Slashdot Mirror


New Opt-Out Clause Makes CAN-SPAM Worse

snydeq writes "Three years of mulling, and the FTC has made the CAN-SPAM Act worse, writes Gripe Line's Ed Foster. Chief among the offenses in the FTC's updated rules is an even worse approach to opt-out procedures. In the future, in scenarios where multiple marketers use a single email message to spam you, 'only one of the senders — the one in the From: field — need be designated the official sender who is responsible for honoring opt-outs,' Foster writes. Translation? 'Other "marketers" who used that spam message, not to mention the spamming service that actually provided the email address list, don't need to honor opt-outs. So try as you might to get yourself off a list, the real spammer can just keep changing the designated sender in the From: field and legally keep on spamming you.' The irony of the CAN-SPAM moniker gets thicker."

37 of 119 comments (clear)

  1. Irony? by Krishnoid · · Score: 5, Funny

    At least the accuracy of the moniker is increasing. Better than PATRIOT act, digital rights management, etc.

  2. Wrong Name for the Act. by featheredfrog · · Score: 5, Funny

    They should have named it "MAY-SPAM"

    1. Re:Wrong Name for the Act. by hairyfeet · · Score: 2, Funny

      icanhazspam? Maybe folks wouldn't be so pissed at getting it if they had that cute fat grey cat as a mascot. Then they would be like "I don't want any v1agr@! But isn't that kitty cute!" But that is my 02c,YMMV

      --
      ACs don't waste your time replying, your posts are never seen by me.
    2. Re:Wrong Name for the Act. by archont · · Score: 3, Insightful

      No, it's named properly. CAN-SPAM. As in CAN-THEREFORE-I-WILL. SPAM.

  3. Genius by MosesJones · · Score: 4, Interesting

    Come on folks you've got to admire sheer dumb ass brilliance of this level. This isn't a matter of minor incompetence this is world class stupidity. Checking my SPAM folder at the moment I picked out a few that looked similar and everyone had a different email address

    So in other words this brilliant change in the rules now means that SPAM isn't SPAM. Maybe that is the real way to get rid of it... just define that it doesn't exist.

    There is no poverty in North Korea either apparently.

    --
    An Eye for an Eye will make the whole world blind - Gandhi
    1. Re:Genius by mabhatter654 · · Score: 5, Insightful

      This is why established industries LOVE regulations! Once you have procedures in place to "follow" the regulation. Then the regulation becomes barrier to entry, or even a legal minefield, to those coming after.
      In this case unsolicited bulk email would be illegal if you didn't follow all these rules up front. But for the guys that already got the grace period to follow the law it's been twisted just enough to be meaningless!!!

      Power, telco, FCC, FAA, FDA, etc all those rule making agencies are run like this. It's just funny to see something so simple twisted so quickly. This is the same reason nobody wants internet neutrality put into law. Then any exceptions to blocking become "rules" that they "have" to block other content/providers... The telcos are already writing the rules the way they want with lots of backwards worded loopholes.

    2. Re:Genius by Anonymous Coward · · Score: 2, Insightful

      This is a failure to regulate effectively, not a place in which regulation necessarily fails. Regulation in itself isn't a bad thing, it just needs to be done by people who actually want to get something done.

  4. So now I can get offers from multiple Nigerieans by multi-flavor-geek · · Score: 5, Funny

    Just think I can have all kinds of people who had a dead uncle leave me millions of dollars in a Nepal lottery and now can't touch the money without offering me a job processing money orders for 50% of the take and a free bottle of Viagr14!!!!

    --
    Like arts? Like cheesy little Indie mags? Check out www.artwerkmag.com, and don't laugh at the bad coding please.
  5. Here's why, the Repug reasoning process: by aeschenkarnos · · Score: 4, Funny
    1. Money is good. Money is God's way of showing who he likes, and who he doesn't. (Except for George Soros.)

    2. Things that are done for money are good. Corollary: people wouldn't do good things but for being given money. Well, we wouldn't, and we have no problem extrapolating to everybody.

    3. Spamming is done for money.

    4. Therefore spamming is good.

    1. Re:Here's why, the Repug reasoning process: by Anonymous Coward · · Score: 2, Funny

      I disagree with premis 2. I affirm that there exist things done for money which are not good. I will give examples:

      Vendor lock-in agreements.
      Frivilous lawsuits.
      Identity theft.
      Murder.
      Marriage.

    2. Re:Here's why, the Repug reasoning process: by Gregb05 · · Score: 4, Funny

      There are people that would say that all but one of those is a good thing.

