea by Threni · · Score: 1

      > Seriously, what jury would convict the guy that shot up a spammer?

      A jury consisting of members who are prepared to jail psychopaths?

    22. Re:I have an idea by mce · · Score: 1

      Bad idea. I'm on the LKML, just to stay up to date with what's going on in kernel land. But every so often I'm away from the net for a few days and when I'm back I regularly have no time to read up on everything that happened in the mean time (look up the average daily volume of the LKML and multiply by +-5 to get an idea how many mails this can be about). So when this happens, I mass-delete all my unread LKML mails without looking at them. That doesn't make my LKML feed unwanted SPAM, tough.

    23. Re:I have an idea by Antique+Geekmeister · · Score: 1

      My God, who bought into Microsoft's proposals seriously enough to bring down this load of bad ideas on our heads? Pleae, please, please, gentle readers, go read up at sites like www.spf.org and www.spamhaus.com and the RBL sites and the various websites on what's already been tried and what doesn't work!

      You're right about the expense and effort being significant. You've also left out that the PGP keys of major sites, once stolen, will be passed around and used by the same crackers who sell access to zombied machines now to sell spam services.

      In the US, at least, there is a major legal hurdle to stopping spam called the Direct Marketing Association. They are the junk mailers and sales-by-phone companies, and vaguely more legitimate advertisers who use bulk mail and bulk email. Getting clear laws in place to block spam will make legal precedents against their members' businesses: that's why they fought the junk fax laws so hard, when junk faxes got so burdensome that it was eventually outlawed.

    24. Re:I have an idea by Math,+The+Ancient · · Score: 1

      It's already been successfully argued (imho) that RBL's do not work, either.

      --
      If I really am talking out of my ass...explain it to me with respect so I'll at least pull my ears out to listen.
    25. Re:I have an idea by R34L · · Score: 1

      Is that what slashdot uses (bayesian) when they stop all the: frist psot (splitFit)

    26. Re:I have an idea by Nelson · · Score: 1
      There are many variations on this idea that don't fundmentally involve that many changes to SMTP. I think we're at a crossroads here. What are the "best practices" for spam? Filters with their obvious problems, Black lists which have worse problems, the sender auth where the smtp server logs in to your server during the message transit to check that your server is valid (you know how screwed up that is?) or my favorite dump HTML email because just text is the way to go anyways.. Maybe we should stop using GUIs too because then there won't be any popup ads...


      We're trying to fix a broken protocol with terrible band-aids.


      Add layering to SMIME or OpenPGP. All server to server communication is signed and optionally encrypted (there are clear benefits besides that like compression also and a degree of security from snooping) There are already well established trust mechanisms, you want to run an SMTP server, you pay a CA to have your cert signed.


      People are already spending money on implementing shit to fix spam, the cost of a cert is next to nothing. You can phase it in, put non-signed email in the "questionable" folder until it all but goes away. No changes to client software and best of all, email will get through, you'll never miss an email because some POS filter thought it might be a spam. If you do get spammed, report it and there is an easy way to track it back to its source and have the problem corrected. Also, and this is indirect, the cost of sending email goes up, you'll have to perform some costly calculations to sign and or encrypt them; that's part of the security, it's like rate limiting.


      Further, if you deploy SMIME or OpenPGP, this could be pushed to the endusers. There are tons of ways to evolve this.

    27. Re:I have an idea by TFGeditor · · Score: 1

      No, it is an ignorant idea. ALL spam has a spoofed FROM address. The only clue as to origin is the IP address in the header, which only identifies the owner of the address. If your server software is smart enough, you can bounce at server level back to the point of origin, or maybe to the absue@ or postmaster@ address for the domain.

      --
      Ignorance is curable, stupid is forever.
    28. Re:I have an idea by Anonymous Coward · · Score: 0

      You sure
      about anarchy never working?

  3. I don't know... by Anonymous Coward · · Score: 4, Insightful

    If it was developed it can be reversed engineered. Sorry to say but spam is here to stay unless of course someday the internet becomes regulated somehow.

    1. Re:I don't know... by cheekyboy · · Score: 1

      maybe,just like radio after 1929 depression was regulated, perhaps after the next depression, they nut cases running the world will get real real paranoid (their drugs must be running out) and then regulate everything that makes them slightly insane.

      They can try, but they will have a tough battle on their hands, and I bet the hackers will rather fight to the death/100% shutdown of the net just to piss em off and send the companies bankcrupt.
      The IT techys working for the 'govt' wont be as motivated by desire as the hardcore hackers. Its like any rebelion vs authority, the rebels always win or get their own 'zone'.

      --
      Liberty freedom are no1, not dicks in suits.
    2. Re:I don't know... by cgenman · · Score: 1

      If it was developed it can be reversed engineered. Sorry to say but spam is here to stay unless of course someday the internet becomes regulated somehow.

      That's silly. Encryption has been thoroughly reverse-engineered, but it's still completely secure. The Linux source code is widely available, but it is still considered relatively secure.

      There are several competing proposals for how e-mail could be re-done to take into account the possibility of spamming. Preventing false headers and return addresses would be a great step towards that. Having some form of human verification system might as well. Using large, distributed networks collecting wild spam would be a third. Any of these would help. Some of the other proposals may very well solve the great majority of the problem.

    3. Re:I don't know... by Anonymous Coward · · Score: 0

      Paul Graham did a pretty good job at killing most spam, for an awful lot of people.

      I'm not alone in thinking so: Joel Spolsky says "in practice, in the presence of lots of spam, human beings are far more likely to delete a real email than a well-implemented Bayesian filter".

      Plus I think it's pretty cool that one guy with a Lisp compiler beat the crap out of Microsoft Research.

    4. Re:I don't know... by Anonymous Coward · · Score: 0

      There's no need to "regulate the Internet", not in any aggressive way. In the US, there's a law against junk faxes, US Criminal Code Section 18, paragraph 2701. It's been extremely effective against reducing though not absolutely stopping junk faxes: it would only take a few words more to extend it to email.

      That law has already stood up well to various constitutional tests, and would free up ISP's to cut off customers for breaking the law and free up victims to sue the spammers. Unfortunately the victims right now are hampered in the US, which gets most of the spam because it's where so much of the money is, by the CANSPAM act which blocks more rigorous state laws and acts only against blatantly fraudulent commercial spam, not spam in and of itself.

    5. Re:I don't know... by permaculture · · Score: 1

      Two points about spam:
      1) The most important feature of any spam filtering system is that it should have a few as possible false positives (genuine email but incorrectly regarded as spam, which are then lost.)

      2) In the end, we need to stop spam being _sent_. At the moment most effort is going into filtering the spam out after it's been _received_. Clearly we can spend forever writing spam filtering rules, with the spammers a few steps ahead all the time.

      Having said that, we work with what we can get. At the moment where I am we're using Ironmail v4.5.2.
      http://www.ciphertrust.com/products/index.php

      This is a big improvement over the last version of Ironmail, which wasn't half bad.

      Check out these numbers:
      MAIL: wk to 07 Apr -
      505365 in;
      16148 viruses; 3%
      399415 spam; 79%
      89802 clear 18%

      March: 2475384 in;
      74300 viruses; 3%
      1995630 spam; 81%
      405454 clear; 16%

      Those are hard and fast numbers from the box. The important number (false positives) is of course not so easy to generate. And there's my point.

      --
      Environmentalism is the new Victorianism. Everyone ties on a green corset and pretends we're virtuous.
  4. The way to stop spam... by John+Seminal · · Score: 0, Flamebait
    Legislate against spam. As long as spam is legal, or the penalties against it are too low, or it is too easy to do, people will continue to try and make a quick buck.

    Also, force all ISP's to monitor how much bandwith a source has. If you get too much usage per day, say 200 megabytes or more, then that person has to explain why they need that much bandwith. If someone gets the RIAA on board, with their lobbyists, that should pass very quickly.

    Also, force all email to have some element which identifies the source. Not just a header that can be forged, but something that can't be hacked. And if a source can not be found, but it is selling a product an identifiable site, charge that site just as if they were the ones sending the spam.

    --

    Rosco: "If brains were gunpowder, Enos couldn't blow his nose."

    1. Re:The way to stop spam... by Sonar · · Score: 5, Insightful

      Of course, one 200MB update from Microsoft would kill this idea. Or how about a 500MB game demo download? Thats legitimately free. Or better yet, what if I need to download a linux distro or a television episode?

      I would hate to have to explain all my actions to my ISP. Espically with the way media is driving the internet nowadays. 200MB is way too small of a limit.

      Now, you can monitor how many e-mails are sent by a host. That would be a better way. At least there could be a filter on the "to:" line. If that list includes over say, 1000+ users, consistantly, then at least there could be some flags raised.

    2. Re:The way to stop spam... by John+Seminal · · Score: 1
      I would hate to have to explain all my actions to my ISP. Espically with the way media is driving the internet nowadays. 200MB is way too small of a limit.

      Now, you can monitor how many e-mails are sent by a host. That would be a better way. At least there could be a filter on the "to:" line. If that list includes over say, 1000+ users, consistantly, then at least there could be some flags raised.

      That is a good point. With my daily bandwith threshold test, I was thinking that if someone is uploading a very, very large daily avarage of bandwith, it might be a red flag. But if you can count the number of emails sent, that is even better.

      I am wondering. Is there any way to force email to only run on 1 port, without any proxies, that all routers can then reject any other mail originating from any other port??

      That also reminds me of another idea floating around. Charge $0.01 per email, or some very small amount of money, so that it does not harm the avarage computer user, but will eat up all the profits of a spammer.

      --

      Rosco: "If brains were gunpowder, Enos couldn't blow his nose."

    3. Re:The way to stop spam... by Anonymous Coward · · Score: 0

      And SPAM is different from junk snail-mail how? (BTW, anyone have any idea as to why bulk E-mail postage costs less than regular snail mail postage?)

    4. Re:The way to stop spam... by pipingguy · · Score: 1


      Now, you can monitor how many e-mails are sent by a host...

      Doesn't Gmail do this already (i.e., receive and analyze millions of messages)? Junk could be filtered with legitimate mailing lists getting a "pass" based on criteria from recipients.

      OK, bad idea and someone's sure to post one of those automated checklists any time now.

    5. Re:The way to stop spam... by John+Seminal · · Score: 3, Interesting
      And SPAM is different from junk snail-mail how? (BTW, anyone have any idea as to why bulk E-mail postage costs less than regular snail mail postage?) The main difference is if I want to send you something through the mail, I have to put a stamp on it and pay money to ship it. If I want to spam you, I can write a virus and get 1000 machines to pump out the spam. I can do it so it does not cost me anything but my time.

      Plus, with the postal service, there are 1000's of laws in place. If I send you an offer through the mail designed to rip you off, that is a federal offense. You can't use the US Postal Service for illegal activities, if you do you get caught.

      Remember the movie The Firm? They did not convict the lawyers for tax evasion or any other crime. They convicted them for mail fraud. And if you let the worst spammers know that each and every time they send a message that is spam, each instance will incur a penalty, that might stop them.

      --

      Rosco: "If brains were gunpowder, Enos couldn't blow his nose."

    6. Re:The way to stop spam... by Anonymous Coward · · Score: 0

      "Also, force all ISP's to monitor how much bandwith a source has. If you get too much usage per day, say 200 megabytes or more, then that person has to explain why they need that much bandwith. If someone gets the RIAA on board, with their lobbyists, that should pass very quickly"

      This is a horrid idea. I probably exceed that limit thrice a week. Game demos can run up to 500 MB, Linux ISOs anywhere from 60 MB to a few gigs.

      And then there's all that music too.

    7. Re:The way to stop spam... by mjensen · · Score: 1

      Check the slashdot archives/history for email.
      These items have been discussed MANY times before here.
      Search slashdot for "spam" or google for "spam solution site:slashdot.org" or "Obligatory spam solution rejection form"

      To answer your wonderings:
      Some ISPs block port 25 except going to their own servers. This means you can only access the email server of your ISP and no other ISP. Can't forge return addresses then. Many people don't like this.

      Charging a fee for email is immediately flamed by mailing lists. Those people legitimately send 1000 or so messages a day to people that signed up for the list. This will cost them upward of $10 a day or more.

    8. Re:The way to stop spam... by Anonymous Coward · · Score: 0

      Of course, one 200MB update from Microsoft would kill this idea. Or how about a 500MB game demo download? Thats legitimately free. Or better yet, what if I need to download a linux distro or a television episode?


      Then, as the post you replied to SAID: "that person has to explain why they need that much bandwith".

      SO, you simply explain that you has a big DL to do. Problem solved.

    9. Re:The way to stop spam... by globalar · · Score: 2, Insightful

      Legislation ultimately runs into international borders and places where U.S. law cannot go. It can help, but honestly I am not sure how to craft a good law that will keep up with the pace of technology. Also, a law does not guarantee effective enforcement.

      A better strategy, IMO, is to work on the commercial level. It has been said here on /. many times that if there were no money for spammers, there will be no spam. When spam becomes an issue which decides where money goes (who wins and who looses), the economics will take over. We need to convince people and businesses of simple ways to stop spam.

      Forcing monitoring is counter-productive. ISP's need to voluntarily enact monitoring schemes for their own benefit and that of other parties. When an ISP is convinced that they can contribute to stopping spam and that this is in their best interests, their efforts are more likely to be aimed at succeeding not simply complying.

      Also consumers need to get involved, but not with lobbying Congress (on this particular matter). ISP's and webhosts need to believe that consumers will factor spam tolerance into their decisionmaking. Consumers (and other buyers) need to follow up and practice this a little - at least a vocal plurality.

      On the community side, black-lists need to be scrapped in favor of informative lists of known, proven spam havens and spammers. What host's are the real problem? That is what buyers need to know. Block them if you want, but that is counter to how the Internet works and will not ultimately succeed. Instead, inform buyers who is responsible for letting spam through. Who should you not do business with? Do not be condescending or militant - be simple and clear. "So-and-so sends spam to your inbox."

      I agree, technical work needs to be done. But beyond protocols, formats, and other standards this is problem which can be solved through small changes in behavior across many groups. It cannot be centralized and squashed.

    10. Re:The way to stop spam... by Anonymous Coward · · Score: 0

      Monitoring what users do is a bad idea all around. I am paying for my bandwidth, I shouldn't have to justify what I do with it each and every day. Make span illegal, that way when a spamer is tracked down somthing can be done about it, but simply makeing large swathes of internet usage illegal in an effort to cure spam.

      sometimes the cure is worse than the disease...

    11. Re:The way to stop spam... by sfe_software · · Score: 2, Informative

      Legislate against spam. As long as spam is legal, or the penalties against it are too low, or it is too easy to do, people will continue to try and make a quick buck.

      I don't see that helping. Legislate in what jurisdiction? In which countries can it be enforced? Note that one can simply lease servers in a country immune to such legislation, or outsource to a company in such a country.

      Besides, FAX spam has been illegal for years, yet it continues to happen pretty constantly.

      Also, force all ISP's to monitor how much bandwith a source has. If you get too much usage per day, say 200 megabytes or more, then that person has to explain why they need that much bandwith.

      My DSL provider seems to have recently blocked port 25 outbound on me. Thanks to spammers I'm sure. So now I'm forced to use SBC's mail servers, or use a different port on my own servers.

      Which is not fair at all. Neither would a bandwidth cap, when I'm paying for "unlimited" usage regardless of what port(s) the traffic may travel on.

      Also, force all email to have some element which identifies the source. Not just a header that can be forged, but something that can't be hacked. And if a source can not be found, but it is selling a product an identifiable site, charge that site just as if they were the ones sending the spam.

      I can deal with the first part of this: if everyone can agree on some authentication/validation standard, some verification can be good. As long as it doesn't cost the sending server operator anything other than the time taken to verify who they are.

      The second part, though, won't fly. Forging the sender's address and/or IP is entirely too simple. And I've seend spam promoting a completely unaffiliated site, in the interest of getting a competing site shut down. In other words, send anonymous (forged headers) spam promoting your competitor, getting them shut down. Unless it can be proved beyond reasonable doubt that the company in question is in fact responsible for the spam, you can't convict or punish them...

      --
      NGWave - Fast Sound Editor for Windows
    12. Re:The way to stop spam... by sfe_software · · Score: 1

      Reply to my own post:

      And I've seend spam promoting a completely unaffiliated site, in the interest of getting a competing site shut down.

      Just to clarify, the typo should have said I've seen spam.... The way it's typed could be interpreted as I've sent, which is certainly not the case...

      --
      NGWave - Fast Sound Editor for Windows
    13. Re:The way to stop spam... by sfe_software · · Score: 1

      It has been said here on /. many times that if there were no money for spammers, there will be no spam. When spam becomes an issue which decides where money goes (who wins and who looses), the economics will take over.

      I agree 100%. The problem is educating the "average" PC user to recognize spam. To most of us it's easy, but to a casual user, that offer they received looks like a great deal. Hm, refinance at 1.3% interest? Enlarge certain appendages with all-natural herbs? One must be educated to be able to recognize scams for what they are.

      Forcing monitoring is counter-productive. ISP's need to voluntarily enact monitoring schemes for their own benefit and that of other parties. When an ISP is convinced that they can contribute to stopping spam and that this is in their best interests, their efforts are more likely to be aimed at succeeding not simply complying.

      Agreed 100%. As much as I hate to admit, AOL has done quite a bit to help the issue (took them long enough!)

