Blue Security Gives up the Fight
bblboy54 writes "According to The Washington Post, Blue Security has closed its doors, which can be confirmed by the Blue Security application failing to work today and their domain no longer resolving. Blue Security's CEO is quoted in the article: "It's clear to us that [quitting] would be the only thing to prevent a full-scale cyber-war that we just don't have the authority to start," Reshef said. "Our users never signed up for this kind of thing." You have to wonder where it goes from here. It seems an effective method has been found but more than a small private company could handle. Will someone else adapt this concept, or does the internet world give up?"
Anyone want to state the obvious answer?
Hey, wait a minute, I've followed Blue Security since I first read about them on /., and I can't believe they're just gonna fold up shop and give up! Isn't this what they got into the business for? Can't they take this attack and use it to demonstrate the validity of their concept? I wish they could think up another tactic besides, 'you win' -- perhaps diversifiying their URLs/IPs so that they're more spread out...less vuln to an attack on one IP? Come on, what do readers think...I know there's got to be some way to use BS software and reroute things through an Onion style network to fight back.
fak3r.com
"When the company's founders first approached the broader anti-spam community and asked them what they thought of the idea, everyone said this was a terrible idea and that they would eventually cause a lot of collateral damage," Underwood said. "But it's also extremely unfortunate, because it shows how much the spammers are winning this battle."
Hell, the idea of flooding the spammers network is older then a reasonably aged Armagnac and was discounted even when it came up.
Building a business model on such an innane idea looks as if the company execs are a few fries short of a happy meal. Speceifically since they where warned by more experienced people.
ich bin der musikant
mit taschenrechner in der hand
kraftwerk
This episode proves that the spammers own and control the internet.
The internet is no longer free (not as in beer). We must pay obesience to the owners by allowing their spam in out inboxes.
I, for one, do NOT welcome our spam-spewing overlords.
Ignorance is curable, stupid is forever.
It's hard not to fall to vigilantism when there's no sherriff in town to keep the peace on your behalf...
I noticed that your user page doesn't have any submitted stories that made the front page. I also comment fairly regularly and have had three submissions accepted. After my first one, I started receiving 20-30 phishing emails a day in my gmail inbox, and about 5 legitimate emails. That's why I've stopped posting any kind of email whatsoever to this site. As it is, my URL currently goes nowhere as well because shortly after I started using that instead I got hit with comment spam and lacking the time to install a solution like captcha images, I decided to just take the server down instead. This is for a site that got at most 20 people a day who were mostly my friends. We need some kind of international solution to stop these people and the harm they're doing.
Wow so the bad guys won? This isn't the way it's suppose to happen. wtf
I came to the datacenter drunk with a fake ID, don't you want to be just like me?
Fine, I'm happy for you. You obviously don't own an active domain, or a business. Because otherwise I could guarantee that it gets to be a problem for you.
But the problem is not you, it's not me, it's not my little kid sisters dog.
The problem is that a couple of hundred big time spammers are getting rich by shitting into the communal water supply!
If you think that's acceptable within a society then you will apologise that I have no respect for you and the likes of you.
ich bin der musikant
mit taschenrechner in der hand
kraftwerk
It seems that the problem here is that they were brought down by the spammer's huge number of bots running on compromised machines. Why has no one tackled this problem? It seems to me that this should be the responsibility of the ISP's. I'm no expert but I believe that if someone reports to an ISP that a particlular IP address is running a bot, that it should be a simple process for the ISP to do some tests to see if that is true by checking the nature of the traffic coming out of the machine. If they decide that the machine has been compromised, they should shut down it's connection and redirect port 80 requests to a web page explaining to the owner that their machine has be compromised and how to fix it.
This does not seem to me to be a difficult technical problem and it is in everyone's interest to get the compromised machines off the net.
The difference between Canada and the USA is that in Canada healthcare is a right and gun ownership is a privilege.
I know the flip side of the spam problem is bandwidth wastage, but anyone who's still getting spam in their inbox should install some nice filtering software.
I have a catch-all email address set up on my domain - so $anything@$mydomain gets to me.
For years, I used to get a very small amount of spam to addresses like info@, sales@, etc, and a throwaway account I used on a website that I never used for any real mails.