      I mean, what kind of sick monster would wish Marriage on anyone?

      --
      --
  6. Can't render it any more impotent by pla · · Score: 4, Insightful

    Other "marketers" who used that spam message, not to mention the spamming service that actually provided the email address list, don't need to honor opt-outs

    Damn! I guess this means an end to the three wonderful years of relief we've all enjoyed from spam thanks to the oh-so-effective initial rules.


    Seriously, this change really doesn't matter, except it will let the FTC claim success due to a massive drop in the number of "valid" complaints against spammers. Whining that it weakens the existing law strikes me as similar to complaining that a serial killer violated a restraining order.

  7. If the government won't stop them... by TihSon · · Score: 2, Insightful

    I fully expect within the next few years we will see average Joe hacker ... as in a person who likes to fool with technology ... begin a personal and secret computer assault against any business or organization who uses the services of spammers.

    In other words, if those in power won't protect me, why should I feel I am doing anything wrong to try and protect myself?

    If using the services of a spammer gets your network shot down with any sort of reliable regularity, it seems logical that using them is going to become a harder and harder decision to justify. Make 40G's using the spammer, spend 37G's fixing the network damage that follows.

    In the long run, I see this fight as one that cannot go any other way.

    --
    In B.C., our fascism is green.
  8. I'm impressed, in a way by damn_registrars · · Score: 5, Insightful

    It seems that they managed to take a completely toothless act, and make it even less helpful.

    I guess it is no wonder that congress has managed to somehow attain an even lower approval rating than our current commander-in-chief, seeing as they managed to squirt out something like this instead of dealing with important national issues.

    --
    Damn_registrars has no butt-hole. Damn_registrars has no use for a butt-hole.
    1. Re:I'm impressed, in a way by AndroidCat · · Score: 2, Funny

      It must have taken a lot of long hard work to make CAN-SPAM even more useless. Ha ha ha, and they said that it couldn't be done!

      --
      One line blog. I hear that they're called Twitters now.
  9. I don't see why this is all such a problem. by Rival · · Score: 3, Interesting

    This can work. After all, most spammers comply with the rest of the act and are legitimate, honest and upright business owners, right?

    I mean, such good people would surely include a visible and operable unsubscribe mechanism, honored quickly and used only for compliance purposes.

    And they would provide relevant subject lines, legitimate physical addresses, and adult-content labels on their "value-added, pre-solicited sales invitation messages."

    And, of course, never falsify header information, use open relays, or send messages to a harvested email address. Right?

    Seriously, what are they really hoping to accomplish with this act? Has it done any significant good?

    1. Re:I don't see why this is all such a problem. by vux984 · · Score: 5, Informative

      This can work. After all, most spammers comply with the rest of the act and are legitimate, honest and upright business owners, right?

      Your being sarcastic, but you are more right than you think.

      The CAN SPAM act isn't REALLY directed at the "Get V1-a--g-ri-alis". Those guys don't provide any sort of optout anyway. The CAN-SPAM act really just regulates legitimate newsletters and their behaviour, and this little tweak makes life a little easier for them.

      The idea here if I read it right, seems to be that if I send out legitimate newsletter and company-X advertises in it, and then you opt out of my newsletter, under the old can-spam rules if company-X advertises in another newsletter that you receive, you could complain that you opted out, and charge them with spamming... which is really a bit absurd. Its like cancelling your subscription to forbes and then being offended the same ads for Lexus showed up in your subscription to Times!

      As you observed the "real" spammers don't give a crap about CANSPAM. This doesn't affect them, because CANSPAM never really affected them. So opening this 'loophole' is primarily about making it easier for legitimate newsletters to operate.

  10. More Proof That Lawmakers Don't Understand Tech by HardCaliber · · Score: 5, Funny

    Who do these lawmakers use as expert advisors on technical issues? Members of the Geek Squad that worked for Best Buy for a month, before being let go?

    1. Re:More Proof That Lawmakers Don't Understand Tech by kat_skan · · Score: 4, Insightful

      Who do these lawmakers use as expert advisors on technical issues?

      Anybody who makes a sufficiently large contribution to their campaign, apparently.

    2. Re:More Proof That Lawmakers Don't Understand Tech by Mr.+Beatdown · · Score: 2

      Se. Stevens catches a lot of flack, but that's the wrong part of his idiotic tirade againt commercial use of the Internet.

      The part you wanted was "I just the other day got, an internet was sent by my staff at 10 o'clock in the morning on Friday and I just got it yesterday. Why?"