      They started blocking port 25 a while ago. This normally sucks, but how many AOL users would be using an outside (leased/hosted) mail server? They also apparently offer spam blocking tools, though I haven't evaluated them personally...

      Instead, inform buyers who is responsible for letting spam through. Who should you not do business with? Do not be condescending or militant - be simple and clear. "So-and-so sends spam to your inbox."

      Not quite the same thing I'll admit, but I've steered a few friends/family away from X10 due to their popup ad practices. I believe they still continue this, though since Firefox I haven't seen their ads...

      More importantly, the best advise I give to friends and family is this: if it sounds too good to be true (especially on the 'Net), it most likely is. Bill gates isn't going to send you to Disney World, and you aren't going to find 10,000,000 USD in your bank account from some random Nigerian with money to launder.

      If the majority of people would learn these things, the majority of spam would no longer be profitable, and would ultimately cease...

      --
      NGWave - Fast Sound Editor for Windows
    14. Re:The way to stop spam... by Anonymous Coward · · Score: 0
      My DSL provider seems to have recently blocked port 25 outbound on me. Thanks to spammers I'm sure. So now I'm forced to use SBC's mail servers, or use a different port on my own servers.


      Not to disagree with your overall point, but FYI, you can request SBC to unblock port 25 outbound. I asked them to do it, and it was unblocked within a day or so.

      I forget the details, but I found the (Web) form I needed through their support site.

    15. Re:The way to stop spam... by Tim+C · · Score: 1

      SO, you simply explain that you has a big DL to do. Problem solved.

      SO, I'll need to explain to my ISP why I'm using a lot of bandwidth every other day or so? Doesn't that strike you as just a little bit of a pain in the arse? (Not to mention the privacy implications)

      You can't even have a system whereby if someone proves themselves to be a genuine "heavy internet uesr" over some period you stop checking them, as their machine could be compromised at any time.

    16. Re:The way to stop spam... by StormyWeather · · Score: 1

      Why is it if a company hires an advertising firm, and that advertising firm breaks the law it's ok?

      If the law made a company liable for a percentage of the liability of their advertisements even if through a third person proxy wouldn't that make companies think twice about dealing with shifty scammers that could get the company being advertised in hot water?

    17. Re:The way to stop spam... by Anonymous Coward · · Score: 0

      Also, force all ISP's to monitor how much bandwith a source has. If you get too much usage per day, say 200 megabytes or more, then that person has to explain why they need that much bandwith. If someone gets the RIAA on board, with their lobbyists, that should pass very quickly.

      That's the most stupid idea I've ever seen.

    18. Re:The way to stop spam... by Alioth · · Score: 1

      Spam requires no new legislation - only existing legislation be enforced.
      The vast majority of spammers are already breaking the law - selling counterfeit prescription drugs which is illegal, using hacked machines in zombie networks which is illegal, or promoting illegal scams. I don't think I've seen a spam message recently that hasn't broken the law in some way (either by using hacked computers or by advertising something illegal).

    19. Re:The way to stop spam... by Anonymous Coward · · Score: 0

      Bulk mail is presorted by the sender, must be the same size and weight. These things must make it cheaper for the post office to handle.

    20. Re:The way to stop spam... by jefu · · Score: 1
      On the community side, black-lists need to be scrapped in favor of informative lists of known, proven spam havens and spammers. What host's are the real problem?

      But spammers keep getting new hosts. Viruses on unsecured machines to send mail, and people just buying new servers or server names. Last fall I got a goodly amount of spam over a period of a couple months and always referring to new web sites - mostly in places like Uzbekistan and invariably registered through joker.com with a new name and address associated with it in the whois info. (Not that I'm saying it was joker.com's problem, it just seemed strange that there were so many, all with essentially the same characteristics and all through the same company.)

    21. Re:The way to stop spam... by TFGeditor · · Score: 1

      Wrong. We're talking about *outgoing* bandwidth, not incoming.

      --
      Ignorance is curable, stupid is forever.
  5. Like the old saying goes....(sorta) by erick99 · · Score: 5, Funny

    Spam is like porn: hard to define but you know what it when you see it. That can be hard to program I would think. But, who knows.

    --
    http://www.busyweather.com/
    1. Re:Like the old saying goes....(sorta) by datafr0g · · Score: 5, Funny

      Our offsite spam engine can detect porn by looking at shapes, colours, etc...
      It works surprisingly well most of the time, though it did once pick up a photo of a broken PCB as porn due to its detected "posture"

      --
      "Who says nothing is impossible? Some people do it every day!" - Alfred E. Neuman
    2. Re:Like the old saying goes....(sorta) by ramblin+billy · · Score: 3, Funny


      Maybe your engine isn't wrong. Maybe it's just perverted.

      billy - hey...that's not sadistic...just kinky

    3. Re:Like the old saying goes....(sorta) by Dimensio · · Score: 1

      Spam is like porn: hard to define but you know what it when you see it.

      Actually, spam is bulk email deliberately sent to recipients who did not request the mail.

    4. Re:Like the old saying goes....(sorta) by The+Archon+V2.0 · · Score: 1
      It works surprisingly well most of the time, though it did once pick up a photo of a broken PCB as porn due to its detected "posture"

      Printed Circuit Board? If so, my hard drive would like to see it. It claims it hasn't got any from the motherboard since little NIC came along. Too many daughterboards to take care of, the motherboard's never in the mood anymore.

    5. Re:Like the old saying goes....(sorta) by dmaxwell · · Score: 1

      It's one of Bender's drinking buddies. "Whoa! Look at the NAND gates on her! She's showing her circuits and everything!"

    6. Re:Like the old saying goes....(sorta) by dodobh · · Score: 1

      Spam is easy to define: Unsolicited Bulk Email. The hard part of it is not about the conTent of the email, it is the consent thing that is difficult.

      We have two conflicting goals with consent based systems:
      1> We want to recieve mails from some people we have not corresponded with.
      2> We do not want mail from some people we have not corresponded with.

      Being able to separate these two things is the hard part.

      Add to that the fact that email can go to different recipients on the same server who have different preferences, and we have big issues.

      --
      I can throw myself at the ground, and miss.
    7. Re:Like the old saying goes....(sorta) by danila · · Score: 1

      Of course, there is some spam, about which you can be quite confident that it's spam, but in some cases there is no clear distinction between spam and legitimate e-mail (on the recipient's side).

      Consider an advert for a seminar on logistics. If I receive it from the spammer, it's spam, if I get the same message forwarded to me by a colleague, it's less so. If we change the topic of the seminar to be more/less interesting to me, the message will become less/more spammy.

      You can't have a filter be 100% reliable in telling spam, because I can't be 100% reliable myself. Sometimes I am not sure whether I should flag the message as spam in my e-mail client, because I actually wouldn't mind getting more unsolicited messages like it.

      Of course, the filters can do a passable job (they can even be better than humans), but you really can't program it perfectly.

      --
      Future Wiki -- If you don't think about the future, you cannot have one.
    8. Re:Like the old saying goes....(sorta) by leshert · · Score: 1

      Correct. The trick (as is often the case in software) is to include a human brain in the decision making, and then automate the drudgery.

      That's what the current crop of Bayesian classifiers do. That avenue will probably end up being the most fruitful in the long run.

  6. The Arms Race Goes On by DumbSwede · · Score: 5, Informative
    Just today I saw a new method in a ebay.com phishing scheme.

    The ebay.com link showed up at the bottom of the browser, but was replaced with some kind of javascript mouseon event. This is probably not new.

    Instead of random text to fool Bayesian filters, it had hidden recent news article summaries (bracketed by html comment tags) that would be similar to what you might post to a friend.

    Spam filters will probably be upgraded to catch this soon, but it was the first time I had seen it. And of course as mentioned in the article, the ebay specifics where obfuscated by html tags between letters.

    1. Re:The Arms Race Goes On by lakeland · · Score: 2, Interesting

      Yeah, that won't cause much problem for bayesian. Essentially your filter will learn that news goes from good to neutral, and that javascript mouseovers go from bad to terrible.

      However, this isn't what Joshua and the rest of MS are working on. His stuff is much more in the area of modifying SMTP so that untrusted clients have to perform some calculations before their email is accepted, or pay a few cents. My guess is it will fail since it doesn't account for zombie PCs but I'm sure he has something planned for them.

    2. Re:The Arms Race Goes On by enosys · · Score: 2, Informative

      I don't think you should be running Javascript in e-mail. I disable it. I even disable automatic loading of images so that someone can't automatically confirm my address if I view a message.

    3. Re:The Arms Race Goes On by tlhIngan · · Score: 1

      Instead of random text to fool Bayesian filters, it had hidden recent news article summaries (bracketed by html comment tags) that would be similar to what you might post to a friend.

      The simple solution is to have your baysian filter ignore comments. Thus the news article disappears, and any broken words get magically reformed into one word and evaluated as a whole. If your email program won't render it in the final output, neither should the filter. The majority of people's email clients out there will refuse to render comments, and since most people won't look to the HTML comments, well...

      (In fact, in the interest of size in emails, there is no reason for comments... ).

  7. Take a lesson by TrIp0d · · Score: 1, Interesting

    If Microsoft email clients had a "bounce" feature spam mail wouldn't be such a problem. Microsoft should take a lesson from KMail. Ha!

    1. Re:Take a lesson by AndroidCat · · Score: 4, Insightful

      I shudder to think on what you mean by a "bounce" feature. Most likely sending a "bounce" reply to the forged sender address? That's part of the problem, not the solution.

      --
      One line blog. I hear that they're called Twitters now.
    2. Re:Take a lesson by MillionthMonkey · · Score: 1

      And spammers could easily deduce from the timing which bounces were genuine and which were not. Assuming they'd even bother to purge nonworking addresses from their lists in the first place, when many of them don't even bother removing duplicates.

    3. Re:Take a lesson by Anonymous Coward · · Score: 0

      Yeah! How I wish I could bounce all mails from my g/f ;-)

  8. Great - that will validate emails for spammers by Anonymous Coward · · Score: 0

    Nothing like letting them keep their mailing lists up-to-date automatically.

    1. Re:Great - that will validate emails for spammers by Sonar · · Score: 2, Informative

      Maybe you didn't quite understand what I was talking about.

      This would be completely done server side. Just like when you sent an e-mail to a host, and you get returned mail because you somehow typed in the address improperly. There would be no difference between that message and one that was sent to a user and then flagged as spam. It would be impossible to tell the difference if the user was a valid address or not.

      Thats what I am getting at.

    2. Re:Great - that will validate emails for spammers by Joseph_Daniel_Zukige · · Score: 1

      In other words, provide a way for the mail browser (MUA) to tell the server to put the "return to sender -- no such address" label on it even though the mail arrived and was read far enough to see that it was spam.

      You also have to make sure the MUA knows not to retrieve images and other external references in that stupid html-mail junk. Otherwise, it's just like the confirm-on-open option.

      Why is it so many so-called business software engineers think that computer systems should take control of things away from people, and don't understand that SPAM is the result?

  9. to stop spam, by havaloc · · Score: 5, Insightful

    give spammers a 9 year prison sentence.

    1. Re:to stop spam, by Anonymous Coward · · Score: 0

      Yeah, and throwing drug dealers in jail has really made an impact in the war on drugs, too.

    2. Re:to stop spam, by Anonymous Coward · · Score: 0

      Yeah, and throwing drug dealers in jail has really made an impact in the war on drugs, too.

      You're right, putting all the drug dealers back on the street would be much better.

      With the same logic I can say Flu vaccinations have never had any impact on Influenza. People all over are out sick with it every year, therefore the vaccine must be just a hoax. Anywho, if they're drug-dealers, maybe 10 years of pound-me-in-the-ass prison is what they need.

    3. Re:to stop spam, by Anonymous Coward · · Score: 0

      Yes, because prison sentences have done such a great job of stopping all other forms of illegal money-making. I can't tell you how great it is to live in a world where robbery, fraud, and the black market don't exist.

      . . .

    4. Re:to stop spam, by Anonymous Coward · · Score: 1, Insightful

      This is you missing the point.

      He didn't say that drug dealers should be put back on the streets. He pointed out the fact that prison sentences have not stopped the crime in question. For that matter, they haven't stopped any type of crime. Therefore, there's no reason to believe they would stop spam as the original poster suggested. Reduce it, maybe. There's a big difference between reduced, and reduced to zero.

  10. coming up next by ch-chuck · · Score: 0

    Msft research tackles war and poverty.

    Technology merely enables ppl - whether they choose to do good or evil with it is beyond technology.

    --
    try { do() || do_not(); } catch (JediException err) { yoda(err); }
    1. Re:coming up next by Anonymous Coward · · Score: 0

      'people'. Were you molested by a Hawaiian as a child or something? Is that why you're so scared of vowels?

  11. Spam is easy to define. by John+Seminal · · Score: 1, Interesting
    Spam is like porn: hard to define but you know what it when you see it. That can be hard to program I would think. But, who knows.

    No, Spam is easy to define, it is any unwanted emails. Name elements that make spam:

    1) It is a form of communication
    2) The communication is unwanted
    3) The source of the communication is hidden
    4) In recieving the communication, you use your bandwith or incur a cost

    --

    Rosco: "If brains were gunpowder, Enos couldn't blow his nose."

    1. Re:Spam is easy to define. by ch-chuck · · Score: 5, Insightful

      1) It is a form of communication

      all email is communication

      2) The communication is unwanted

      "wanted" is a subjective property of the recipient - the computer has no programmable decision procedure for wantedness.

      3) The source of the communication is hidden

      There may be some system of authenticating sender ID, and will be as easy as getting ppl to use pk encryption.

      4) In recieving the communication, you use your bandwith or incur a cost

      again a property of all emaiil.

      --
      try { do() || do_not(); } catch (JediException err) { yoda(err); }
    2. Re:Spam is easy to define. by John+Seminal · · Score: 1
      It is not 4 different definitions of spam, it is 4 elements that make up a definition. If any 1 element is missing, then it would not be considered spam for purposes of law enforcement. What I am getting at is what are all the elements that make up spam, so that if any 1 element is missing, it is not a criminal offense.

      Spam is a form of communication. You can't have spam without some kind of communication (I would like a definition that inclused the telemarketers and all the shit I get in the mail). That is element 1. Spam is unwanted. It would not be spam to recieve something you requested. Spam comes from a hidden source, so you can't track who sent it. That would protect honest buisnesses from having their emails classified as spam. Maybe CompUSA sends me a 10% off coupon for a sale next month that I never asked for and did not want. But I know who they are, I have somewhere to complain, and if the abuse the emails, someone to sue. And the last part is you use your bandwith, or have some cost. Maybe another element of spam is one source sends out many copies of the same mail.

      --

      Rosco: "If brains were gunpowder, Enos couldn't blow his nose."

    3. Re:Spam is easy to define. by MrNonchalant · · Score: 1

      There may be some system of authenticating sender ID, and will be as easy as getting ppl to use pk encryption.

      You over-estimate the average computer user.

      If you're thinking of a transparent solution then you under-estimate how fragmented the e-mail client "industry" is.

    4. Re:Spam is easy to define. by Tim+C · · Score: 1

      I generally consider spam to be unsolicited commercial email:

      1) I didn't ask for it (unsolicited)
      2) it's advertising a product or service (commercial)
      3) I'll assume you know this one ;-)

      The problem with your definition, as others have pointed out, is that both 1) and 4) is true of *all* email, and so are redundant. 2) is highly subjective, and may apply to genuine email too - is a mail from say a slashdot user calling me nasty names for something I said here unwanted? Yes. Is it spam? Not by most people's definition - you *definitely* wouldn't want the guy facing fines or jail time for it, other than perhaps under an existing harrasment law or similar.

  12. How about a secure OS to get rid of zombies? by Anonymous Coward · · Score: 3, Insightful

    That'd probably be the best thing M$ could do to help reduce spam.

    1. Re:How about a secure OS to get rid of zombies? by Anonymous Coward · · Score: 0

      well they now have a reasonably secure OS which is used by zombies!

    2. Re:How about a secure OS to get rid of zombies? by drxray · · Score: 1

      Preventing outlook express from displaying html emails wouldn't hurt either - you couldn't use html tricks to fake your way past spam filters then.

      (yeah, pine user...)

      --
      Slashdot - Mutual Assured Discussion
    3. Re:How about a secure OS to get rid of zombies? by Tim+C · · Score: 1

      How does a secure OS prevent a user from installing a trojan that turns their machine into a spam zombie as well as telling them the weather forecast, or giving them a "cool" mouse cursor, or whatever?

      If I can install and run software, and that software can make network connections, my machine can be zombified, and there's nothing that MS can do about it (or any Linux distro, or anyone else producing an OS).

      Eliminate all the remote and local exploits, and you'll still be left with one - the user.

  13. Microsoft Research by panaceaa · · Score: 2, Funny

    So, does Microsoft Research plan on combating Spam with a Bob-like approach, or the more refined Clippy approach?

    Or are they going to come up with an entirely new file system to combat it, hype it up for every Windows release, but then delay its release a few more years?

    Oops, pardon me while I reminisce about all the great advances Microsoft Research has given me :).

    1. Re:Microsoft Research by AndroidCat · · Score: 1

      The refined Clippy approach will use an expert learning system and database to provide friendly personalized filtering.

      --
      One line blog. I hear that they're called Twitters now.
    2. Re:Microsoft Research by lakeland · · Score: 1

      MS research comes up with some very cool stuff. Virtually none of it makes its way into Microsoft's products, I have no idea why :(

    3. Re:Microsoft Research by Technician · · Score: 2, Funny

      or the more refined Clippy approach?