Then, a few months ago, some scum-sucking shit-brained low-life motherfucker* decided to use my domain name in forged From: addresses.
(* But I'm not bitter)
I now receive on the order of a thousand spams, bounces and assorted related crap per day. Now, of these, only a tiny handful make it to my inbox, and they're all easy to spot. I've not done the stats, but I'd image that Thunderbird's filtering is 99% accurate or better.
It's still a pain in the arse though, and it's still utterly unacceptable behaviour on the part of the morons responsible.
I don't necessarily think that vigilantism is the answer, but something has to be done.
(Yes, I could switch off the catch-all addressing, but I actually find it useful, inconsiderate wankers trying to ruin the entire net for everyone not withstanding)
It's official. Most of you are morons.
At this point I'm convinced that the only solution is a worldwide series of gory murders of spam kings with "death to spammers" written on the walls at the crime scenes in the spammers' blood.
The correlation between ignorance of statistics and using "correlation is not causation" as an argument is close to 1.
The bad guys won this time because we tried to match force with force. I've said it multiple times in this forum - we have to accept that spam isn't going to go away. The only way we're going to get it down to an acceptable level is to make it not worth doing.
Filtering is one way, but basing it on the raw content of the email won't work. If there was a public key repository where legitimate users placed a public key for decryption, and all legitmate email were sent encrypted with the corresponding private key, the authenticity of the email could be known. Then, if someone starts making a nuisance of themselves, they could get their public key revoked. If this method were used, filters could be made to only let through emails that decrypted with the public key of the sender.
Let's face it, spam is a fact of life. Remember that you're up against people who do this as their 9-5er with no regard for law, ethics or their public image if you want to go the force-vs-force route.
DISCLAIMER: This post was not checked for speling and grammar- if you complain- you're a whiner
And underground, it'd be also be helpful to DDoS the fuckers. The problem with that is that the dickhead 13 year old kids running the botnets don't care about spam.
Anymore then people want to know their 3 ton car is causing global warming. Imagine if Shell refused to sell gas to cars that do not have a certain fuel efficiency. How long would they stay in business?
It is one of the reason to liberetarians are wrong. A lot of things can only happen because they are written down in law.
Should there be a law that forces ISP's to shutdown bots? Well, it all depends on the kind of internet you want. A totally free on that is controlled by criminals or a non-free one that is controlled by the state.
Cause freedom doesn't exist. There is always someone in control. For now it is the spammers.
MMO Quests are like orgasms:
You may solo them, I prefer them in a group.
This really demonstrates the need for a distributed version. Not only is the centralised architecture easy to attack, as we saw with BS vs PM, but also it's at the mercy of its operators. A living breathing antispam system was in place, with many willing users, but had to be shut down because the tiny head at the top of the body wanted out. If it was less monolithic, head shots wouldn't even exist.
Tie that in with my other idea, and maybe there's a good method in there somewhere.
Hello spammers. In Soviet Russia, the angry citizens beat the shit out of YOU!
"Our users never signed up for this kind of thing. You have to wonder where it goes from here. It seems an effective method has been found but more than a small private company could handle. Will someone else adapt this concept, or does the internet world give up?"
/. style, I haven't *yet* done), but can we please at least try to make somewhat clear what an article is about, so that everyone can decide for himself whether this subject is of interest to them in the first place?
What kind of thing? What kind of effective method has been found to do, what exactly? What is "this" concept we are talking about?
I read this site (almost) daily but have never ever heard of this company before. As it is apparently some kind of small startup, I'd imagine many others around here have never heard of them, either.
Without any context, this "article" is pure gibberish. Maybe it makes sense after reading the linked article (which, I'll admit in good
Every expression is true, for a given value of 'true'
I don't necessarily think that vigilantism is the answer,
Why not? It obviously is. Nothing else is working. Once a few spammers have died horrible deaths, or have been mutilated, tortured, branded and hung out in the marketplace covered in honey with a big ant colony nearby, there just might be a reduction of spam.
Spamhaus knows the top 200 or so spammers, many with addresses. $1 from everyone who hates spam and there's a pretty good bounty, and it is cheaper than installing new filters all the time.