      We have been describing the Internet as a series of tubes which we connect fat pipes to for a long time, because that analogy makes sense. Sen. Stevens, on the other hand, doesn't.

      --
      My fellow Americans, let's restore the death penalty for child rapists. Let's do it . . . for the children.
  11. SPAMMERS WRITE CAN-SPAM ACT by Anonymous Coward · · Score: 2, Insightful

    Steve Richter, father and lawyer to "SPAM KING" Scott Richter helped write the CAN-SPAM act. The act is a joke.

    1. Re:SPAMMERS WRITE CAN-SPAM ACT by Kozar_The_Malignant · · Score: 4, Informative

      Links please.

      Here's a press release about his affiliation with his son's company. Here is a speaker bio of Steven Richter, and here is the Wikipedia entry confirming the statements in the GP post. While I agree that it is nice to document one's assertions, it is pretty easy to fact check stuff like this.

      --
      Some mornings it's hardly worth chewing through the restraints to get out of bed.
  12. You Have this Completely Wrong by Talaria · · Score: 5, Informative
    You have this completely wrong, although this is *such* a confusing clause, that nobody could blame you.

    First let me qualify by saying that I am not only a lawyer in the Internet and anti-spam industry, but I helped author the "affiliate spam" section of CAN-SPAM, to which this clause is a natural extension. We are also fresh from a teleseminar which we provided on this very subject.

    The following is an excerpt from our CAN-SPAM compliance page, which is at http://www.isipp.com/can-spam.php:

    In large part, this requirement is an effort to hold affiliate programs responsible for how their affiliates promote them. If the affiliate is honest about who they are, and their "From address", and if they put something in the email about themselves, then the user will be able to unsubscribe from the affiliate's list. But if the affiliate is dishonest, and hides their true identity, then the affiliate program for the product featured in the email (which will be the product being sold under the affiliate program) becomes responsible. In other words, if you are advertised in the affiliate's email, and the affiliate cloaks who they are, you become responsible. By shifting responsiblity for mislabled email to the companies being advertised in the email, there is an incentive for affiliate program managers to more tightly police their affiliates.

    Anne P. Mitchell, Esq.
    CEO/President
    Institute for Spam and Internet Public Policy
    http://www.isipp.com/

    1. Re:You Have this Completely Wrong by joocemann · · Score: 3, Insightful

      Cool, then can you please make it so spam is an OPT-IN thing instead of OPT-OUT?

      As it stands, the majority of people who receive the 'opt-out' spam DO NOT WANT IT, which makes the solution obvious: Change the system to Opt-In. That way, those of us who want something from someone, get it, and those whose spam is unsolicited can be prosecuted.

      It is ridiculous that something so problematic to day-to-day functions is treated as OPT-OUT. If you're a policy maker, how do you justify that aspect of the policy?

    2. Re:You Have this Completely Wrong by Antique+Geekmeister · · Score: 2, Insightful

      I'm afraid that you have powerful motives in protecting spam, and keepiingi CAN-SPAM useless. We only need to look at your business, 'SuretyMail', as described at http://www.suretymail.com/. It's apparently a 'keep your business spam off the blacklists' set of tools. And most spammers simply don't care. They're quite willing to use throwaway accounts or stolen computer time to send their spam, and they've been doing it since the original Canter&Siegel spam.

      You are apparently trying to protect your business from being caught by anti-spam legislation. A robust anti-spam law, such as a simple extension of the junk fax laws to cover spam, would probably destroy your business because your legitimate customers would be forced to use opt-in and not face such blacklists. Most email 'accreditation' schemes such as yours are quickly infested by spammers who use it to pretend legitimacy, whether by buying your services or by simply stealing access from people like your customers. It's the same flaw suffered by various 'micropayment' email schemes, and by Microsoft's SenderID program.

      Do you see some flaw in my analysis?

  13. There is only one solution: by Lilith's+Heart-shape · · Score: 2, Insightful

    Find the spammers, and impale them. DEATH TO SPAMMERS!

  14. wow.. what a set up for a Joe Job... by way2trivial · · Score: 2, Interesting

    imagine if I obfuscate all my emails, but always mention an item avaialble from amazon.

    --
    every day http://en.wikipedia.org/wiki/Special:Random
  15. Re:whitelist by vbraga · · Score: 3, Insightful

    (Can we please drop SMTP already? Just looking at my inbox is vomit-inducing.) Pardon me for my ignorance, but what are the viable alternatives for SMTP?
    --
    English is not my first language. Corrections and suggestions are welcome.
  16. Time for the form again by Kayamon · · Score: 5, Funny

    Your post advocates a

    ( ) technical (X) legislative ( ) market-based ( ) vigilante

    approach to fighting spam. Your idea will not work. Here is why it won't work. (One or more of the following may apply to your particular idea, and it may have other flaws which used to vary from state to state before a bad federal law was passed.)