      Clippy "It looks like you are trying to send a lot of e-mail. Would you like to send the first one to 1lol56@aol.com?"

      Clippy "It looks like your return address is incorrect. Would you like me to fix it?

      --
      The truth shall set you free!
    4. Re:Microsoft Research by MLopat · · Score: 1

      Actually a great deal of it makes it into our products however it usually doesn't filter down for nearly 10 years. The database technology for example that was researched 10 years ago is now appearing in the next release of SQL Server 2005.

    5. Re:Microsoft Research by lakeland · · Score: 1

      Interesting, thanks :)

    6. Re:Microsoft Research by panaceaa · · Score: 1

      Clippy "It looks like your return address is incorrect. Would you like me to fix it?

      Shouldn't that be:

      Clippy "It looks like your return address is correct. Would you like me to mangle it?

      :)

  14. Microsoft Research? by datafr0g · · Score: 3, Funny

    Don't you mean, Microsoft Mergers & Acquisitions?

    --
    "Who says nothing is impossible? Some people do it every day!" - Alfred E. Neuman
    1. Re:Microsoft Research? by ajp · · Score: 1

      Microsoft spends more money on research than any other company in the industry. Even more than IBM which is a far bigger company than Microsoft.

      But wait, you ask, why hasn't Microsoft actually invented anything? It's simple: everything useful was invented back when Bell Labs was the dominant monopoly with the huge research budgets. And some more stuff (but not Unix!) was invented when IBM was the only choice. And Xerox Parc, of course, lasted just about until Canon and Ricoh started making good photocopiers.

      Research spending comes from them with money. Microsoft's got it. And Microsoft's actually doing research. Funny joke, though. I can hardly contain myself.

  15. SPAM is not different from the rest of publicity. by GNUALMAFUERTE · · Score: 0

    Publicity in general is each day more like SPAM.

    For example, i don't consider google's adsense SPAM. But, for example, the ANNOYING flash banners m$ pays EVERYWHERE to get their crap into your mind IS SPAM.

    With certain advertisement, you only here about a company once in a while. If a giant like m$ spends millions on publicity, and you just here about them ANYWHERE, all the time, regardless of how much you try to avoid them, then, that's SPAM too.

    Just think about this: Try to live an hour online whithout listening about micro$oft. It's just not possible.

    --
    WTF am I doing replying to an AC at 5 A.M on a Friday night?
  16. validating email addresses for more spam by John+Seminal · · Score: 3, Insightful
    Also, if you reply, the spammer will know your address is active and send more crap.

    I don't undertsand this. On one hand, you have the police saying they can't track spammers. Spammers use drones, they remain hidden, they hide their tracks. On the other hand, if you unsubscribe, they know your email is a real one, and you get more spam. That tells me whoever runs the unsubscribe service is in cahoots with the spammer and is just as guilty. They have to know where to send their lists? Just track them as part of the war on spam.

    --

    Rosco: "If brains were gunpowder, Enos couldn't blow his nose."

    1. Re:validating email addresses for more spam by anon+mouse-cow-aard · · Score: 3, Informative

      Your unsubscribe is executed on a bot (a captured machine) which the bad guys can look at, the after taking precautions not to be observed, and harvest what they want from it. The good guys, if they capture the machine will just get your address (if it isnt encrypted by the bad guys) and a machine that is acting funny (if they dont know how to knock to get into the bot-ware) Since logging cannot be trusted on a compromised machine, what they need is a non-compromised machine beside the compromised one (on the same segment) to watch the traffic go in and out... a honeypot. That is a lot of hard work.

    2. Re:validating email addresses for more spam by damiangerous · · Score: 1

      I don't see how those two "hands" are "the other" or even related. What do not being able to ascertain the physical identity of a spammer and responding to spam email validating your address as good have to do with one another?

    3. Re:validating email addresses for more spam by AvitarX · · Score: 2

      Maintaning these lists of active addresses sounds like more work then it is worth, what is their cost of sending to bogus and inactive addresses?

      Maintaning secret knock patterns and keeping track of which ones are where (if they are all the same it seams a honey pot would be a good investment to me).

      logging of requests for invisible .gifs that have a serial number may be worth it (co-host with fake credentials in random country, capture for a day, and move on with a new one), but maintaning a mail server with DNS records would seam to make the weak link the registrar and not a bot machine if they are using DNS addresses.

      I would think that they use security through transience and not through rigid security.

      --
      Wow, sent an e-mail as suggested when clicking on "use classic" banner, and got a fast response that addressed my msg
    4. Re:validating email addresses for more spam by anon+mouse-cow-aard · · Score: 1
      All valid email addresses with eight characters or less... letters+num+_+-+.+'' say 8**40... python says that that is: 1329227995784915872903807060280344576L addresses to check for each domain. Sending is cheap, but it isn't that cheap. They desperately need lists. They trade lists. There are probably spammers whose only trade is to build good lists, and sell them to other spammers who use them.

      While straight-forward knock sequences are pretty hard to figure out to begin with, somebody watching can see and do a replay. Unfortunately, replays can easily be defeated... knock patterns can be arbitrarily hard to figure out without requiring a db. What about a combination of the first two bytes of the IP address (likely to remain constant) as well as the time of day, acting as some sort of hashing function to pick the exact knock sequence. You don't need a huge table, just a good algorithm, and a salt that would be varied to taste.

      for a computer program to know what .gifs are invisible is a similar problem to detecting spam, but harder. Legitimate .gif's with numbers in them are pretty common, you're going to have a lot of chaff to wade through.

      People can just pay for domains with bogus contact data, using a stolen credit card or money order. Don't spam with that domain, make that a registrar for other domains. Think there might be some slimy registrars? That if all the slimy registrar does is register a domain that is just semi-fictious registrar. The semi-ficitious registrar processes domain requests really quickly. The spammers create domains (at a probably higher than normal costs) with these registrars, and change them frequently.

      One of the first things a hacker does when they take over a machine is to patch it to make sure no other hacker can take it away from him. There are continuous running battles between botnet controllers for bots. Hackers do try to be secure, they move on when they have to.

  17. Whoa, he's an expert? by Rick+Zeman · · Score: 2, Informative

    Also, Spam-Research is reporting the SplitFit Technique that Spammers are using to fool Yahoo! Mail SpamGuard."

    How much credence should we put into an analysis from a guy who goes to the spammer's web site to unsubscribe?

  18. Slashdot typos strick again! by VeryProfessional · · Score: 5, Informative

    I thought the name David Hackerman was a bit too good to be true, and it turns out it was. Following the link shows that his name is David Heckerman . Note to /. eds: please proofread your posts. It's not like they're very long...

    1. Re:Slashdot typos strick again! by Anonymous Coward · · Score: 0

      Note to /. eds: please proofread your posts. It's not like they're very long...

      You must be new here.

    2. Re:Slashdot typos strick again! by Deltaspectre · · Score: 0

      Hah, I knew someone would mention that, so I fired up my fingers to press CTRL+F :D

      --
      My UID is prime... is yours?
    3. Re:Slashdot typos strick again! by Anonymous Coward · · Score: 0

      Seriously, how insulting. I've worked with the guy, and first thing I think when I read that was "goddamn Slashdot" ...

    4. Re:Slashdot typos strick again! by Justin205 · · Score: 1

      Read the title of the parent...

      Slashdot typos strick again...

      And again...
      And again...
      And again...

      It's a curse!

      --
      "Your effort to remain what you are is what limits you."
  19. The easiest way to stop span. by Anonymous Coward · · Score: 0, Insightful

    ISP's just have to restrict the number of emails that each account can send in day. After all does John / Jane Doe need to send thousands of emails a day ?

    Robert

    1. Re:The easiest way to stop span. by FooAtWFU · · Score: 1, Insightful
      People don't send spam from their ISP's account. They send it straight through their computer. Now, you could put outbound filtering on port 25, and require everyone to send mail through the ISP's servers (with authenticated SMTP of some sort), though there will be some legitimate traffic surpressed if that happens...

      That'll trim spamming more than any 'message count'.

      --
      The World Wide Web is dying. Soon, we shall have only the Internet.
    2. Re:The easiest way to stop span. by game+kid · · Score: 1

      Stop span?

      Why would I want to stop the inline alternative to the harmful font tag?

      ...but yeah, definitely crimp those e-mails to realistic amounts. I for one would quickly welcome our spam-restricting ISP overlords.

      --
      You can hold down the "B" button for continuous firing.
    3. Re:The easiest way to stop span. by Technician · · Score: 2, Informative

      People don't send spam from their ISP's account.

      Very true. They use a botnet.

      They send it straight through their computer.

      Not they don't. It's the easy to be on a RBL.

      Now, you could put outbound filtering on port 25, and require everyone to send mail through the ISP's servers (with authenticated SMTP of some sort), though there will be some legitimate traffic surpressed if that happens...

      The botnet is used to send just a few e-mails from each bot. Get an unfiltered inbox. Check the multiple copies of SPAM you get from diffrent senders. Check the headers. Identical SPAM arriving from many domains typicaly hit my inbox within a half hour of each other. This is the teltale sign of a botnet sending SPAM.

      --
      The truth shall set you free!
    4. Re:The easiest way to stop span. by Anonymous Coward · · Score: 1, Informative

      Now, you could put outbound filtering on port 25, and require everyone to send mail through the ISP's servers (with authenticated SMTP of some sort), though there will be some legitimate traffic surpressed if that happens...

      Back in 1999 when I worked for a hosting provider, I hated that some ISPs were doing this. Having to explain to our users why exactly they couldn't use their own SMTP server (our servers) was a nightmare. It also sucked for me with my laptop; I could be home, where I had to use my ISPs server, or I could be at a hotel where I had to go change my settings to use my own (hosted) mail server.

      But, I've come to the conclusion that disallowing outbound port 25 traffic isn't such a bad thing. A zombie'd machine on a DSL or cable connection can be dangerous, and can go undetected for months sending spam... and though it's a minor inconvenience to me (since SBC started doing this recently), if it stops some of the spam I receive then I'm all for it.

      SBC seems to now require that I use their SMTP servers, but I can still specify my From:, Reply, and Return-Path addresses as I see fit -- so it really doesn't make a difference to me once it's been (re-)configured to use the appropriate SMTP server.

      Personally I'm a fan of SMTP-Auth, which I believe most (all?) clients support these days... but that still doesn't prevent worms/trojans from sending spam through the configured outbound server if the login info is accessible...

    5. Re:The easiest way to stop span. by The_Mr_Flibble · · Score: 1

      On our adsl connections we have a default port 25 blocking policy, however we will stop blocking port 25 for anyone that asks (and has a good reason ( a good enough reason is I am running my own mail server or I am using a different mailserver)). However we still have a couple of people that have port 25 open and still get hit by trojans and proxies. It now costs them £250 to have their connection turned back on everytime.

    6. Re:The easiest way to stop span. by benb · · Score: 1

      > you could put outbound filtering on port 25,
      > and require everyone to send mail through
      > the ISP's servers

      Just that you wouldn't be an ISP anymore. An Internet Service Provider is for me primarily an IP packet transporter. If they fail to deliver an arbitary or random set of packets, they fail to deliver on their primary purpose.

      Alternatively, call it censorship or whatever. In ayn case, I won't let myself be forced to use the ISP SMTP servers.

  20. Murder is the answer to everything by RotJ · · Score: 0, Troll

    If the people who click on and buy things through spam--and therefore making spam a profitable business--were all horrifically murdered somehow, that would solve the entire problem without the need of any of this technological muckery. The only technology you would need to develop is be some kind of device that can murder people cheaply and efficiently.

    1. Re:Murder is the answer to everything by Anonymous Coward · · Score: 0

      You mean a handgun? Like what the US is full of?

      Why doesn't everyone in the US just kill themselves, and we'll see how much of the spamming stops - based on the results we'll make our decision

    2. Re:Murder is the answer to everything by Anonymous Coward · · Score: 0

      I have a friend for you. RotJ, meet Zyklon B.

    3. Re:Murder is the answer to everything by Anonymous Coward · · Score: 0

      You're just tired of the US telling you what to do. Shut up, go back to stuffing that Big Mac in your face, and wait your turn. We can't invade everyone at once you know.

      We'll get to you soon enough.

  21. "SplitFit" by 1000101 · · Score: 2, Interesting
    From the SplitFit link...

    Dera Blcraays Mbmeer, Thsi eamil was stne by the Barclays serevr to vreify yuor emial adsserd. You mtsu competel thsi pssecor by ccilking on the likn bewol and entireng in the smlal wiodnw yoru Braclays Membership nrebmu, passcedo and meelbarom word. Tsih is doen for yruo proteoitcn - buacese semo of our mrebmes no lonegr haev assecc to theri emlia adserdses and we muts virefy it. To vyfire yruo eiaml arddess and accses yruo bnak anuocct , cilck on the lnik bolew:"

    That email is extremely difficult to filter out because the only 'real' words are no, of, our, and, etc. Simple words that occur so many times in legitimate emails that most spam filters practically ignore them. But I have to wonder.. who would actualy 'cilck on the lnik bolew' anyway? I hate to use the term 'you get what you deserve', but if you are naive enough to click the link, then the problem isn't your spam filter, it's you.

    1. Re:"SplitFit" by op12 · · Score: 1

      Doing some sort of dictionary word check could easily cause such an email to be flagged as spam. Just have a threshold for number of misspelled words for a legitimate email, and this email wouldn't get through.

    2. Re:"SplitFit" by Anonymous Coward · · Score: 0

      Just have a threshold for number of misspelled words for a legitimate email, and this email wouldn't get through.

      Dood! That si so kewl. U R teh l33t.

      (Wait, I wouldn't want to see that email either. Nevermind.)

    3. Re:"SplitFit" by Spy+der+Mann · · Score: 3, Insightful

      You haven't RTFA it seems.

      That garbled text is ungarbled by certain software (i.e. outlook). That's because there are invisible chars in there that activate the "right to left" mode.

      Example:
      De*ra* B*lcra*ays M*bme*er
      translates to:
      Dear Barclays Member

      (I tried to copy the text I got in Yahoo, and paste it in MSN messenger. Amazingly, the text was "ungarbled". That's when I realized how tricky spammers were)

      SPAM software could simply detect left-to-right characters in such text, and ipso-facto label it as spam. Unless of course, you're reading hebrew. Which is obviously NOT the case.

  22. Hmm.. by Anonymous Coward · · Score: 0

    You know, sometimes in software industry, they are stuck with old code, and over the years they keep adding bug fixed and work arounds, to make it still usable, until at some point, the cost of keeping that code updated requires more effort than a complete rewrite of the software.

    All these bloated technologies like optical character recognition and flawed baysian and other content scanning techniques, just to keep a very simple and perhaps extremely outdated SMTP server operational, seems quite absurd in todays advanced technology world.

    I'm thinking we need to start introducing secure mail servers, linux based of course, which deal with trusted security certificates.

    Now I think that Thawty, Verisign and Microsoft, just like domain name registrars, are ripping us off our money for a few lines of text, but we need mail servers that have security certificates, so that only trusted mailservers can relay e-mail and all other sources are rejected.

    Or another white listing mechanism needs to be used. I really haven't thought about this much, but if we assume we get rid of Simple Mail Trasfer Protocol and turn it into a Highly Secure And Paranoid Mail Transfer Protocol of some kind, what would be the options?

    Currently whitelisting sources and using an automatically generated confirmation e-mail to the sender as a verification method, is I think the best, though not always user friendly, way to fight spam. Another way is a distributed spam fingerprinting like they exist.

    While I love to beat the shit out of spammers, because in today's world, nobody can spam without knowing they are pissing off the majority of the people, I think using legal means to fight technological flaws, including prosecution of hackers or other admirable technological curiosity, is the wrong way to go.

    Technical problems require technical solutions. And I'm sure we can come up with something better than SMTP.

    I'd like to see a technology that protects the privacy of the majority, but where the majority (not the govt) can reveal the identity of a spammer (by comparing distributed spam resources and using replacement for SMTP protocols) when the majority of the users think so.. a democratic way to public scrutany so to say, though there's a danger in that too. I trust linux users' healthy level of paranoia, but not that of windows users. :)

    Cheers

  23. Microsoft HATES Competition... by cdbaric · · Score: 0

    Lest we forget that Microsoft wants to control everything that appears on our desktops.

    Anybody remember Microsoft's 'Push Technology'?

    Neither do I.

    Bar

  24. bullets are cheap by Anonymous Coward · · Score: 0

    a couple of dead spammers and the problem will be radically reduced.

    especially if law enforcement decides not to waste resources investigating dead spammers.

    1. Re:bullets are cheap by Technician · · Score: 1

      a couple of dead spammers and the problem will be radically reduced.


      And a couple dead Joe Job'ed anti-spammers would get law enforcement heavly involved.

      --
      The truth shall set you free!
    2. Re:bullets are cheap by Anonymous Coward · · Score: 0

      Here's one I'd like to see taken out of business:

      MCG Titan,Inc.
      Christopher Cosie
      1094 greenbriar circle
      decatur, ga 30033
      US
      Phone: 404.292.4658
      Email: ccosie@yahoo.com

    3. Re:bullets are cheap by Technician · · Score: 1

      Here's one I'd like to see taken out of business:

      Is he a spammer, or someone you don't like and want to joe job? You were not specific in your post.