Assorted stuff I do sometimes: Lemuria.org
Do it right then. If you've got 15 names, murder 10. Then drop a Usenet post with a couple of scene shots saying "There's five names left on my list. If you want to know if yours is on it, just keep spamming." That would stop much more than 15 spammers. (Or at least they'd cower.)
Any sufficiently advanced libertarian utopia is indistinguishable from government.
There's nothing stopping me shitting in the reservoir. Does this mean that tapwater is dead?
If you do that sort of thing enough, you will be tracked down and (if caught) prosecuted.
The same apparently cannot be said of spammers - or at least, not the ones that pick on individuals. I imagine that the story would be different if they chose to forge addresses from amazon, google, microsoft, etc.
It's official. Most of you are morons.
I don't necessarily think that vigilantism is the answer...
Vigilantism is exactly the answer. For some reason, there's this idea that people aren't supposed to "take the law into their own hands". Well, who is supposed to maintain the law? The authorities? They can't do it. If every last cop on every last police force was Joe Friday, they still wouldn't come close to having the manpower to control traditional crimes, let alone email spammers.
More to the point, every last cop on the force isn't Joe Friday. Frank Herbert wrote that the saying "power corrupts" needed to be re-written as "power attracts the corruptible". With profound respect to those who become the authorities of society because they genuinely want to make the world a better place, there are also lots of people who do it because they want the power. From street cops to the presidency, we have seen that bad people are drawn to power. The worst ones are on the take, beating people who surrender, invading other countries without justification, passing legislation that favors institutions over individuals, and so on. The ones who are just misguided genuinely believe that only particular, designated officials should run a society. Both types support the idea that people aren't supposed to take the law into their own hands.
How does all this happen? How do people get into situations where bad people ruin things and nothing can be done? Because there are people who don't believe in taking the law into their own hands. Because there are people who believe that making things better is a job for someone else, not a sacred trust. Because there are people who don't feel like this is their world. And because lots of people who care only for themselves are willing to take advantage of people who don't believe in vigilantism.
Of course, the word "vigilantism" is not a native part of my vocabulary. I have another word that I use there. Let me rewrite the original statement: "I don't necessarily think that responsibility is the answer..."
Five percent of one year's DoD budget puts us on Mars.
A new protocol will help greatly, but it won't stop the REAL problem which is people shitting in communal waters.
Interesting metaphor. Fact is that public waters tend to be full of shit, and there's nothing we can do about it. Reservoirs are routinely colonized by fish, waterfowl and aquatic arthropods, which eat the plants and each other and shit out the waste. Water supplies can only minimize this; they can't prevent it. So, rather than fighting a hopeless battle and delivering contaminated water, they accept the situation. They try to keep the reservoir somewhat clean, but they also filter and sterilize the water while delivering it.
It's likely that the same situation with email is permanent. Attacks can cut down somewhat on spammers, but like the insect larvae in the reservoirs, there will always be spammers in the internet. Delivering clean email will require filtering and decontamination software. We already have lots of it in place, and it's likely that we will always need it.
There will always be hucksters and scammers out there trying to separate us from our money.
Those who do study history are doomed to stand helplessly by while everyone else repeats it.
Yes, but the Lycos screen saver was owned by a company. Companies are easily pressured into changing their ways. An open source project on the other that belongs to everyone wouldn't have a single point at which to attack. Each person who chooses to use the tool takes upon themselves the repercussions of their own use.
Except only the slashdot hive-mind thinks that what Blue Security were doing was OK. I know about the whole "one web request for one email" but spam is a problem of traffic, and fighting that by INCREASING the traffic on the network is just utterly bizarre to anyone involved in email except for BS.
As for: You will be attacked by professionals who have more money than you, more resources than you, better programmers than you, and no scruples at all that's not exactly true. There are anti-spam organisations and companies that have been running for years, are very good at keeping peoples inboxes clean, and also work within the industry to find long term solutions to the spam problem. And they haven't been DDoS'd off the internet. Now it's true that Spamhaus and SORBS regularly get attacked, but they're still here, and they will be for the long term because the ISPs are willing to put up with a bit of bad network traffic for them because what they're doing is admirable. What BS were doing wasn't, and I'm sure their ISP wasn't willing to ride out the storm of the DoS.