    (X) Spammers can easily use it to harvest email addresses
    ( ) Mailing lists and other legitimate email uses would be affected
    ( ) No one will be able to find the guy or collect the money
    ( ) It is defenseless against brute force attacks
    ( ) It will stop spam for two weeks and then we'll be stuck with it
    ( ) Users of email will not put up with it
    ( ) Microsoft will not put up with it
    ( ) The police will not put up with it
    (X) Requires too much cooperation from spammers
    ( ) Requires immediate total cooperation from everybody at once
    ( ) Many email users cannot afford to lose business or alienate potential employers
    ( ) Spammers don't care about invalid addresses in their lists
    ( ) Anyone could anonymously destroy anyone else's career or business

    Specifically, your plan fails to account for

    ( ) Laws expressly prohibiting it
    ( ) Lack of centrally controlling authority for email
    ( ) Open relays in foreign countries
    ( ) Ease of searching tiny alphanumeric address space of all email addresses
    (X) Asshats
    ( ) Jurisdictional problems
    ( ) Unpopularity of weird new taxes
    ( ) Public reluctance to accept weird new forms of money
    ( ) Huge existing software investment in SMTP
    ( ) Susceptibility of protocols other than SMTP to attack
    ( ) Willingness of users to install OS patches received by email
    ( ) Armies of worm riddled broadband-connected Windows boxes
    (X) Eternal arms race involved in all filtering approaches
    (X) Extreme profitability of spam
    ( ) Joe jobs and/or identity theft
    (X) Technically illiterate politicians
    ( ) Extreme stupidity on the part of people who do business with spammers
    (X) Dishonesty on the part of spammers themselves
    ( ) Bandwidth costs that are unaffected by client filtering
    ( ) Outlook

    and the following philosophical objections may also apply:

    ( ) Ideas similar to yours are easy to come up with, yet none have ever
    been shown practical
    (X) Any scheme based on opt-out is unacceptable
    ( ) SMTP headers should not be the subject of legislation
    ( ) Blacklists suck
    ( ) Whitelists suck
    ( ) We should be able to talk about Viagra without being censored
    ( ) Countermeasures should not involve wire fraud or credit card fraud
    ( ) Countermeasures should not involve sabotage of public networks
    ( ) Countermeasures must work if phased in gradually
    ( ) Sending email should be free
    ( ) Why should we have to trust you and your servers?
    ( ) Incompatiblity with open source or open source licenses
    ( ) Feel-good measures do nothing to solve the problem
    ( ) Temporary/one-time email addresses are cumbersome
    ( ) I don't want the government reading my email
    ( ) Killing them that way is not slow and painful enough

    Furthermore, this is what I think about you:

    ( ) Sorry dude, but I don't think it would work.
    (X) This is a stupid idea, and you're a stupid person for suggesting it.
    ( ) Nice try, assh0le! I'm going to find out where you live and burn your
    house down!

    --
    Kayamon
  17. Definition. by SanityInAnarchy · · Score: 3, Insightful

    Spam lacks sufficient definition. While there are certain things that most of us can agree are spam, there is a sufficiently large gray area that it's not really possible to define clearly as law.

    However, some things are absurdly easy to define -- take freedom of speech. You are allowed to say pretty much what you want, where you want, short of "Fire!" in a crowded theater. No one has yet found a way to twist the First Amendment into meaning something it doesn't -- into somehow meaning, for example, that all speech except blasphemy is protected.

    Murder is another one. Killing someone on purpose is murder, short of self-defense or actual war.

    I think net neutrality is sufficiently easy to define that if we can get any law right, it should be this one. ISPs should transfer all packets to where they are addressed, with no preference given to one packet over another -- except for a specific customer, at their explicit request (if I ask for a spamfilter, they may intercept port 25.)

    Granted, telcos may subvert the process, but I'd rather at least try than have no legislation at all.

    --
    Don't thank God, thank a doctor!
    1. Re:Definition. by thePowerOfGrayskull · · Score: 3, Insightful

      However, some things are absurdly easy to define -- take freedom of speech. You are allowed to say pretty much what you want, where you want, short of "Fire!" in a crowded theater. No one has yet found a way to twist the First Amendment into meaning something it doesn't -- into somehow meaning, for example, that all speech except blasphemy is protected. That's debatable; let's look at the text:

      Congress shall make no law respecting an establishment of religion, or prohibiting the free exercise thereof; or abridging the freedom of speech, or of the press; or the right of the people peaceably to assemble, and to petition the Government for a redress of grievances.