      --
      The truth shall set you free!
  25. Economic problem--NOT technical by shanen · · Score: 3, Insightful
    SMTP is working exactly as designed--but the design is broken. You can't fix a fundamentally economic problem with any number of technical tools. It's like adding more epicycles to the earth-centered "perfect spheres" models of the universe.

    The article barely mentions economics, and only in terms of the real costs of email--which only shows how much room there is for a real economic model with real business, real email, and *NO* spam.

    I really wish one of the major email players would offer an option for prepaid email. That would be an absolutely spam-proof system. It doesn't matter if the postage is two cents, the spammers can't afford it. Two cents against 50,000,000 spams turns out to be *REAL* money. Any email via that address would be at least some kind of real thing.

    --
    Freedom = (Meaningful - Coerced) Choice != (Speech | Beer^2), and sad sock puppets' bad mods avail them naught.
    1. Re:Economic problem--NOT technical by WolfWithoutAClause · · Score: 1
      SMTP is working exactly as designed--but the design is broken.

      I would agree with this, to an extent. If I can finger anything that is obviously broken in SMTP it is that it lacks verification of the sender domain (sender).

      That makes it way too easy to fake out who sent the email in the first place, hence phishing and faked email headers. It also makes it impossible to use reputation as a spam fighting tool- the spam currently appears to be coming from all over the place, whereas in reality only a tiny, tiny fraction of the internet is involved; and they need to be muzzled.

      You can't fix a fundamentally economic problem with any number of technical tools. It's like adding more epicycles to the earth-centered "perfect spheres" models of the universe.

      The 'nice' thing about computers is that they can handle thousands of epicycles. Merely throwing computers at something often works fine.

      In other words, I don't agree, and hold up naive Bayesian filtering as a pretty good temporary fix until we can finally nail the b******s inflicting this on us. Spam has no chance really, if the techies, and the ISPs, can finally get their act together on this. I see the light at the end of the tunnel. The war can be won.

      --

      -WolfWithoutAClause

      "Gravity is only a theory, not a fact!"
    2. Re:Economic problem--NOT technical by groomed · · Score: 1

      It doesn't matter if the postage is two cents, the spammers can't afford it. Two cents against 50,000,000 spams turns out to be *REAL* money.

      This doesn't seem to be a major issue for telemarketers and direct-mail advertisers. All it will do is make the spam glossier.

      Well, that's not entirely true. It will reduce the volume of spam. But in the process it will reduce the volume of email, period. It's a bit like fighting crime by decimating the population.

    3. Re:Economic problem--NOT technical by fmobus · · Score: 1

      I really wish one of the major email players would offer an option for prepaid email. That would be an absolutely spam-proof system. It doesn't matter if the postage is two cents, the spammers can't afford it. Two cents against 50,000,000 spams turns out to be *REAL* money. Any email via that address would be at least some kind of real thing.
      Hmm, so granma and Joe-six-pack will have to pay when they have their PCs zombied? Not a good idea. It would only work if someone we know patch their OS holes.

    4. Re:Economic problem--NOT technical by Anonymous Coward · · Score: 0

      I firmly believe that spam IS a technical problem. If I could verify the sender, I could stop receiving spam tomorrow. I can't do this because of a simple technical limitation.

    5. Re:Economic problem--NOT technical by thedustbustr · · Score: 1

      If some future SMTP replacement mandated authentication, spammers would simply spam from legitimate email addresses. No, it won't read support@wachovia.com, but spammers could easily register wachoivasecure.net and the likes. The targetted users are too uneducated to know the difference.

      --
      This sig is false.
    6. Re:Economic problem--NOT technical by Anonymous Coward · · Score: 0

      you are an ahole and a taxing commie. I pay enough taxes and I don't want to add a 2,3,,37,39 postage to every e-mail I send. I you are unemployable and want the gov taxes to support you, look for other way to tax. Actually, why don't you find some "real" work?
      BTW, did you post here using your company or government account? Do you work for IRS?

    7. Re:Economic problem--NOT technical by shanen · · Score: 1
      I really can't understand why it is so difficult to get this point accross:

      Email is *NOT* free. It has *NEVER* been free. SMTP email pretends to be free and there is no pretense of accounting. That is because the original design of SMTP was the fantasy of fairness and equality and all that wonderful stuff. As long as both of us send and receive about the same amount of email, we can cancel things out without worrying about the exact accounting.

      In reality, there are costs of email, and they are simply disguised and paid by all of us.

      The spammers are *NOT* playing by those rules. The spammers have noticed that there is no accounting in SMTP, so sending one real message is the same as sending 10 million spams. If you are dividing by zero, then any return on your "investment" looks like an infinite profit. Spammers think: "Another 50 million spams might get one more sucker for herbal viagra? Great!"

      You can escalate your Baysian adaptive filters out the wazoo, and as long as the spammers continue to fantasize about striking it rich, they will continue to devise new and despicable strategies to shove their garbage in your face.

      No one is telling you to abandon your free email. However, if the option existed for a completely spam-free email system, I would certainly want at least one such address, and I'm sure there are plenty of other people who would figure out a use for it. Obvious example is an address you could use on the newsgroups, and if someone really wants to email you for the post, they'd have to put up the two cents (or dime).

      --
      Freedom = (Meaningful - Coerced) Choice != (Speech | Beer^2), and sad sock puppets' bad mods avail them naught.
    8. Re:Economic problem--NOT technical by Captain+DaFt · · Score: 1

      You mean like this one?
      http://www.cashette.com/

      --
      The U.S. really needs an English to Wisdom dictionary.
    9. Re:Economic problem--NOT technical by Anonymous Coward · · Score: 0

      There is an excellent solution along these lines that doesn't even require us to work out a real, dollar-based payment system.

      Just add a step to SMTP that requires the sender to return the prime factors of a large random integer presented by the recipient before the email will be accepted. This costs the sender CPU cycles.

      As CPU technology advances, recipients could easily raise the "price" of email by increasing the length of the integers. Senders could also configure a maximum "price" they are willing to pay by specifying the largest integer they are willing to factorize.

      The beauty of this approach is that, while it has almost no impact on casual email senders, bulk email senders could easily be forced to purchase 1000x as many CPUs as they currently use.

      Legitimate bulk email (e.g. mailing lists) would still be possible if recipients are allowed to maintain a white list of senders who are not required to pay.

    10. Re:Economic problem--NOT technical by groomed · · Score: 1

      It's remarkable how you manage to write so many words yet not a single one of them seems to be in response to my comment.

    11. Re:Economic problem--NOT technical by dodobh · · Score: 1

      Who manages the payments? Also, spammers aren't sending spam from their own systems, the zombie PCs they control are.

      What happens when you get infected by a spamming virus/trojan, and you get billed thousands of dollars?

      BTW, we are speaking more emails per unit time than credit card transactions, so you need an incredible financial infrastructure to support this idea.

      This has been discussed so many times with the same old rebuttals and the same FUSSP still keeps popping up.

      --
      I can throw myself at the ground, and miss.
    12. Re:Economic problem--NOT technical by shanen · · Score: 1
      It was a collective response, and your comment was last. However, your comment itself was basically irrelevant and not worth more direct mention. Do you really insist on having your nose rubbed in the obvious?

      As you sort of noted, there is plenty of legitimate advertising, but it never has and never will reach the levels of email spam. My "best" spamtrap address gets 50/day now. In the real world of legitimate business, a certain amount of advertising helps, but if the advertising budget is wasted or misdirected, the company goes down the tubes. Of course it isn't an absolute guarantee, but you really can tell something about a legitimate company based on their advertising.

      This is not the economic model used by spammers. Spammers are *NOT* worried about repeat customers for their herbal viagra.

      Actually, the economic model I want is an auction. I would be willing to sell a certain amount of my time to advertisers. The well-run businesses are the ones that are going to be able to afford to do things properly, including directing their advertising money to the real customers. I'd be willing to cooperate.

      However, actually I would prefer to sit back out of the loop and let a commissioned middleman handle the bids for my time. For example, I might inform my middleman (a new kind of email service provider) that I'm looking for a new apartment in a certain area, and I'm willing to spend 15 minutes a day reading email from realtors. The middleman would aggregate my personal information and handle the bidding for that amount of email--and of course the middleman would also have a sincere interest in protecting my privacy. (If my personal information leaks, the middleman is out of the loop.)

      However, anything like this depends on getting a controllable *REAL* economic model wrapped around some part of the email system.

      --
      Freedom = (Meaningful - Coerced) Choice != (Speech | Beer^2), and sad sock puppets' bad mods avail them naught.
    13. Re:Economic problem--NOT technical by groomed · · Score: 1

      Despite ever increasing demand for bandwidth the cost of network traffic has only gone down over the past decade. There is nothing to suggest this trend will not continue into the foreseeable future. So in so far as spam is a real problem it doesn't seem to affect what is arguably the most important metric here, namely end user cost.

      From one kind of economic perspective, yes, it might make sense to differentiate between network services and users, and to mandate elaborate tariff structures, authorization mechanisms, etc. But it is just as likely to lead to the creation of cartels and innovative sclerosis: witness the slow uptake of multimedia services in the mobile phone market, which are widely recognized as too expensive and lacking in interoperability.

      The Internet is a dumb network which solves problems by brute force. It is exactly this property which caused it to win out over smarter networks such as Minitel or the various X.25 implementations. (a fairly comprehensive account of this development is given in the following web lecture by Paul Kunz)

      But since the Internet is dumb, there's nothing stopping you from offering a prepaid email service. If spam is really as big a problem as you make it out to be then people will flock to your service. But I don't think they will.

    14. Re:Economic problem--NOT technical by shanen · · Score: 1
      Natural solution is you have someone pay in advance--essentially a kind of bond posted by the sender or the senders mail provider. As postage is expended, it can't be reused (though incoming postage could be bartered against it for legitmate and balanced email users). That means that even if a spammer somehow manages to hack into someone's account, he would only be able to send a small amount of spam.

      Zombie PCs are no problem, since they won't have any postage to play with. If a zombie sends to a address that requires postage, it just bounces, which is basically the same as now happens with the invalid addresses in the spammers mail boxes.

      --
      Freedom = (Meaningful - Coerced) Choice != (Speech | Beer^2), and sad sock puppets' bad mods avail them naught.
    15. Re:Economic problem--NOT technical by shanen · · Score: 1
      I don't think they have to flock to make it a success. Actually, in a funny way, it's almost the inverse of the spam problem. If only a very small percentage of email users wanted to opt into this system, it would already be a LOT of people, and I think the percentage of people who hate spam a lot or who just need a truly non-spammable email address is much more than a small percentage.

      Unfortunately, there is something keeping me from offering it myself--my career and the company policy against moonlighting. That's the problem with working for big companies... They mostly aren't going to change the world, since they mostly like it the way it is.

      --
      Freedom = (Meaningful - Coerced) Choice != (Speech | Beer^2), and sad sock puppets' bad mods avail them naught.
    16. Re:Economic problem--NOT technical by WolfWithoutAClause · · Score: 1
      They are, but the ISPs can correlate spam against addresses and can unilaterally block it- as far as ISPs are concerned, spam costs them money; the spammers aren't paying them to carry spam.

      It's going to be much, much harder for the spammers to get legitimate addresses, even if they buy/own domains; ISPs can be blocking new domains within minutes.

      --

      -WolfWithoutAClause

      "Gravity is only a theory, not a fact!"
    17. Re:Economic problem--NOT technical by Anonymous Coward · · Score: 0

      Why is this modded as insightful? The parent is clearly talking out of his ass.

      Zombied PC's hello?

      The ONLY way to solve the spam problem is to go with authenticated sendmail and increased antivirus protection / security awareness of end users.

      You've obviously never worked in any form of ISP or had experience with the Abuse department if you had..

      Detecting and blocking spam coming from a single sender is pretty trivial and easy.. identifying and blocking it from a ton of compromised home users PC's is a much bigger problem.

      Authenticated mail is a good solution as it (but it requires all the major ISP's to get on board with it and reconfigure all of their users)
      The greater issue is it still doesn't stop someone from hacking the average joe's box and using the saved password in their outlook client/(insert mail client here) to send the mail.

    18. Re:Economic problem--NOT technical by shanen · · Score: 1
      Actually, I was rather shocked to discover this is not true for the portable phones in Japan--at least for KDDI. You pay for all the packets you receive, including the packets of spam email. I was so astounded by this, that I actually called them to doublecheck, and asked them what if my address is harvested, for example by some clumsy friend who clicks on a Beagle variant, and I suddenly get 100 spams. (Actually, one of the first times I got 700, but I think there were probably several sources.) They didn't put it in these terms, but the basic response was "tough titties--you pay for the spam we deliver to you and we profit from it". It annoyed me so much as to contribute greatly to my decision to cancel that service.

      In situations like this, a prepaid email system makes absolute sense, and I certainly would enable it if they offered the option. Unfortunately, the market in Japan is controlled by a few companies, and (in the usual Japanese tradition) would never dream of offering any new an innovative service unless everyone (including their competitors) is willing to go along.

      By the way, they do offer an unlimited packet service, but at a price I regard as very unreasonable, and nor really unlimited either, but only for certain phone-specific services. If anyone actually does sign up and use those services while staring at that tiny screen, I'm expecting them to go blind.

      --
      Freedom = (Meaningful - Coerced) Choice != (Speech | Beer^2), and sad sock puppets' bad mods avail them naught.
    19. Re:Economic problem--NOT technical by shanen · · Score: 1
      I think you're reply should be modded up to informative. This http://www.cashette.com looks to be almost exactly what I've been looking for. Kind of a primitive implementation, but they're starting in the right place. They should clean up their registration form some, and it doesn't run perfectly in Opera, but looks good.

      Main concern so far is the use of a whitelist. The spammers have an obvious countermeasure against that by linking addresses to make sure your spam seems to come from a friend. However, my intended use is not for my friends, so I won't need any whitelist on the account.

      --
      Freedom = (Meaningful - Coerced) Choice != (Speech | Beer^2), and sad sock puppets' bad mods avail them naught.
    20. Re:Economic problem--NOT technical by shanen · · Score: 1
      Gee, do you want to be admired for your ad-hominemo delusions.

      Actually, I worked for several ISPs over the years, mostly doing technical support, but for one period I was the postmaster of one of the largest free email systems in a very large city. That was actually in the transitional days when PPP service was young, but a system with 12 phone lines (or maybe it was 16?) was heavy duty. It was actually a bizarre proprietary system, but my Windows PC ran a conversion program pulling it out of the Novell network, converted it from and to SMTP, which I then sent out through one of our Suns using regular TCP/IP. I don't think the network support guy every believed the system could work... Spam was already there, of course, though nothing compared to the current floods.

      As you noted in your continued delusions, authenticated email has the well known and basically fatal problem of requiring everyone to go along, but I've already addressed that issue and the zombie stuff elsewhere. Hopefully, the entire issue is moot, since it certainly looks like this system at www.cashette.com may be just what the anti-spam doctor ordered.

      --
      Freedom = (Meaningful - Coerced) Choice != (Speech | Beer^2), and sad sock puppets' bad mods avail them naught.
    21. Re:Economic problem--NOT technical by davaguco · · Score: 1

      There is an easy fix to this. It is not my idea, I read it somewhere else: There will be 2 kinds of e-mail accounts: The "free" accounts and the "protected" accounts. The free accounts work exactly as the current e-mail accounts work today. For the protected accounts, however, you have to pay a small fee for every e-mail that you send through your ISP (like a stamp). HOWEVER this fee will be fully refundable, in 3 months, if nobody tells your ISP that you are a spammer. Thus, every e-mail stamp price that you pay will be returned to you as long as nobody tells your ISP that you are sending spam. There must also be a reasonabe limit to the maximum amount of "protected" e-mails that any computer can send, so that no zombie PCs ruin their owner. Also, anybody running a "protected" account can choose to only receive e-mails from other "protected" accounts.

      --
      Please google and research "peak oil" a bit. You will discover this crisis is a lot worse than they have told you
    22. Re:Economic problem--NOT technical by dodobh · · Score: 1

      Zombie PCs are no problem, since they won't have any postage to play with.

      Zombie PCs are PCs owned by normal users, but with spammers controlling them. If you have e-postage, and your PC is taken over, the spammer now has your money.

      --
      I can throw myself at the ground, and miss.
    23. Re:Economic problem--NOT technical by shanen · · Score: 1
      Depends on how the postage email system is handled. It's possible the zombie PC will have direct access to a small amount of postage--but that doesn't do much for the spammer. Remember the spammer needs to send millions, not tens.

      However, it's more likely the spammer gets nothing so far. For example, one natural implementation would be via a Web-based implementation where the actual postage is on a remote server. Okay, so now we've added another two or three levels of security and the spammer has to add a keyboard logger and try to sniff out the right password and figure out how to log into some other system without getting logged. I admit there's no such thing as perfect security--but in this case we're already way past the point of diminishing returns. For all his effort, the spammer finally captures your postage--and maybe can send a few spam messages until your current postage is used up. This sort of nickel and diming is *NOT* helpful from the spammer's perspective.

      Remember, the spammer always wants to send millions, not tens. Even trying to account for stolen postage is going to make the system totally unwieldy and useless from the spammer's perspective, so he'll go after the "soft" no-postage targets.

