New Opt-Out Clause Makes CAN-SPAM Worse
snydeq writes "Three years of mulling, and the FTC has made the CAN-SPAM Act worse, writes Gripe Line's Ed Foster. Chief among the offenses in the FTC's updated rules is an even worse approach to opt-out procedures. In the future, in scenarios where multiple marketers use a single email message to spam you, 'only one of the senders — the one in the From: field — need be designated the official sender who is responsible for honoring opt-outs,' Foster writes. Translation? 'Other "marketers" who used that spam message, not to mention the spamming service that actually provided the email address list, don't need to honor opt-outs. So try as you might to get yourself off a list, the real spammer can just keep changing the designated sender in the From: field and legally keep on spamming you.' The irony of the CAN-SPAM moniker gets thicker."
This is why established industries LOVE regulations! Once you have procedures in place to "follow" the regulation. Then the regulation becomes barrier to entry, or even a legal minefield, to those coming after.
In this case unsolicited bulk email would be illegal if you didn't follow all these rules up front. But for the guys that already got the grace period to follow the law it's been twisted just enough to be meaningless!!!
Power, telco, FCC, FAA, FDA, etc all those rule making agencies are run like this. It's just funny to see something so simple twisted so quickly. This is the same reason nobody wants internet neutrality put into law. Then any exceptions to blocking become "rules" that they "have" to block other content/providers... The telcos are already writing the rules the way they want with lots of backwards worded loopholes.
Other "marketers" who used that spam message, not to mention the spamming service that actually provided the email address list, don't need to honor opt-outs
Damn! I guess this means an end to the three wonderful years of relief we've all enjoyed from spam thanks to the oh-so-effective initial rules.
Seriously, this change really doesn't matter, except it will let the FTC claim success due to a massive drop in the number of "valid" complaints against spammers. Whining that it weakens the existing law strikes me as similar to complaining that a serial killer violated a restraining order.
I fully expect within the next few years we will see average Joe hacker ... as in a person who likes to fool with technology ... begin a personal and secret computer assault against any business or organization who uses the services of spammers.
In other words, if those in power won't protect me, why should I feel I am doing anything wrong to try and protect myself?
If using the services of a spammer gets your network shot down with any sort of reliable regularity, it seems logical that using them is going to become a harder and harder decision to justify. Make 40G's using the spammer, spend 37G's fixing the network damage that follows.
In the long run, I see this fight as one that cannot go any other way.
In B.C., our fascism is green.
It seems that they managed to take a completely toothless act, and make it even less helpful.
I guess it is no wonder that congress has managed to somehow attain an even lower approval rating than our current commander-in-chief, seeing as they managed to squirt out something like this instead of dealing with important national issues.
Damn_registrars has no butt-hole. Damn_registrars has no use for a butt-hole.
Steve Richter, father and lawyer to "SPAM KING" Scott Richter helped write the CAN-SPAM act. The act is a joke.
Anybody who makes a sufficiently large contribution to their campaign, apparently.
This is a failure to regulate effectively, not a place in which regulation necessarily fails. Regulation in itself isn't a bad thing, it just needs to be done by people who actually want to get something done.
Find the spammers, and impale them. DEATH TO SPAMMERS!
I write sci-fi for metalheads
Cool, then can you please make it so spam is an OPT-IN thing instead of OPT-OUT?
As it stands, the majority of people who receive the 'opt-out' spam DO NOT WANT IT, which makes the solution obvious: Change the system to Opt-In. That way, those of us who want something from someone, get it, and those whose spam is unsolicited can be prosecuted.
It is ridiculous that something so problematic to day-to-day functions is treated as OPT-OUT. If you're a policy maker, how do you justify that aspect of the policy?
English is not my first language. Corrections and suggestions are welcome.
Spam lacks sufficient definition. While there are certain things that most of us can agree are spam, there is a sufficiently large gray area that it's not really possible to define clearly as law.
However, some things are absurdly easy to define -- take freedom of speech. You are allowed to say pretty much what you want, where you want, short of "Fire!" in a crowded theater. No one has yet found a way to twist the First Amendment into meaning something it doesn't -- into somehow meaning, for example, that all speech except blasphemy is protected.
Murder is another one. Killing someone on purpose is murder, short of self-defense or actual war.
I think net neutrality is sufficiently easy to define that if we can get any law right, it should be this one. ISPs should transfer all packets to where they are addressed, with no preference given to one packet over another -- except for a specific customer, at their explicit request (if I ask for a spamfilter, they may intercept port 25.)
Granted, telcos may subvert the process, but I'd rather at least try than have no legislation at all.
Don't thank God, thank a doctor!
No, it's named properly. CAN-SPAM. As in CAN-THEREFORE-I-WILL. SPAM.
I'm afraid that you have powerful motives in protecting spam, and keepiingi CAN-SPAM useless. We only need to look at your business, 'SuretyMail', as described at http://www.suretymail.com/. It's apparently a 'keep your business spam off the blacklists' set of tools. And most spammers simply don't care. They're quite willing to use throwaway accounts or stolen computer time to send their spam, and they've been doing it since the original Canter&Siegel spam.
You are apparently trying to protect your business from being caught by anti-spam legislation. A robust anti-spam law, such as a simple extension of the junk fax laws to cover spam, would probably destroy your business because your legitimate customers would be forced to use opt-in and not face such blacklists. Most email 'accreditation' schemes such as yours are quickly infested by spammers who use it to pretend legitimacy, whether by buying your services or by simply stealing access from people like your customers. It's the same flaw suffered by various 'micropayment' email schemes, and by Microsoft's SenderID program.
Do you see some flaw in my analysis?
It should be, but unfortunately that's not the case in today's world. What is your proposed alternative? One that doesn't require the recipient to be online at all times? I like IM systems for transferring files and chatting. What method can you use to eliminate spam unless you don't actually have a built in method of requesting to be added to a white list - so you could just phone up the recipient instead letting them know your username. Even then if you have a phone you're still getting hit by advertising drones all day. And you can't just say "don't send through any calls" because sometimes they are actually valid calls. I should probably make a whitelist of allowed companies or certain 'keywords' mentioned that mean reception can pass a call up to me..
which is totally what she said