      Maybe I'm just too naive, but it seems to me that it's established such that: a) there would not be a new Church of England taking power in the US and that people can choose whatever religion they want b) people could criticize the goverment. c) people can protest when the government is being stupid. d) the press should be able to report on activities of the government without limitations.

      Yet somehow in the last couple hundred years, this has evolved to mean that anything anyone wants to say is fine. That freedom of the press means the press can invade peoples lives without permission or consequence. That people can smear shit on a painting, call it art, and have that considered "protected".

      Are you so sure that it hasn't been twisted? Because it's used now to protect a /lot/ more than it says it protects.

    2. Re:Definition. by Rary · · Score: 3, Insightful

      How do you translate "or abridging the freedom of speech" into "people could criticize the government"? It makes no mention of the government, except in the final point, "to petition the Government for a redress of grievances", which is a separate bullet point.

      In other words, the entirety of the Amendment, as it pertains to freedom of speech, is "Congress shall make no law abridging the freedom of speech". That's a pretty clear way of saying "the Government can't legally prevent you from saying anything -- period".

      Standard disclaimer applies: IANAANHIRTCIIEIJIIDYP (I Am Not An American, Nor Have I Read The Constitution In Its Entirety, I'm Just Interested In Discussing Your Point).

      --

      "You cannot simultaneously prevent and prepare for war." -- Albert Einstein

    3. Re:Definition. by SanityInAnarchy · · Score: 2, Insightful

      Are you so sure that it hasn't been twisted? Because it's used now to protect a /lot/ more than it says it protects. -1, Factually incorrect. Borrowing the other poster's phrasing, it pretty much exactly says "Congress shall make no law abridging the freedom of speech."

      Say what you will about historical context, but I very much doubt you can twist it (or untwist it, as you say?) to mean anything other than "The people can say whatever the fuck they want." Because that is pretty close to what it literally says.
      --
      Don't thank God, thank a doctor!
    4. Re:Definition. by MindlessAutomata · · Score: 2

      Yes, and not that I agree with HIS point, but you must look at context in order to establish meaning, at times; looking at things "literally" fails when definitions or meanings of terms shift or change.

      The second amendment is a prime example of this; read it in context of the times and the meanings of the words (regulate, militia) and it's definitely saying that the federal government cannot take your guns away.

    5. Re:Definition. by Anonymous+Brave+Guy · · Score: 2, Insightful

      Say what you will about historical context, but I very much doubt you can twist it (or untwist it, as you say?) to mean anything other than "The people can say whatever the fuck they want." Because that is pretty close to what it literally says.

      And yet the law recognises concepts such as defamation, certain types of intellectual property, incitement to commit certain crimes...

      Either all these laws are unconstitutional, or the free speech right isn't completely universal after all.

      I think there is a rational explanation for this apparent contradiction, which I've written about here before, but how do you reconcile these facts (assuming your previous comment was meant to be taken literally)?

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
    6. Re:Definition. by Tanktalus · · Score: 2, Insightful

      Omitting context ignores how language evolves over time. For example, the difference in meaning that "beg the question" has gone through from its original inception (indicating a circular argument) to its modern and common interpretation (raising a question - begging a question be asked).

      It also ignores how society evolves over time - socially, technologically, etc. For the press to invade the privacy of even the President was unheard of in their time. It was a given: that doesn't happen in polite society. Today, invading the privacy of any public figure is the given, even if it takes telephoto lenses to do. It seems obvious to me that the US's first amendment was contextually referring solely to political and religious speech - areas of concern at the time from the former English rule of the colonies.

  18. Re:email is dead. by somersault · · Score: 2, Insightful

    It should be, but unfortunately that's not the case in today's world. What is your proposed alternative? One that doesn't require the recipient to be online at all times? I like IM systems for transferring files and chatting. What method can you use to eliminate spam unless you don't actually have a built in method of requesting to be added to a white list - so you could just phone up the recipient instead letting them know your username. Even then if you have a phone you're still getting hit by advertising drones all day. And you can't just say "don't send through any calls" because sometimes they are actually valid calls. I should probably make a whitelist of allowed companies or certain 'keywords' mentioned that mean reception can pass a call up to me..

    --
    which is totally what she said