      --
      Freedom = (Meaningful - Coerced) Choice != (Speech | Beer^2), and sad sock puppets' bad mods avail them naught.
  26. As if one ISR-prone thread wasn't enough... by LokieLizzy · · Score: 0
    In Soviet Russia, Spam stops YOU!

    Sorry. I couldn't help myself :^(

    --
    My digital rights don't need management.
  27. my solution by ricochet81 · · Score: 2, Interesting

    Here's my solution to the greater unwanted communication Anti-spam paper submitted to Conference on Email and Anti-Spam

    --
    Error: Id10t detected
    1. Re:my solution by Anonymous Coward · · Score: 0

      Are the freaking moderators on crack?

      First of all this is a terribly written technical paper. What's with all these "theory" vs "implementation" sections!? I can't take any paper seriously that has an abstract with the sentence "...technology-specific implementations of the messages, task standards to define general needs, task detail standards to define task details, task implementation standards to merge tasks, task detail and the specific technology implementation and finally task implementors that implement task implementation standards and provide the functionality of this framework to a messaging system."

      Please tell me this paper is a joke? Surely no normal person would actually write "task implementors that implement task implementation standards"?

      Anyway you're not solving the problem. You're still sending requests to send email; these requests require just as much attention as email itself currently requires. What's the difference if the thing you're attending to is email or a request to send email? It's like the town that has a shortage of water but plenty of salt, so they decide to start calling salt "water", and start calling water "salt". Now they have plenty of water! But a terrible salt shortage.

      Either way, you're proposing the same old solutions of whitelists, blacklists, etc.

      Take a gander at potential signs you're an anti-spam kook. You've hit most of those points. Congrats.

    2. Re:my solution by maxjenius22 · · Score: 1

      A conference paper with no references? Nice.

  28. Or perhaps... by Canberra+Bob · · Score: 2, Funny

    Each year they will announce that This is the Year of No More Spam on the Desktop (of course this never happens).

    Or they will invent a brilliant new way to stop spam but as it requires the user to recompile all their OS and apps every 3 days it never gets used.

    Or they just tell the end users "Why dont YOU code some anti-spam software?"

    Or they produce an anti-spam system but the user must install 3 desktops and window managers, requires a 10,000 line config file that must be written by hand, comes with either missing or misleading documentation depending on the version you download and randomly purges any non-free software from the hard drive.

    1. Re:Or perhaps... by Anonymous Coward · · Score: 0

      Just out of curiousity, when did this happen to you? I know I've never had any non-free software purged from my hard drive. Hell! I've had Windows installed alongside Linux, and never had it "purged". So, again, if this has happened to you, please relate the experience, because I'd love to know about this.

      Sincerely,
      A. Coward

    2. Re:Or perhaps... by cgenman · · Score: 1

      Ballmer keeps running around insisting everyone call it GNUNWNTD/Spam.

      Their Anti Spam system will reduce your Total Cost of E-mail. Or raise it a little. Or possibly keep it the same.

      Their (K)illSpam system will be promply forked into five apps known as GnoMoreSpam, OpenSP, Xithergy, WAGIJIG, and Betty.

      It will accept, filter, parse, and sort incoming mail, while additionally precaching any keywords you are likely to look up on google, but it will take twenty minutes to open an ASCII based letter.
      It will use the function keys for essential behaviors that aren't documented anywhere.

  29. To stop spam, stop the money laundering by Animats · · Score: 5, Interesting
    A spammer needs certain resources to survive. Most spam control effort focus on cutting off the spammer's ability to send spam. Much has been done in that direction. Now more effort needs to be applied to the other direction - cutting off the spammer's payment stream.

    Legally, this is promising. First, there's no free speech issue. Second, in most jurisdictions, it's illegal to operate an anonymous business. So most spammers are criminals. Third, laundering transactions through intermediaries is usually a crime, too.

    The problem for law enforcement is that following the money is difficult. Additional technical support for that would be a big help.

    A good starting point would be to get a credit card issuing bank to cooperate in a scheme where, when one of their credit cards is used, full transaction details, including the payee's full identity, are immediately returned to the cardholder, using encrypted E-mail or some other secure means. That would make "following the money" much easier. This only requires one cooperating bank. That bank's credit cards might become popular with heavy Internet users. Especially if this works for prepaid credit cards, so you can find out who's behind a web site by using some disposable credit card.

    The next step is to crack down on "credit card intermediaries". Non-bank credit card intermediaries that handle spammer transactions should be stuck with the legal liability of the spammer. Legally, they're the "merchant". They shouldn't be allowed to pass the buck to some other party. This will make "cheap merchant accounts" harder to get, which is probably a good thing.

    1. Re:To stop spam, stop the money laundering by krishn_dev · · Score: 0
      Now more effort needs to be applied to the other direction - cutting off the spammer's payment stream.

      ROFL....man which world u r from.

      More than 60% spam i have received have been talking about fixin credit card, or fixin bad credit, auto loan and tons of finance related stuff. A big proof that they are funding spamming big way.



      Death, Taxes and Spam are unavoidable..:-D

    2. Re:To stop spam, stop the money laundering by killjoe · · Score: 3, Insightful

      In the past the FBI has already caught people by simply buying what they were selling and then finding the person who cached the check.

      Of course the FBI can't arrest people in the lawless places of the world like croatia and hungry so those government will need to shed their corruption.

      In other words I don't think your scheme will work because so much of the world is out of the reach of law enforcement.

      --
      evil is as evil does
    3. Re:To stop spam, stop the money laundering by Animats · · Score: 1
      It's "Hungary". Which is actually doing rather well since they got out of the Soviet sphere of influence.

      Speeding up the disclosure of the identity of credit card merchants from 30 days to two minutes makes finding them much easier.

    4. Re:To stop spam, stop the money laundering by davids-world.com · · Score: 1

      It seems to me that D.C. scores high on the list of lawless places, no need to go to Hungary, which has joined the European Union recently.

    5. Re:To stop spam, stop the money laundering by killjoe · · Score: 1

      " It's "Hungary". Which is actually doing rather well since they got out of the Soviet sphere of influence."

      Apparently those that are launching a relentless stream of spam and hack attacks on my firewall from "Hungary" haven't gotten the message yet. From what I hear spam and hacking are the least of it.

      --
      evil is as evil does
    6. Re:To stop spam, stop the money laundering by Big+Mark · · Score: 1

      Yeah, they do have more Nobel prize winners per capita than any other nation. Dismissing them as some Communist backwater is a gross underestimation.

    7. Re:To stop spam, stop the money laundering by pyrotic · · Score: 1

      About 25% of spam I get is for US re-mortgages (and I'm not in the US). Never mind tracking the spammers, there must be serious institutional capital backing for those schemes, if the US government financial services regulator is incapable of tracing several hundred thousand dollar transactions, heck, they ain't doing their job properly. Is there even an equivalent to the FSA regulator in the US? These mortgage spams only ever seem to come out of the US.

    8. Re:To stop spam, stop the money laundering by pyrotic · · Score: 1

      And while I'm on the subject of financial regulation, how come I keep getting all these NASDAQ related penny stock spams? If a company spams to boost it's own share price, it really shouldn't be trading on a public exchange. As far as enforcement goes, there is the problem of identifying joe-jobs, but it's not impossible.

    9. Re:To stop spam, stop the money laundering by bluGill · · Score: 1

      In many cases it is not the penny stock company itself that is spamming, nor their backers. Instead it is some "broker" who is manipulating the stock for this own gain, often against the interests of the company or the officers.

      Penny stocks are fairly easy to manipulate, and they can claim in court that they did their research and thought it would be good, pointing out they they did get all the reports they could get, often calling the management. (In some cases they will find a legitimate firm with a similar name so they can claim confusion) Then they tell the court they got lucky that some scammer decided to push the stock up just afterwords, and at the new price it was worth selling.

      Note that in some cases penny stocks are for companies that have for all practical purposes stopped operating. The owner (often it was a small business trying to make money, but they ran out of money before producing anything promissing, and lost interest) just hasn't filed the paperwork to declare the company non-existant, so the stock still exists even though you cannot contact them.

      Its not just that there is a problem identifying joe-jobs, it is that in most cases it is a joe-job, and the allibis are good. Still, the SEC does investigate these as best they can.

    10. Re:To stop spam, stop the money laundering by pyrotic · · Score: 1

      Some good points, but why are we not seeing mass prosecutions on this? During the dot-com boom Meryl Lynch (UK) brokers got into shit with regulators for knowlingly advising the public to buy shares that their own analysts and pension fund managers were dumping. They were caught because there was an audit trail on the sales. Correlating "anonymous" spam emails gathered via honeynets with price movements and institutional selling should not be rocket science, the sums of money involved are not trivial, but I've yet to hear of any prosecutions for securities fraud by this method.

      Again, we're only seeing US spam on this, and while the US market has the greatest liquidity, all other factors being equal you should also see this kind of spam on other markets. This suggests that either US investors are guilable fools, or the SEC is not doing it's job.

    11. Re:To stop spam, stop the money laundering by bluGill · · Score: 1

      In the case of a true penny stock mass amounts of money do not need to be moved. 1000 shares trading in a day is an unheard of large number, and since we are talking less that $5/share, and often just a few pennies, the average person can manipulate prices! Of course you can't make enough from one manipulation to live, but if you do several at a time you can make money.

      I agree the SEC should do more, but it isn't as easy as you would think to find these people.

  30. A penny an email will keep the Spammer Away by raga+muffin+disco · · Score: 0, Flamebait

    A very simple way to stop spam would be to charge someone a small amount of money for example a penny for every email that is sent. That amount will go to the person who is receiving the email. Thus for every email that you send you need to pay a penny and for every email you receive you get a penny. Thus the total cost of sending an email will be zero if whoever you wrote to writes back to you. This will even out the cost of sending and receiving emails. The only person who this would hurt is the spammers who send out millions of emails to total strangers who most often just delete the junk that they receive. So this solution is good for people who use emails for legitimate reasons. Heck this way spammers can send me all the emails that they want, I will just be making money off of them.

    1. Re:A penny an email will keep the Spammer Away by Anonymous Coward · · Score: 0

      Then spammers would just spam themselves from public STMP servers.

    2. Re:A penny an email will keep the Spammer Away by TummyX · · Score: 1

      Perhaps you should RTFA

    3. Re:A penny an email will keep the Spammer Away by Technician · · Score: 1

      A very simple way to stop spam would be to charge someone a small amount of money for example a penny for every email that is sent. That amount will go to the person who is receiving the email. Thus for every email that you send you need to pay a penny and for every email you receive you get a penny. Thus the total cost of sending an email will be zero if whoever you wrote to writes back to you. This will even out the cost of sending and receiving emails. The only person who this would hurt is the spammers who send out millions of emails to total strangers who most often just delete the junk that they receive. So this solution is good for people who use emails for legitimate reasons. Heck this way spammers can send me all the emails that they want, I will just be making money off of them.


      It's a great idea until the e-mail is paid for by your stolen identity and banking information.
      These are criminals who don't give out their own iformation. They use someone else's identity to avoid lawsuits. Deflecting the mob to someone else is standard pratice.

      --
      The truth shall set you free!
    4. Re:A penny an email will keep the Spammer Away by polle404 · · Score: 0
      A penny an email?

      and who should pay for all the billions of daily transactions of pennies?
      I think you'll find it costs somewhat more than a penny to transfer a penny.

      --

      ~men are from earth. women are from earth. deal with it.~
  31. Hidden Markov Model by icejai · · Score: 2, Interesting

    Why not use a hidden markov model to filter spam that use random digits as filler?

    A very basic filter will work this way:

    Train a network of say, 30 to 40 units, with any english text. The training text doesn't just have to be limited to letters and numbers, it can include other ascii characters as well, because the hidden markov model will create distributions for them as well.

    Now, for each new email that comes in, grab random chunks of text (maybe random 30-character strings) and see how probable the text would be in this hidden markov model. If it turns out not very likely, then scrap it.

    Any thoughts?

    1. Re:Hidden Markov Model by mcc · · Score: 3, Insightful

      Right now spam is usually filtered using a brownian model. As a result, spammers have begun structuring their emails so as to target brownian models. How many spams have you gotten lately with the subject line ending in confiscate ok wallop yls oblivion?

      If we move to filtering spam using markov models, spammers will begin structuring their emails so as to target markov models. Look forward to all your spams ending in 500-word blocks of text from a copy of MegaHAL trained on old grandmothers' email boxes.

    2. Re:Hidden Markov Model by slazar · · Score: 1

      Oh those brownian filters! What, do they filter based on how motive the email's atoms are? This thread has so many incorrect and brainless comments!

    3. Re:Hidden Markov Model by TheBackBencher · · Score: 1

      I actually wrote a paper on using Markov Random Field Model for spam filtering. its here: http://it.slashdot.org/article.pl?sid=05/04/12/014 4245&tid=111&tid=95&tid=218

      --
      www.cs.ucr.edu/~schhabra www.spam-research.com
    4. Re:Hidden Markov Model by Keeper · · Score: 1

      Look forward to all your spams ending in 500-word blocks of text from a copy of MegaHAL trained on old grandmothers' email boxes

      Some spam is already including the text of random news articles to defeat filters...

  32. Ugh by Mr.+Underbridge · · Score: 3, Insightful
    Legislate against spam. As long as spam is legal, or the penalties against it are too low, or it is too easy to do, people will continue to try and make a quick buck.

    First, I guess you didn't see the guy in VA who just got something like 9 years in jail.

    That said, spam doesn't obey jurisdictional boundaries. Any single country can only solve a small part of the problem, and any spam incident often involves over 3 jusrisdictions that may be in separate countries (sender, spambot, recipient, etc). That's a logistical nightmare that isn't soluble outside of a dream world.

    Also, force all ISP's to monitor how much bandwith a source has. If you get too much usage per day, say 200 megabytes or more, then that person has to explain why they need that much bandwith. If someone gets the RIAA on board, with their lobbyists, that should pass very quickly.

    That's fantastic. Trade a bad problem for one that's much worse. Get the RIAA to legitimize their practices by using a guise of stopping spam? Let's not.

    Also, force all email to have some element which identifies the source. Not just a header that can be forged, but something that can't be hacked.

    Now by force, what do you do if they don't? Enforement issues again here.

    Ultimately, legislative solutions for spam DO NOT and CAN NOT work for much but a small part of the problem. It's satistfying when some moron is clumsy enough to get caught (as with the guy in VA), but mostly these days the spammers aren't that stupid. Technological solutions work far better.

    1. Re:Ugh by Anonymous Coward · · Score: 0
      Grandparent: force all email to have some element which identifies the source. Not just a header that can be forged, but something that can't be hacked.

      Parent: Now by force, what do you do if they don't? Enforement issues again here.

      No, all routers in the USA can be forced to reject all email, unless it comes on a specific port, with specific identifiers. For example, maybe have a ISP program that you must instal on your machine that identifies your email. If the hash made by that program is wrong, they drop the email. Like what microsoft does when you try and instal software, you have to validate that you own the software and it is running on one machine.

      Or government can step in, and force all new computers to have a chip that identifies the machine. After a period of 2 or 3 years, phase in a law that says any internet communication is only alowed if that chip is working and sending information identifying you. Something like the MAC address on your NIC, but something that can't be forged at the OS level.

    2. Re:Ugh by Mr.+Underbridge · · Score: 2, Insightful
      No, all routers in the USA can be forced to reject all email, unless it comes on a specific port, with specific identifiers. For example, maybe have a ISP program that you must instal on your machine that identifies your email. If the hash made by that program is wrong, they drop the email. Like what microsoft does when you try and instal software, you have to validate that you own the software and it is running on one machine.

      None of those "let's redefine the SMTP standard" crackpot schemes are going to work. Remember, any solution has to be implementable for a billion internet users, and none of those hash schemes are. When the cost of implementation is higher than the cost of spam, the solution becomes a problem.

    3. Re:Ugh by mcc · · Score: 1

      That said, spam doesn't obey jurisdictional boundaries. Any single country can only solve a small part of the problem, and any spam incident often involves over 3 jusrisdictions that may be in separate countries (sender, spambot, recipient, etc). That's a logistical nightmare that isn't soluble outside of a dream world.

      The convenient thing here is that jurisdictional boundaries are often accompanied by physical boundaries, such as the atlantic ocean. There is a known number of internet links into the United States. If we can use legislative means to ensure that spam originates outside the U.S., that has the potential to make technical solutions to the spam problem vastly easier.

      Spam is not a technological problem. It is a commercial problem taking advantage of imperfection in technology. You probably can't solve the spam problem through purely technical means, since supply and demand-- the thing that's actually driving spam-- has shown itself adept at surmounting technical barriers. You can, however, if you target spam's commercial nature, make relatively sure at least that at no point does their cashflow come from within the U.S..

    4. Re:Ugh by nonicenamesleft · · Score: 1
      First, I guess you didn't see the guy in VA who just got something like 9 years in jail

      From http://www.azcentral.com/news/articles/0408spamsen tence-ON.html
      "Jaynes was prosecuted not for pumping out e-mail in bulk, but for falsifying information used to route the messages."

    5. Re:Ugh by Mr.+Underbridge · · Score: 1
      The convenient thing here is that jurisdictional boundaries are often accompanied by physical boundaries, such as the atlantic ocean. There is a known number of internet links into the United States. If we can use legislative means to ensure that spam originates outside the U.S., that has the potential to make technical solutions to the spam problem vastly easier.