Matt. Want XML + Apache + Stylesheets? Get AxKit.
but spam is a problem of traffic
NO! SPAM is a problem of bandwidth STEALING! Spammers are using OUR bandwidth to GAIN MONEY.
Remove one of the two (our bandwith, or their money) and we'll solve the problem.
fuck you
leave all my ports open, thanks
There are places where the networks are not touching,and there are places where they are-Boeing's Lori Gunter
While I do hope someone does something about spam, I'm not certain if vigilantism is such an answer... just think if one of Spamhaus's 200 spammers is mis-identified.
We have been mistaken for spammers once, and it's not nice, we were blacklisted for 3 days before we convinced the blacklisters that we were a legitimate business, during that time our sales people had a hard time (and no we don't send newsletters or nothing of the kind, just business email).
Being DOS'd or some of the scarier options proposed does not sound good to me.
There are three kinds of lies: lies, damned lies, and statistics.
The question is, are you giving them the way out, or are you leading them into damnation? You're assuming that your interpretation is the only possible true interpretation, and that therefore you have the right & duty to enforce that interpretation on people who disagree with you. That is incredible hubris.
In the modern day, we see a lot of people judging and throwing stones, and claiming that they're right to do so. Now, I'm no biblical scholar, but I'm pretty sure that both the OT and the NT are pretty specific about people usurping the perogatives that belong to god.
Let me be blunt: It is not given to you to be judge and jury to your fellow man. No one appointed you the sole keeper of god's laws, and nothing makes your interpretation of those laws superior to anothers.
ad logicam Claiming a proposition is false because it was presented as the conclusion of a fallacious argument.
Interesting point. I am not, as you seem to be suggesting, an ethical relativist. On the other hand, Christian dogma is so amazingly fragmented it would be difficult to attribute anything like a consistency of belief across the whole of the religion.
My point, thus, is that, where there is doubt, there should be circumspection. I've never heard a defense of murder, for example, that would appeal to a rational audience. On the other hand, biblical passages have in times past been used to justify murder, for example, the Salem Witch Trials.
Now while I hold that anyone who feels strongly that witches should be burned has every right to that belief, I strongly object when they try to impose that belief on a world that disagrees. Likewise with the modern evangelical tradition of deciding, arbitrarily, on what constitues the truth, and then attempting to force that belief on all and sundry. They would certainly expect their beliefs to be honored...indeed recent history can be conclusively shown to demonstrate a tendency on the part of evangelical christians to hysterically denounce any and every action that they feel impinges on the fullness of their belief (e.g The "Holiday Tree" debate, and others).
Now, historically, there has been a way around this impasse of beliefs that I'm going to refer to as laws, which, for the purposes of discussion, we can think of as "enforcable beliefs" that are agreed on by people who otherwise have different belief structures. Now recently, the evangelical types have taken to thinking of any "belief" (be it legal, moral, logical, or scientific) that runs a counter to their own beliefs as less valid, and, indeed, a purely personal attack on their correct beliefs.
Now my argument, if you would call it thus, is simply to point out that, with so much disagreement on the fine points as it were, of their beliefs, it would be wise for them to accept, with some Christ-style holy humility, that other people are also entitled to beliefs, before their hysterical intolerance breeds domestically the very same problems we see all over the world.
ad logicam Claiming a proposition is false because it was presented as the conclusion of a fallacious argument.
I'd have no objection to ISP's blocking outgoing SMTP by default, but with a policy to unblock upon request. Better yet if they provided a means for users to block/unblock at will.
Actually, yes, it is. Pretty nearly anyway.
Because spam is not just about cluttering you inbox.
A substantial portion spam is now primarily a revenue generator for serious criminal organisations. The sort of organisations which also PRODUCE child pornography and traffic in child prostitutes from destitute countries.
That is why so many people are now muttering about vigilante justice.
And why I post as an Anonymous Coward. Something else to consider: if someone comes up with a method which hurts them as badly as Blue Frog's technique, but can't be stopped by technical means, they WILL try to kill you.