      Marginally if at all. What are you going to do, turn off the pacific rim (it would be nice, but not feasible)? It's also quite easy for foreigners, then, to hijack a spambot in the US. What do you do, bust the bot owner? Not likely, those sorts of actions would make the RIAA look warm and fuzzy.

      Spam is not a technological problem. It is a commercial problem taking advantage of imperfection in technology. You probably can't solve the spam problem through purely technical means, since supply and demand-- the thing that's actually driving spam-- has shown itself adept at surmounting technical barriers. You can, however, if you target spam's commercial nature, make relatively sure at least that at no point does their cashflow come from within the U.S..

      Sounds nice. How do you do that? How do you examine their cashflow if they're foreign? Subpoena? Not happening. That's where those jurisdictional boundaries get ugly. That's why internet gambling still works, because all these places are based in Aruba and the US has no way to shut them down, and no way to peek at their books to make sure Americans aren't patronizing them. If our government can't shut down internet gambling - and it would like to - the same techniques will also fail for spam.

      The problem is that when you reduce any of these non-technical spam solutions to actual details, they don't work. If the problem were so easy to solve, it would have BEEN solved.

  33. It willl never work by heybo · · Score: 1
    Do you really think a law will stop it? Laws aren't worth the paper they are written on if you don't have someone to enforce the laws! We have a law. Ever called the FTC to report a spammer? Ever tried to get the police to arrest a spammer? It doesn't work.

    Yes the ISP could monitor the bandwidth on port 25 or just block port 25 and people could still download ISO or large updates. This still wouldn't stop it. Why? What about servers in Russia or China. Do you think american laws have any effect on them? Have you ever tried to contact an admin in China? What a joke.

    Just who is going to charge this site for the spam? Even if you find the site how are you going to find the owner? All whois info on a site like this is a lie. ICANN will not drop a site for bad whois info.

    Talking aobut the ISP they are using, most use someone like UUNET or a 100 others that do not give two sh_ts what they are doing as long as they are paying the bills. There are ISPs out there that this is where thay make their money. What are you going to do about them?

    Why this is modded intresting I do not understand. It is obivous that you don't have to chase these kind of people for a living. None of your ideas will work.

    I wish they could....

    1. Re:It willl never work by Anonymous Coward · · Score: 0

      What about servers in Russia or China. Do you think american laws have any effect on them? Have you ever tried to contact an admin in China? What a joke.

      I used to work for a web hosting provider, and I currently sell shareware. When I find a site offering cracks or serials for my software, if the site is hosted in Russia or China I don't even bother emailing their provider. I've had some US- and Canadian-hosted sites shut down, but most everywhere else I get no response, so I don't even bother trying.

      With spam (when I worked for a host, and even recently just trying to curb my personal spam intake) I've gotten about the same results. Even many US-based companies simply ignore reports, with UUNet and Sprint among the worst (most spam-friendly) providers out there. Stricter laws *might* help somewhat with US-based companies, but other countries don't care; they're making profits from it themselves, and in many cases they don't care for us Americans much anyway.

      I've heard many proposed solutions to the spam problem over the years, and I don't think there's any one that is sufficient. Authentication means trusting some "authority" such as (for example) Verisign. Perhaps not the worst idea (SSL is realtively secure and trusted)...

      Pay-per-email won't work IMO. Who will keep track? Who will collect, and distribute, the money due? Who decides who gets charged and how is this authenticated? It'd have to be under the control of one single entity, which I do not like regardless of who that entity is.

      I'd almost rather deal with the spam problem than give up the freedom of a relatively open and accessible network that we enjoy now. Some will abuse it, of course, but if we could simply educate people to recognize spam (and thus refuse to do business with spammers) it would simply go away. Oddly it seems that the recent virus outbreaks may have helped, only because the "average" user is afraid to respond to any email message from an unfamiliar party...

      Ugh, I should be in bed...

    2. Re:It willl never work by CohibaVancouver · · Score: 1
      but if we could simply educate people to recognize spam (and thus refuse to do business with spammers) it would simply go away

      That's the only solution. In probably twenty years or so enough of the populace will realize what spam is and respond to it. But right now, with spammers able to make hundreds of thousands of dollars, the problem will persist.

  34. Solution or complication? by Gary+Destruction · · Score: 3, Insightful

    Is there really such a thing as a solution to spam? For every new technique that is developed, the spammers will find a way to circumvent it. Spam is a multi-million dollar business. I'd go so far as to say that it's a science. At least, the spammers seem to have it down to a science.

    Trying to find a solution to spam is an idea in the eyes of experts and analysts. But to spammers, it's a road block that they must work around to stay in business.
    Spamming techniques will no doubt end up as signatures in spam filters that are not unlike those signatures used by IDS and virus scanners. The experts don't seem to understand that if there's a will, there's a way. And the spam will just keep coming in another form or by some other technique. All that can be done is to keep up with changing techniques and patterns and treat spam for what is truly is -- an attack vector.

    1. Re:Solution or complication? by aXis100 · · Score: 1

      I agree. Stopping spam via code can and will be circumvented.

      We need to stop spam legally and politically. Instead of targeting the spammers, target the companies that utilise it. If it were illegal to advertise your product via spam, there would be no market for it. It cant really be circumvented - somehow there has to be a link to the product/company in the email.

    2. Re:Solution or complication? by TummyX · · Score: 1

      Perhaps you should RTFA.

      I like the computational problem solution. Most of us wouldn't mind if email took 5 seconds longer to send because the computer had to solve a computation challenge.

    3. Re:Solution or complication? by Anonymous Coward · · Score: 0

      Yes, and it's simple. Charge money for the time you spend reading emails. www.cruelmail.com

  35. Spellcheck by Anonymous Coward · · Score: 0

    How about taking the current spam fighting techniques and just adding some spellchecking? Too many mispelled or gibberish words/phrases - it is spam. For folks using IM, that think beeing 1337 is so cool, this might not work. But for unsolicited email it should work fine, shouldn't it?

    Here are the subject lines of the last couple of SPAM notes my daughter got:

    Re: VALLlUM C1ALlS VlAGRA

    use C0DE1NE, C1AAL1S, V1AAGRRA, V1C0DD1N, /ALLIU..

    profession Z0LOFT, C0DE1NE, V1AAGRRA, C1AAL1S, V..

    AAA replica LV Bags & Rolex Watches at good prices

    young /ALLIUM, V1C0DD1N, Z0LOFT, S0MMA, V1AAGRRA..

    These were all caught by comcast's built in filter, so she never actually received them, but since SPAM filters are so good now it is obvious that these louts are relying a lot more on misspelling to get through.

    1. Re:Spellcheck by maxjenius22 · · Score: 1

      I think SpamAssassin does this spellchecking thing already.

  36. briefly worked on contract for a spam company by Fox_1 · · Score: 3, Interesting

    Well they weren't really a spam company, they sold software that allowed you to generate spam messages. I was going to do some telephone sales for them, cold call their market (I know, it's evil but I was calling corporations, not individuals, and I needed some cash) but after I got a copy of their software and became familiar with it's capabilities I felt icky, like I stepped in something, I couldn't in good conscience work for them. It had been presented to me as a customer contact software package - but it had too many little sneaky features that marked it to me as spam software, (built in SMTP server, throttle control on smtp activity so your ISP didn't get mad at you, and a bunch of message generation/tracking options) or at least there was nothing stopping customers from using it in that way, no matter how the company described their product.

    --
    The rock, the vulture, and the chain
  37. Foolishness by Urusai · · Score: 0

    Any spam defense model that analyzes the text is doomed (until the advent of bona fide AI).

    Domain Keys is similar to an idea I had a while back for a trivial thesis topic (stupid prof dismissed it out of hand). I think authentication to remove the anonymity of spammers, combined with laws to regulate it, is the solution. Since any domain can serve up its own public keys, there is no need to have a centralized certification authority, either.

    1. Re:Foolishness by DNA+Beast · · Score: 1

      >> Any spam defense model that analyzes the text is doomed (until the advent of bona fide AI). Actually, when bona fide AI comes on the scene it's going to be nigh on impossible to filter spam. Do you have a friend who you've only ever met online? Would you trust their judgement if they told you where to buy online? Maybe the turing test should be changed. If a program can convince you to buy Viagra online, then it passes.

    2. Re:Foolishness by Anonymous Coward · · Score: 0

      Not necessarily. Take a good look at CRM114, at crm114.sourceforge.net. It's having very good results. It needs some work to make setting it up and integrating it into your mail client easier, but it's extremely effective at saying "I want this" versus "I don't want this", irrelevant of whether it's spam or anything else.

  38. hacker? by TLouden · · Score: 1

    hackerman or heckerman?
    I wish my last name was legally hacker. I'd change my first and middle to black and hat respectively.

    --
    -Tim Louden
  39. Re:SPAM is not different from the rest of publicit by datadriven · · Score: 1, Offtopic

    Try to live an hour online whithout listening about micro$oft. It's just not possible.

    Especially if you spend that hour on slashdot.
  40. What's so bad about spam in the first place? by ChuckSchwab · · Score: 2, Funny

    I see all this time and money being invested into research to block spam. But we need to rethink our premises: does spam even need to be blocked? Is it actually a problem?

    What you call "spam", I call "emails that help me learn about the latest products, websites, and business models". You want less of it? I want MORE of it. "Spam" keeps me informed about the world. And the fact is, consumers LIKE spam. Why do you think spam is profitable? Because people buy the products advertised! Studies show that 3 in 5 people who dislike "spam" have actually bought something online. So frankly, you need to be real careful about how you define "spam" because you could be targeting something you LIKE.

    1. Re:What's so bad about spam in the first place? by aXis100 · · Score: 1

      Just to feed the troll some more....

      How is it acceptable to be sitting at work and recieve pornographic SPAM selling sex sites, penis enlargement and viagra?

      You might want junk mail, but it seems that the majority of us dont.

    2. Re:What's so bad about spam in the first place? by ChuckSchwab · · Score: 1

      Feed the troll? I am not a troll, sir. But you know who is a troll? You, for calling me a troll. That is trolling. You just can't accept that I made a valid point, so you have to slander me.

    3. Re:What's so bad about spam in the first place? by Anonymous Coward · · Score: 0

      You insensitive clod! You might be sitting pretty with your large, functioning and oft-serviced penis, but what about the rest of us? Huh?

    4. Re:What's so bad about spam in the first place? by Technician · · Score: 1

      I shouldn't feed the troll, but....

      Studies show that 3 in 5 people who dislike "spam" have actually bought something online.

      I fit right into that catagory. I get lots of spam. I have bought something online. Is this related somehow? I dislike SPAM. I bought a game. The SPAM and the game purchase are unrelated. I have bought nothing from any e-mail I have ever received.

      I did a search to see who had the best deal on the game I wanted. I did not search my e-mail account for the information.

      Please reveal the source of your studies and provide some information how spam and online purchases are related. Is there a relationship to the number of people who dislike SPAM and have bought something from a SPAM e-mail?

      --
      The truth shall set you free!
    5. Re:What's so bad about spam in the first place? by ChuckSchwab · · Score: 1

      Source: Wall Street Journal

      Comment: Chill out dude. I was just saying that people who don't like spam are likely to buy things online. I NEVER said the things they bought online were based on spam emails. I was just showing the GENERAL contradiction in how people approach spam. Specifically, they hate online marketing, yet buy online.

    6. Re:What's so bad about spam in the first place? by Technician · · Score: 1

      Comment: Chill out dude. I was just saying that people who don't like spam are likely to buy things online.

      Thanks for the clarification. The original context tended to imply the online purchases were from SPAM e-mails. Thanks for the reply that not that many people have responded to SPAM.

      --
      The truth shall set you free!
  41. Ok not a problem spam just opens a million account by Anonymous Coward · · Score: 0

    or hacks users makes no difference to the spammer

  42. Microsft falls short... again by lpenz · · Score: 0, Troll

    As an evil company, they probably spam better than filter.

  43. Article covers more than stated here... by Anonymous Coward · · Score: 0

    That hypertextus interruptus technique is, in fact covered in the article (at least in the print edition - it may have been a sidebar that did not come through in the web page.)

    I'm always kind of surprised that no one mentions cloudmark Spamnet in any of these discussions - it's worked for me for years, and it takes advantage of that one remainging vulnerability of spam - you know it when you see it.

  44. Your silly troll by fmobus · · Score: 1

    Spam damages productivity, period. I, for one, don't want and don't need to know about "V14gra and C1Al15", can I shove it upon your ass?
    3 in 5 ppl who dislike "spam" have actually bought something online Hm... you mean, from the spammers? I guess not...

  45. Spamalot by Doc+Ruby · · Score: 1

    Doesn't Outlook let you filter for only messages that come from addresses in your contact list? That cuts down on most spam - even spoofed address spams don't usually target people in the address owner's contact list. They just harvest addresses from phishing or web pages, which doesn't access contact lists.

    The viral spams, where a virus reads a contact list and sends itself to the contacts from a familiar (and actual) address, are vulnerable to a server-based strategy. Servers could detect identical (or nearly) messages received by multiple recipients. Servers could check hashes of the messages with each other, to see if the duplicates are spread thinly across many servers. Then flag those messages as spam, or just "bulk mail", for client filters. Once a message was identified as spam, its hash (including a fuzzy hash) could immediately flag any matching message as flash.

    With Microsoft distributing so many email clients and servers (plus Hotmail), they could drastically cut spam with this simple comparison tech. The time they spend on these exotic research techs are really just a way to generate PR, fanning their image as "smart". I guess their PR delivers better ROI than their product development. And then there's the actual profits they make on spam. Maybe MS isn't so well positioned after all.

    --

    --
    make install -not war

    1. Re:Spamalot by fuzzyrabbit · · Score: 1

      The contact list scenario doesn't work if you are running a support email address for customers to obtain software support.

      Even if you hide the email address behind contact forms, you still get people who get trojans on their PC, which then run through their contact list, happily submitting our (up til then) unspammed email addresses to harvestors.

      I can't even give my email address to my friends or Grandma in case they get a trojan and spoil my clean email address. What is the world coming to :-(

      --
      Smoke me a kipper, I'll be back for breakfast... - AJ Rimmer
    2. Re:Spamalot by zappepcs · · Score: 1

      This server based rule does work, and well. It is used in several areas where I have some knowledge. When virus emails are running rampant, the servers are very effective at keeping lists of repetative email subject/content/sender and just pounding them into the round file.

      In a business, an e-mail arriving from outside the company domain and going to many inside recipients with questionable content, just kill it, all of 'it'.

      This can be done by ISP mail servers. And the parent is right here, if ISP's and e-mail client vendors simply worked together, it could be a totally opt-in service where questionable e-mails never make it out of the bulk-mail folder on the client. It doesn't require any major change other than ISP mail server/service changes and client software that can use the bulkmail flag/listing provided by the ISP or mail service provider.

      I would suggest that the F/OSS community can come up with an anti-spam usage for P2P networking with this... build a spam block list, share it out, the world starts getting less spam??????

    3. Re:Spamalot by Doc+Ruby · · Score: 1

      Spam is an intractable (NP-complete) problem, because spammers are at least as smart as spamees. But there are ways not to get buried in the arms race.

      The problem is divided in two: getting email from people with whom you have a relationship, and email from others with none. Forms are a way to protect you from "strangers" ("new friends"). Contact lists help ensure that people have a relationship with you. Your initial form, that replies by email, sends a unique code string ID, and requires that replies quote the original message. That keeps people who initiated replies "in the fold", and excludes trojans. Until someone writes a trojan that looks for unique codes. But there are simple ways to harness human intelligence against machine bulk mailers. Like including six codes, with a request to reply with only one, in slightly roundabout language. You filter out the ones with the wrong codes, and followup with people who have dropped the conversation because they mistakenly sent the wrong code. Add the server-comparison system I mentioned to discover bulk emails, and most spam is gone.

      These solutions are very productive, and don't require lots of R&D. And they don't really harm anything, so they're worth doing while they work. Which means they'll undermine spammers, by depriving them of revenue, while the law goes to work on stopping the spammer, instead of the spam. That's the best we can do. The perfect is the enemy of the merely good, when we insist on waiting for the perfect.

      --

      --
      make install -not war

    4. Re:Spamalot by Doc+Ruby · · Score: 0

      This is exactly the kind of feature where open source projects have the edge over Microsoft: interop without the corporate "spam profit" baggage. A victory here could push implementors to Apache-quality market dominance, with much better press for "beating spam while the corporations spin their wheels". If I weren't busy hitting all day, I'd start it. Anyone on an SMTP-ser project want some help?

      --

      --
      make install -not war

  46. Microsoft Research saves the day! by Anonymous Coward · · Score: 0

    Glorious! Microsoft Research turns their attention to Spam. Let's hope they're more successful than their research into preventing viruses, fireall penetrations, mail worms and mail attachments (hello Outlook).

  47. STOP FORWARDING! by Dark+Coder · · Score: 1

    The single MOST effective anti-spam is to stop supporting mobile IP and ".forward" mechanism.

    Once done, then ALL mail administrator can then implement DNS verification against the sender^H^H^H^H^H^Hspammer's IP address. If they don't match, NULL-BIT bucket it.

    Seems like a small price to pay for restoring normalcy (until the next SMTPv2 comes along).

    1. Re:STOP FORWARDING! by samjam · · Score: 1

      Seems like a funny kind of normalcy to me.

      Sam

  48. another patent grab? by pixel+fairy · · Score: 1

    just a wild guess...

    what happend with the senderid thing?

    of course they could see a buissiness problem if people stop wanting to use email, and thus thier exchange servers, or maybe even they are tired of it...

    but really, i smell another patent grab...

    1. Re:another patent grab? by Anonymous Coward · · Score: 0

      It sucked goat rocks. Patented and completely un-expandable protocol, incompatible with open source licenses, forciing SMTP servers to incorporate proprietary Microsoft XML parsers and forcing the recipients to receive the full message to parse the header for XML before blocking it, Microsoft would collect the fees and issue all the SenderID keys so spammers could simply steal the keys from zombied machines and use the relevant SenderID keys from inside local NAT's which breaks the IP address authentication of SenderID, and spammers could simply buy throwaway keys for $20/spam run, etc., etc.

      The original SPF idea that Microsoft tried to "embrace and extend" and take credit for by lying and calliing the SPF deployed base "SenderID" users, is still going merrily along at http://spf.pobox.com. That uses DNS TXT records to describe a list of hosts that are allowed to send mail from that domain: MX records, A records from that domain, maybe legitimate SPF authorized mail from another domain, etc.

      It's very lightweight and works quite well to reduce forgery, and helps force spam email to include legitimate header information so the sending site can be contacted and block the spam, and it really helps a lot to contain virus traffic from machines inside networks that shouldn't be directly sending email from that network. I highly recommend it.

  49. The HP Way by Anonymous Coward · · Score: 0
    "In 1978 the first spam e-mail--a plug from a marketing representative at Digital Equipment Corporation for the new Decsystem-20 computer--was dispatched to about 400 people on the Arpanet"

    Does this mean HP can take out patents on spam, and sue anyone who uses it without a license?

    The spam division could be bigger than the printer division... (Compaq bought DEC, HP bought Compaq.)

  50. Spam still an issue? by groomed · · Score: 2, Informative

    Between SpamAssassin, procmail, and MUA filtering rules, I rarely get to see spam anymore. The spam which does slip through is so absurd and surreal that it's more hilarious than annoying.

    If everybody did this, the volume of spam would quickly dry up. Because when people don't see the spam, they can't respond to it, and when they don't respond to it, the spammer doesn't have a business.

    Educate the people around you and help them reduce the spam that gets to their inbox. Don't support solutions which effectively render nodes at the network periphery to second-class status.

    1. Re:Spam still an issue? by Anonymous Coward · · Score: 0

      My ISP offers a (free) spamfilter that can be enabled by ticking a checkmark. They use SpamAssassin.
      It indeed works very well, about 100 spams discarded every day (they are moved in a temporary spambox that you can view via webmail).

      They don't want to enable this by default because of the false-positive risk, but I have never seen a false positive and rarely any false negatives.

      Indeed, if everyone would have this it would kill the spam at first. However, it would probably mean spammers would change tactics.
      What is really needed is some way to kill the zombie networks, and a more secure email network that provides unambiguous identification of the sender of every mail.

    2. Re:Spam still an issue? by dodobh · · Score: 1

      The traditional response of spammers to better filters has been to send more spam. A large portion of the cost of spam is in handling the traffic itself. Your solution does nothing to reduce that.

      --
      I can throw myself at the ground, and miss.
  51. Commitment by Deliveranc3 · · Score: 2, Interesting

    They blocked the block function for microsoft messages in hotmail.

  52. Microsoft already has a "spamming division" by Anonymous Coward · · Score: 1, Insightful

    ... it's called "HotMail"

    How else do you explain getting 50 pieces of junk mail a day even when you never use your account?

    1. Re:Microsoft already has a "spamming division" by Dave2+Wickham · · Score: 1

      The fact that hotmail is one of the most common providers of webmail out there and so spammers generate likely addresses for it to spam?

  53. Do you know what you're talking about? by Anonymous Coward · · Score: 0

    Have you ever thought about why these ads are legal and there nothing being doen to stop them? You should get yourself educated.

  54. the anti-spam "it won't work" checklist by bersl2 · · Score: 1

    I just got out of a six-hour meeting, so I'm a bit senseless. But I see no one has posted this yet, so:

    Your post advocates a

    (X) technical ( ) legislative ( ) market-based ( ) vigilante

    approach to fighting spam. Your idea will not work. Here is why it won't work. (One or more of the following may apply to your particular idea, and it may have other flaws which used to vary from state to state before a bad federal law was passed.)

    ( ) Spammers can easily use it to harvest email addresses
    ( ) Mailing lists and other legitimate email uses would be affected
    ( ) No one will be able to find the guy or collect the money
    ( ) It is defenseless against brute force attacks
    ( ) It will stop spam for two weeks and then we'll be stuck with it
    (X) Users of email will not put up with it
    ( ) Microsoft will not put up with it
    ( ) The police will not put up with it
    ( ) Requires too much cooperation from spammers
    (X) Requires immediate total cooperation from everybody at once
    (X) Many email users cannot afford to lose business or alienate potential employers
    ( ) Spammers don't care about invalid addresses in their lists
    ( ) Anyone could anonymously destroy anyone else's career or business

    Specifically, your plan fails to account for

    ( ) Laws expressly prohibiting it
    (X) Lack of centrally controlling authority for email
    ( ) Open relays in foreign countries
    ( ) Ease of searching tiny alphanumeric address space of all email addresses
    ( ) Asshats
    ( ) Jurisdictional problems
    ( ) Unpopularity of weird new taxes
    ( ) Public reluctance to accept weird new forms of money
    ( ) Huge existing software investment in SMTP
    ( ) Susceptibility of protocols other than SMTP to attack
    ( ) Willingness of users to install OS patches received by email
    ( ) Armies of worm riddled broadband-connected Windows boxes
    (X) Eternal arms race involved in all filtering approaches
    (X) Extreme profitability of spam
    ( ) Joe jobs and/or identity theft
    ( ) Technically illiterate politicians
    ( ) Extreme stupidity on the part of people who do business with spammers
    ( ) Dishonesty on the part of spammers themselves
    (X) Bandwidth costs that are unaffected by client filtering
    ( ) Outlook

    and the following philosophical objections may also apply:

    ( ) Ideas similar to yours are easy to come up with, yet none have ever
    been shown practical
    ( ) Any scheme based on opt-out is unacceptable
    ( ) SMTP headers should not be the subject of legislation
    ( ) Blacklists suck
    ( ) Whitelists suck
    ( ) We should be able to talk about Viagra without being censored
    ( ) Countermeasures should not involve wire fraud or credit card fraud
    ( ) Countermeasures should not involve sabotage of public networks
    ( ) Countermeasures must work if phased in gradually
    ( ) Sending email should be free
    ( ) Why should we have to trust you and your servers?
    (X) Incompatiblity with open source or open source licenses [hey, it's Microsoft... they've probably already submitted the patent...]
    ( ) Feel-good measures do nothing to solve the problem
    ( ) Temporary/one-time email addresses are cumbersome
    ( ) I don't want the government reading my email
    ( ) Killing them that way is not slow and painful enough

    Furthermore, this is what I think about you:

    (X) Sorry dude, but I don't think it would work.
    ( ) This is a stupid idea, and you're a stupid person for suggesting it.
    ( ) Nice try, assh0le! I'm going to find out where you live and burn your
    house down!

  55. MAD LIB on Troll post by Fox_1 · · Score: 1
    MAD LIB on Troll post
    Spam = killing babies

    see all this time and money being invested into research to block killing babies. But we need to rethink our premises: does killing babies even need to be blocked? Is it actually a problem?

    What you call "killing babies", I call "emails that help me learn about the latest products, websites, and business models". You want less of it? I want MORE of it. "killing babies" keeps me informed about the world. And the fact is, consumers LIKE killing babies. Why do you think killing babies is profitable? Because people buy the products advertised! Studies show that 3 in 5 people who dislike "killing babies" have actually bought something online. So frankly, you need to be real careful about how you define "killing babies" because you could be targeting something you LIKE.

    --
    The rock, the vulture, and the chain
  56. Solution: disable javascript by Anonymous Coward · · Score: 0

    Disabling javascript is the number one way to avoid phishing scams and annonying email/web browser behaviors. Just say no to bad technology!

  57. Something is suspicious here. by ciscoguy01 · · Score: 1

    This article in Scientific American says
    "The suffocating effect of spam sometimes seems likely to undermine, if not wreck, Internet communications as we have come to know them."
    Which seems to mean spam is getting to be MORE of a problem than in the past.
    But yesterday in /. there was another article about how spam was LESS of a problem for people than in the past.

    People are More Accepting of Spam
    http://it.slashdot.org/article.pl?sid=05/04/11/015 7208&tid=111

    So which is it?
    Personally I have MUCH MORE spam than I had a couple of years ago.
    It is handled marginally better but THERE IS LOTS MORE.
    For me Spam is much more of a problem than at any time in the past.
    And yeah, it does and will wreck internet communications as we have come to know them.

    --
    .
  58. kill botnets , thats the solution. duhhhhh by cheekyboy · · Score: 1

    You have to find the distribution of bot nets and wipe em out, then find the bot nets and whipe them out.

    1. find all bot net PCs
    2. once found, firewall them so they can ONLY LOOK at the ISP homepage, nothing else.
    3. dont let them in until the user cleans the PC.
    4. find the irc channels that bot nets connect to, and log their servers to see who is controlling the bot nets, if a private irc server, firewall it world wide amongst the big ISPs/international gateways.
    5. Find all trojan websites and get the hosters to delete them, if not, then firewall the WHOLE HOSTER.

    --
    Liberty freedom are no1, not dicks in suits.
  59. I know how to get rid of spam. by aerozeppl · · Score: 1

    People with a small penis will be killed so there is no need for "Enhancement" And I will personally handle all loans and mortgage transactions.

  60. No doubt it involves buying Microsoft software. by Anonymous Coward · · Score: 0

    MS Researcher 1: "I've discovered that the only way to stop spam is to stop using Windows!"

    Bill Gates: "Communist. You're fired."

    MS Researcher 2: "Uh, I've discovered that convincing everyone on earth buy Windows is the best way to stop spam!"

    Bill Gates: "Kiss ass. You're fired."

    Steve Ballmer: "Uh...I don't unders-"

    Bill Gates: "Hey, firing people is fun, Steve! Why would I give a fuck about spam anyway?"

  61. what if people talk in latvian? by cheekyboy · · Score: 1

    Ok so your going to make a filter tester for 2000 languages?

    Im sure email that is written in PNG or other languages that arent in the top 10 will look like '99% wrong spelling'

    --
    Liberty freedom are no1, not dicks in suits.
    1. Re:what if people talk in latvian? by Anonymous Coward · · Score: 0

      With the exception of two or three asian spams, the rest of the spams I've received are english. And I've received tens of thousands of spams through the years.

      And hey, the english spams I've received contain really bad english too - even worse than mine. They even seem to confuse 1 (one) with the letter L, and 0 (zero) with the letter O.

    2. Re:what if people talk in latvian? by Antique+Geekmeister · · Score: 1

      IT's got an image attachment of any sort in the mail? Then it's spam. No problem to block, and you can notify the user so they wise up and don't send anything that auto-opens in your mailer.

      Unfortunately, it doesn't block spam that includes HTML and image URL's to show the content in Windows email clients, but if you block HTML email as well, you block another format that is almost entirely spam. Yes, this is very harsh, but people should be discouraged from sending HTML email for other reasons.

  62. An ad campaign by Anonymous Coward · · Score: 0

    We're geeks, so we're thinking of technical solutions. However, the best part of a decade's worth of technology haven't even slowed the pace of growth of spam. No technical solution can be anything but temporary.

    The problem doesn't lie here, anyway. The problem is that spam is profitible, because people buy shit from spammers.

    So, we need to engineer THAT behaviour. The US has some of the world's best marketers and advertising people. It's time to turn them loose on the problem.

    And run a massive education/marketing designed to reeducate the idiots who buy from spammers. Make 'em feel like suckers, make 'em feel unamerican. Make 'em feel scared and alone--publicise stories about spammers running up millions in bogus credit card charges, or working with identity thieves to drain people's banks accounts.

    We have to condition the public NOT to respond to spam. This will be counter-intuitive to the powers that be, because all of the rest of US culture is trying as hard as it can to do the opposite with regard to advertising media.

    If the bushitters put a quarter of the pressure on banks and credit card companies over spam that they've exerted over porn, the problem would be halfway to being solved.

  63. My guess to Microsofts solution by Felinoid · · Score: 1

    I'm guessing Microsoft will cripple Outlook or Windows so that it's not possable to spam using that software.

    This of course will have zero impact on spam.

    As to my solution...
    Enforce existing laws.

    Most spam violates quite a few laws.
    Truth in adverting.
    Harrasment.
    Dishonnest buisness practaces.
    Advertsing to someone who can not legally buy the product.

    If any spammer tried any of this via cold calling or postal they'd be in jail but spammers get a pass.

    Don't loby for more laws just yet. Loby for enforcement of the laws we already have in place.

    If needed bring spam in complience with junk mail and telemarkting.

    --
    I don't actually exist.
  64. So, where's the contradiction again? by Anonymous Coward · · Score: 0

    How many of those "3 out of 5 people" are bitching about getting emails asking them to buy some h3rb4l \/14gr4 and then hitting "reply" and ordering a whole case of p3|\|1s p1LLs? To be contradictory, that is what people would have to be doing. Getting hammered with "R3f1 ur m0rtg4g3!!!" emails is a very different proposition from actively deciding "hey, I need a new router" and buying one from an online merchant.

  65. General rule by IBeatUpNerds · · Score: 1

    Never trust anyone in the computer software industry with a last name of "hackerman." Sorry, I couldn't resist.

  66. The latest: Ascii art spam by really_blurry · · Score: 1

    This morning I got a new kind of spam. It was ascii art promoting valium viagra xanax and many more. The mail was formatted in a pre-tag and the font size set to 2.5. Creative spammers...

    --
    > You've gotta sin to get saved.
  67. Lovely spam! Wonderful spam! by DarkIye · · Score: 1

    "Scientific American today has a very interesting article about "Stopping Spam" by Joshua Goodman, David Hackerman and Robert Rounthwaite from Microsoft Research. They talk about different types of spam -- spam with emails, spam on IMs, spamlinks on web pages and image based spam. They mention different techniques for spam..."

    I can hear the Vikings chanting now.

  68. How many spammers spam direct from their own boxes by aug24 · · Score: 0, Troll

    Don't put fucking windows boxes on networks! If spam wasn't sent via zombies, the real-time blocking list would make all this go away (the tinfoil hat wearers amongst us could make their own lists).

    It's only because crappy microsoft machines can be used to obfuscate the source of the mails that they can do send this many mails without being barred.

    IT'S FUCKING MICROSOFT'S FAULT FOR PROVIDING MILLIONS OF FREE PROXIES!

    J.
    PS I'd have put a question mark on the title if /. didn't have such a damn silly length limit for subjects!

    --
    You're only jealous cos the little penguins are talking to me.
  69. Why Do People Use HTML for Email ??? by mamladm · · Score: 2, Insightful

    The overwhelming majority of spam filter deceiving techniques relies on HTML. If you block messages containing HTML on the mail server, the spam that gets through is near 100% identifiable as spam using bayesian filters.

    So why on earth do people still use HTML in their email? Email should be plain text only anyway.

    --
    the macintosh asterisk mailing list http://www.astm
  70. I think all HTML mail is spam. by TractorBarry · · Score: 1

    > spammers of splitting words using HTML comments, pairs of zero width tags, or bogus tags.

    Personally I'd like to be able to specify that I simply will not receive HTML mail. If someone does send it to me then I'd like my mail server (even better my ISPs mail server) to automatically return a "this recipient does not wish to receive HTML formatted email, please either resend as plain text or don't bother" reply (or is it that this is already possible and I'm just too lazy to work out how to do it ? :)

    Maybe I'm old fashioned but I just like plain text. If I want to read it using a fancy font I'll set that myself thanks.

    --
    Sky subscribers are morons. They pay to be advertised at !
  71. Yes i have ... by GNUALMAFUERTE · · Score: 1

    It's because in this capitalist world money makes the rules, and the big companys rule that they want their product down our throats, all the time. And legislators are part of that system. The law should be a printed reflection of the set of ethical rules of a given society, but in many cases, IT'S NOT, or it's based on the mindset of a group of people that has no ethics, or they ethics has been seriously compromised by their own thirst for power and money. So, NO, the fact that this shit is legal doesn't make it correct or ethical.

    --
    WTF am I doing replying to an AC at 5 A.M on a Friday night?
  72. did the researchers by harryoyster · · Score: 1

    Did the researchers also look at making operating systems more secure. Most of the spam that I get these days is from exploited/trojaned or other systems. If we can slow the source we can help eliminate the problem.

    --
    Got a question about UNIX ask it here : Unix/xBSD Forum
  73. Desirability does not need to be subjective. by jotaeleemeese · · Score: 1

    You can define your willigness to receive a message in programmable terms, thus spam could be:

    -Messages whose senders I have not authorized to send me messages (that authorization could take the form of signed emails, white lists, etc)

    --
    IANAL but write like a drunk one.
  74. Dyslexix phishing by Hieronymus+Howard · · Score: 1
    I liked the phishing email from the 'split fit' article:
    Date: Mon, 28 Mar 2005 18:41:22 -0800 (PST)
    From: "B&#1983;rclay&#1980;s" <amwmwngkev@yahoo.com>
    Subject: Braclays Emlia&#8236; Veacifition
    MIME-Version: 1.0
    Content-Type: multipart/alternative; boundary="0-1893089315-1112064082=:45059"
    Content -Length: 1338

    Dera Blcraays Mbmeer,

    Thsi eamil was stne by the Barclays serevr to vreify yuor emial adsserd. You mtsu competel thsi pssecor
    by ccilking
    on the likn bewol and entireng in the smlal wiodnw yoru Braclays Membership nrebmu, passcedo and
    meelbarom word.
    Tsih is doen for yruo proteoitcn - buacese semo of our mrebmes no lonegr haev assecc to theri emlia
    adserdses and
    we muts virefy it. To vyfire yruo eiaml arddess and accses yruo bnak anuocct , cilck on the lnik bolew:


    Is anyone going to be stupid enough to respond to this one?

    1. Re:Dyslexix phishing by 10Ghz · · Score: 1
      Is anyone going to be stupid enough to respond to this one?


      Short answer: yes
      --
      Lesbian Nazi Hookers Abducted by UFOs and Forced Into Weight Loss Programs - -all next week on Town Talk.
  75. Actually, it's not that complicated by Moraelin · · Score: 2, Insightful

    1. Most civilized countries are sick and tired of SPAM too. E.g., most European countries. So there is enough scope for a spam free zone, if the USA does want to get its act together and cooperate. It's not like you're alone against the world on the SPAM issue, except for the fact that:

    2. It's mostly your spam that's dumped upon the rest of the world. USA is currently _the_ biggest source of spam, followed by... offshored operations paid for by someone from the USA.

    So on one hand, the USA could halve the SPAM traffic on its own, without even needing much international cooperation, if it actually got its act together. And on the other hand, hey, there's a lot of incentive for a lot of other countries to cooperate. Just show us where to sign, if it means we'll stop getting your crap in our inboxes.

    3. Once you have secured an EU+North America treaty on that issue, the rest of the world should IMHO be actually pretty easy.

    We're talking some major combined economic power there. Any country who doesn't want to play ball with that kind of a behemoth can be whacked into submission in a variety of ways, ranging from economic sanctions to just disconnecting them from the Internet.

    Makes that country unattractive to spammers too in the process. See, I don't think spammers want to target the local citizens of Elbonia with their operations. You disconnect them from the rich targets, you've killed that operation. So any country which thought it'll get rich by sheltering spammers, will quickly lose that investment too and be left with just the other disadvantages.

    So I think they'll play ball.

    4. But I don't think the spammers want to move to Elbonia or East Bumfuckistan and run their operation from there anyway. They might pay some local 5 bucks to run a server for them there, but they don't want to go live in a third world country. Those countries aren't that much fun.

    You may see that even for legitimate operations, IBM might offshore their tech support to India or China, but you won't see the CEO of IBM moving there. (And those are already developping countries, not third world ones.)

    --
    A polar bear is a cartesian bear after a coordinate transform.
  76. attacking from another direction by Fuji+Kitakyusho · · Score: 1

    What about making it a crime to purchase products advertised via spam? The spammers may not care about enforcement, but John Q. Public might give it a second thought if he could be held accountable for supporting the industry.

    1. Re:attacking from another direction by Anonymous Coward · · Score: 0

      Congratulations. You just proposed outlawing Viagra, mortgages, and porn. That'll go over real well, I can assure you.

  77. Re:How many spammers spam direct from their own bo by Anonymous Coward · · Score: 0

    No, that's just one part of the problem. Take a close look at the old Cyberpromo case. The ISP's are refusing to dump spamming custoomers because professional spammers pay bills the ISP's need paid to stay afloat, and the ISP's are very nervous to act on their own due to liability concerns.

    Even if an ISP cares a bit, it's expensive and dangerous to cut off a spammer. When Cyberpromo found their colocation sites being cut off before they even spammed because the upstream network providers refused to permit the downstream colocation companies to carry Cyberpromo as a customer, it was a bit of a legal train wreck. It wasn't ended by legal means: it was ended because Cyberpromo's primary ISP, agis.net, had the upstream router for Cyberpromo denial-of-service attacked out of service and kept that way for days, until agis.net threw in the towel and dropped Cyberpromo. Mind you, they had grounds to drop Cyberpromo due to criminal activity by Cyberpromo such as bringing major ISP's to a grinding halt with fraudulently sent spam floods, but this was typical.

    The point is that it's not just unsecure machines: there's a real problem with the process where it's very difficult to act against a spammer, and each spammer can stay in business for years.

  78. Re:Overview of Spam Filtering Approaches by PatrickCynicExtraord · · Score: 1

    There is also source code to create your own spam filter (Java)...

  79. That isn't easy at all. by Mr.+Underbridge · · Score: 1
    Most civilized countries are sick and tired of SPAM too. E.g., most European countries. So there is enough scope for a spam free zone, if the USA does want to get its act together and cooperate. It's not like you're alone against the world on the SPAM issue, except for the fact that:

    I realize that. But Europe isn't the real problem either, it's Asia. And it only takes a few jurisdictions who don't care to keep spam rolling. And it's also easy to find cracks in jurisdictional entanglements even if everyone works together. Look, if we were talking about murder, they might get it together. But I don't see the FBI and Interpol getting their braintrusts together to solve spam.

    It's mostly your spam that's dumped upon the rest of the world. USA is currently _the_ biggest source of spam, followed by... offshored operations paid for by someone from the USA.

    Don't know why you're making this a US issue. If I were to bite, I'd also say we have more people connected, and I haven't seen stats that say we spam inordinately given our internet presence. But this is an international problem regardless, it doesn't matter.

    Once you have secured an EU+North America treaty on that issue, the rest of the world should IMHO be actually pretty easy.

    I wish. China will pay lip service but they don't have the resources now to solve a problem they don't really see as a problem. Look at copy protection as an example. They'll sign the treaty and smile, and that'll be that.

    We're talking some major combined economic power there. Any country who doesn't want to play ball with that kind of a behemoth can be whacked into submission in a variety of ways, ranging from economic sanctions to just disconnecting them from the Internet.

    You only have so much political capital, and I don't think nations are willing to use it on spam. Really, it's not enough of a priority. So no one's going to make that level of a threat against China. China would be insulted, it would set back relations severely, and they're doing worse things (like dumping product against WTO rules). So again, not happening. If our Attorney General went into a cabinet meeting and said that if China didn't cooperate on spam that we'd disconnect them and sanction them, he'd be laughed at. If we don't sanction them for unfair trade and human rights violations, we aren't doing it for spam.

    But I don't think the spammers want to move to Elbonia or East Bumfuckistan and run their operation from there anyway. They might pay some local 5 bucks to run a server for them there, but they don't want to go live in a third world country. Those countries aren't that much fun.

    No? How about Aruba, where all the internet gambling sites run? Bottom line is there will always be enough places that don't play ball, and that aren't worth shutting off from the net. And there will always be spambots, so that wouldn't help anyway. And there will always be enough jurisdictions that don't have enough time/money to pursue this problem that really doesn't hit the radar of (for example) our Department of Justice which generally has bigger problems. So you can forget about the nations of the world getting together to hammer out a solution to this problem. I don't plan to sit on my hands waiting for governments to solve the problem.

    Utimately, yes, this problem could be solved if everyone worked together. But if you think that'll happen, you're truly naive.

    1. Re:That isn't easy at all. by Moraelin · · Score: 1

      That is a very insightful observation, except for the fact that most people and countries don't give a damn about internet gambling. It's not like it actively goes spreading gambling-zombie viruses or actively goes forcing people to gamble, or anything.

      So IMHO it doesn't even invalidate my point.

      1. We're still talking about a simple offshoring operation. We're not really talking about having to _move_ there, because your country would throw you in prison for that operation.

      I'm willing to bet that the people making money from those gambling operation still live comfortably in the USA or EU. If they actually faced a choice like "(A) personally move to a third world country, (B) shut down the operation, or (C) go to jail" I still believe that most would choose B.

      But either way, it doesn't really either contradict or prove my point. It's just not the same situation.

      2. Because noone is actively fighting Internet gambling, a country hosting those isn't in any danger of being disconnected from the 'net for that. I.e., it doesn't prove that point either.

      Now let's think we were talking spam there. That all the world's spam was coming from a single third world nation, let's call it Elbonia. I'm thinking you can already see where this is going: everyone's spam filters and most ISP's would completely block emails from that block.

      I.e., as I've described before, that country would find itself quickly off the net, and its spammers effectively disconnected from their source of income. Sure, the country may still encourage them. But suddenly they can't actually make money as long as they stay in that country. Are you that sure they wouldn't drop it like a hot potato?

      3. As illustrated above, it doesn't even take any political effort to take a few bad apples off the net. Any third world country that becomes _the_ source of spam will just make every ISP's and admin's day: it's a single rule to block the trash. Incidentally, the rule that also takes that country off the net.

      It's much the same as from half the world you can't make a credit card purchase any more. There was no political decree to start blocking those countries' citizens from online purchases. It's the banks themselves who eventually just had enough of those countries' encouraging fraud.

      So what's China going to do there? Call my ISP and threaten with sanctions if they don't start allowing spam from China? Threaten my ISP with WTO violations, even? Now that would make a few people's day at the ISP. I can imagine some general fits of laughter.

      --
      A polar bear is a cartesian bear after a coordinate transform.
    2. Re:That isn't easy at all. by Mr.+Underbridge · · Score: 1
      That is a very insightful observation, except for the fact that most people and countries don't give a damn about internet gambling. It's not like it actively goes spreading gambling-zombie viruses or actively goes forcing people to gamble, or anything.

      The US attorney general does. You're right, gambling is not as big a problem. But I'd reiterate, it doesn't matter what we think the problem is, it's the priorities of the government. And spam is a low priority for them compared to gambling. So you're not going to see them "waste" time and political capital on spam. That's just the US, but I haven't seen any country really make an effort to - or even talk about - solving the problem. Unless it becomes a much higher priority, spam cannot be solved internationally.

      I'm willing to bet that the people making money from those gambling operation still live comfortably in the USA or EU. If they actually faced a choice like "(A) personally move to a third world country, (B) shut down the operation, or (C) go to jail" I still believe that most would choose B.

      I've read about it. They live in Aruba. One guy interviewed fully realizes he'll be arrested if he ever comes back to the US. He's fine with that, because he's 1) rich, and 2) lives in a tropical paradise.

      I.e., as I've described before, that country would find itself quickly off the net, and its spammers effectively disconnected from their source of income. Sure, the country may still encourage them. But suddenly they can't actually make money as long as they stay in that country. Are you that sure they wouldn't drop it like a hot potato?

      So why is that not happening? Because NO COUNTRY, let alone an ISP, is willing to have the arrogance of completely cutting another country off, even for spam. The question of whether this would work is completely irrelevant because it would cause much bigger problems than it would solve. It would cure spam in much the same way that decapitation would cure acne.

      It's much the same as from half the world you can't make a credit card purchase any more. There was no political decree to start blocking those countries' citizens from online purchases. It's the banks themselves who eventually just had enough of those countries' encouraging fraud.

      And why aren't ISP's doing this now? Maybe a few do, but because enough spam comes from, say, Korea, and that's a big country, cutting it off isn't an option. Hell, we can't even catch people spamming in *this* country easily because of the inefficiencies in the bureaucracy, jurisdictional problems, and the difficulty of tracing spam back to its actual sender.

      Basically, your plan requires every country of any significant size to simultanuously solve the spam problem. That's why it won't happen. Ideas like yours sound great in a bottle, but when you actually go to implement them, it gets messy. The place where it falls apart is the same as with air pollution laws, a significant portion of the countries will balk at implementing the plan if there's anyone who won't, as all it takes is a few bad apples to make the entire effort pointless. So unless you can solve the problem internationally all at the same time, it won't work. And since that'll never happen, that's why legislating spam away won't be successful.

      Bottom line, if the govs/ISPs want to solve the problem, and your idea is implementable, why aren't they doing it? I can assure you, it isn't because they haven't thought of it.

  80. Just uploaded my old mail to a gmail account by Anonymous Coward · · Score: 0

    Out of ~40,000 e-mail, only ~4000 were valid messages.

    No wonder I abandon e-mail quite some time ago.

    Though, it is fun to reminsis over the past via gmail

  81. Defeating Bayesian Filters by Anonymous Coward · · Score: 0

    Anyone interested in antispam technology should give the Whitedust article 'Defeating Bayesian Filters'. Registration is required I'm afraid but it's free... so... Enjoy ;]

  82. Spam by NAACPsupporter · · Score: 0

    Since we turned on SPF/Caller ID on the barracuda box, our spam has gone down to maybe 3 or 4 messages per day per user. SPF is so easy to implement and it could end all spam.

  83. Nice April Fools joke, that paper is by Anonymous Coward · · Score: 0

    Really had the mods going there.

  84. Stocks by jefu · · Score: 1

    Perhaps Mr "Schwab" is selling penny stocks and wants to expand his market?

  85. White Lists by tilleyrw · · Score: 1

    My thought is simple. White list.

    Any mail you receive is automatically classified as spam unless it was sent by a known, approved sender.

    Now let me go back to deciding if the sender of the Nigerian Penis-enlarging Hot-N-Horny Virgins is a friend.

    --
    This post encoded with ROT26. If you can read it, you've violated the DMCA. Handcuffs please, sergeant.
    1. Re:White Lists by Anonymous Coward · · Score: 0
      You make a good point, but not the point you intended to make.

      The problem with white lists is simply this: when an old friend you haven't seen in years, and whose email address you don't know, gets your email address from another friend, and then he emails you to say "hello", his email will be classified as spam since he's not on your white list.

      The point that you successfully made is this: you can't cripple spam without crippling email.

      Email is useful because it's: free, fast, easy.

      Spam exists because email is: free, fast, easy.

      To rid the world of spam, email has to become: less free/fast/easy.

  86. Posting Spam in Yahoo Groups by mysterystevenson · · Score: 1

    What I hate is when someone spams a member group so much with so many links in posts that the group ends up breaking up over the attacks. I just quit about 10 groups over the same spammer; Lou Gentile is supposed to be a talk show host on the radio, but he either/or knows 20 or 30 different people that are willing to post all the same posts every day, and I mean long posts that take up a lot of room in your email when they get forwarded to you from your group. So many names and everyday a new header- there is no way to filter it all. So I quit all the groups this was happening in. Of course now I am getting a few from them anyhow as they mined my email, but that I may be able to filter, may mind you, cause they are always finding a way to annoy. As to the rest of it, I skim the rest of my email just to make sure a piece of good email isn't in the junk. I never open anything I don't know. But I can spot a phish a mile away and that is begining to take more of my time as I feel it is my resposibility to report those to the fraud investigators. You see I do no electronic transfers of funds whatsoever, and any financial activity online raises immediate flags, everywhere. Any bank or paypal, ebay and so on, is known to be fraud. I don't even write checks. So I am able to help out a number of investigations groups by reporting and auto-alerting activity which is new. So there is talk of Spam not bothering people as much, well it seems to be screwing up my life pretty good. Ruins good groups, and I seem to be taking up 4 times more this year reporting fraud online.And I don't go looking for it, it comes to me. Jerks.

    --
    MYSTERY
  87. Spell check? by avicarmi · · Score: 1

    why not just run a spell checker on suspected spam?

    if there are too many misspelled words, flag as spam:

    Thsi eamil was stne by the Barclays serevr to vreify yuor emial adsserd. You mtsu competel thsi pssecor

    also, with some adaptation, this can work with HTML e-mail:

    1 - do not even parse the HTML

    Hypertextus Interruptus: Fi</n>nd N</n>ew </n>Fri</n>end</n>s
    Slice and Dice: <br>U<br> <br>O<br>a<br> <br>D<br>u<br>a
    Ze Foreign Accent: eárn mõnéy thrôugh unçõlleçted
    The Black Hole: V<font size=0></font>i<font size=0>
    etc...

    none is a valid dictionary word, so that there will be many misspellings...

    2 - strip only valid HTML tags, leaving any bogus HTML tags such as ab and run the spell checker again, looking for both misspellings and trigger words.

    3 - just strip all HTML codes and check the resulting words, both for spelling and for trigger words.

    4 - to avoid possible false positives, since valid HTML will also fail step one when the HTML is not parsed, parse the HTML and see if there are many valid dictionary words. since non-spam usually uses "nice" HTML this should be easy to parse, if the HTML is not valid, flag as possible spam.

    can also check the ratio of HTML tags to text outside the tags, if there are lots of html or html look alike tags in the code, relative to the text, possible spam.

    --
    -avi
  88. Did the MS Gurus mention ... by Tjp($)pjT · · Score: 1

    That it is a good idea to stop using email clients that automatically execute live code or allow disguised programs to have the appearance of some other class file luring unsuspecting neos into double clicking into virus heavan. Or email clients that allow access through scripts to the address book with no warnings? For example that odd Outlook product. "satire for the humor impaired warning, well actually so I won't be sued satire warning"

    --
    - Tjp

    I am in wallow with my inner money grubbing capitalistic pig. ... Oink!

  89. Hey! by aug24 · · Score: 1

    I posted this below and got modded troll! No fair!

    J.

    --
    You're only jealous cos the little penguins are talking to me.
  90. "only" half of the spam by Mugros · · Score: 1

    Clearly, no law of a single country can hope to end spam. Only about half of all junk e-mail comes from the U.S

    Well, "only" is a nice understatement. The population of the USA is about 4.5% of the world population. (OK, not everyone on earth has a PC)