US Web Firm Described As "Phantom Registrar" Haven
snydeq writes "InfoWorld's Martin Heller directs attention to ongoing investigations of more than 40 phantom registrars linked to The Directi Group, including PDR, one of the 10 worst offenders on the Net. According to KnujOn, an additional 19,000 domains advertised through spam have been hiding their ownership behind PrivacyProtect.org, which The Washington Post has outed as Directi-owned. Directi claims it suspends illicit domains, but KnujOn provides documentation suggesting that Directi reports the registrars suspended and then reinstates them at another IP address. 'There has been some outcry about all this from the ICANN At-Large Committee, but as of this writing there has been no response from ICANN's Tim Cole,' Heller writers. 'Perhaps that has something to do with the fact that LogicBoxes, a Directi-owned registrar, has sponsored ICANN meetings in L.A. and Delhi.' Directi has since issued an official response to the allegations."
Quite simply, even if they shut Directi down, another company will take over the job of hiding the spammers for one simple reason: money. The spammers can afford to pay a company to hide them because they are making bank. Amazingly, about 1% of all spam emails actually result in a sale! So if you send out 1,000,000 emails, you can expect 10,000 sales! If people would just stop buying shit from spam emails, this wouldn't be a problem.
Now on the other hand, why do we even bother to try to pass spamming laws? Talk about another waste of time and money. If we pass a law saying all spam email must contain the words "unsolicited email" in the subject line, everyone will set their servers to block such email and therefore the spammers will certainly not put that in the subject line. So now we have to spend even more money to try and track the spammers down, which in essence we can't do because they pay companies like Directi money to hide their domains, IPs, etc.
Bottom line, this is an endless loop, and if anyone has any REAL suggestions on how to get rid of spammers, or how to force companies to stop hiding them and their domains, I'd love to hear it.
Make sending unsolicited mail slightly criminal. Say, one minute in prison per recipient. 1M spams would be 695 days in jail.
Spam and viruses cost people money that they could have spent elsewhere. When a company buys a spam filter and hires people to run it, that's money that could have been profit or could have been spent on something useful to the company. Maybe that budget could go to making the health insurance a bit cheaper. Or give the receptionists a raise. Put a foosball table in the break room. 1K$/year is 1K$/year too much to spend on something you never wanted. Spammers are making people/companies/agencies throw away time and money. The only way to not get spam is to not have an address.
Hell, make it the penalty the sum of the amount other peoples time they wasted, 1 second per recipient. Even that would get people to think twice.
Alas, the spam from outside the US and extradition friendly countries would not be unabated, but it would be something.
Maybe such a law would be wrong/unethical, but it would give us some kind of satisfaction. i don't know, i'm speaking mostly out of frustration here. When i was a sys admin dealing with spam was a frustrating waste of my time and the time of my users.
Any law grokkers on hand to tell us what laws and penalties are in place?
Utilizing the synergization of benchmark e-solutions to pre-workaround action items!
On a related note, Spamhaus recently issued this statement about Atrivo/Intercage, US-based persistent criminal spammer hosts. In the news.admin.net-abuse.email newsgroup, Steve Linford of Spamhaus indicated they made this statement because they are highly frustrated with law enforcement's inaction.
Al Capone was prosecuted and imprisoned because he failed to pay his taxes. Use the same tactic on spammers. Subpoena the customer list of these registrars under conspiracy to avoid taxation. Then audit the taxes of all the domain owners.
These types of registrars and domain owners will no longer have a viable business if the expense of avoiding the government is too high. This would also be a useful method of giving lawyers something to do and stop bothering us normal people (with NewYorkCountryLawyer as an exception of course).
Every mans' island needs an ocean; choose your ocean carefully.
I've been doing some digging into this over the last few months and noticed an awful lot of spamvertized sites seem to have their domains registered with such privacy protecting registrars.
I've been thinking about how to use the fact that a domain is registered with such a registrar as part of a spam scoring metric and whether anyone else has already done work on this? Just on the mail passing through my systems, I'm seeing a very strong correlation between a mail being spam and it referring to a domain registered with such a registrar, with the domain nameservers being on dynamic IP space, and with the DNS for the spam domain having a very low TTL value set.
It's also interesting to track back the nameservers for any domains referred to in the NS records of the spam domain. By doing so I can find fairly large networks of interrelated spam domains and spam websites, the addresses of many of which already appear on the likes of the Spamcop and Spamhaus SBL/XBL lists or appear there shortly afterwards.
The point is, is it practical to use this sort of information against spammers and is anyone already doing it?
Apparently, Bhavin Turakhia Founder, CEO & Chairman of Directi "...also serves as a technical advisor to the local CyberCrime Investigation Cell" it says on the Directi website.
Ha Ha Ha Ha Ha Ha! Sometimes you can't beat real life for a great laugh.
Hold on, it also says,"Directi operates various online web properties and web services. To report any form of abuse activity (spam, phishing, adware etc) with respect to any Directi service simply send an email to abuse [at] directi [dot] com"
Argh, ha ha, oh dear, oh dear, I think I'll never stop laughing...
In the Directi response, "# The report claims that âoe48 ICANN-accredited Registrars (affiliated with Directi) ⦠do not seem to exist and are phantom.â
This statement is factually incorrect, and was completely unverified by Knujon. Knujon did not even bother to contact ICANN in this regards to get the right facts. The truth of the matter is that all 48 companies which belong to Directi and its clients, are in existence and are duly incorporated and validly existing under law."
IANAL, but I don't think phantom corporations are illegal in the USA. There seems to be plenty of corporations that exist only as a name on a piece of paper. So, yes, given this, they are right in saying that they validly exist. That does not address the fact that the companies may in fact be phantoms and appear to be a rather inappropriate way of doing business.
Bearded Dragon
goes to show EVEN ICANN can be bought
I was getting a lot of spam which had links redirecting to this scam site. It was one of those sites that does a fake virus scan and claims you're infected so they can sell you a bogus product (funny how it was scanning windows-related files on my Linux system, eh).
I sent the offending URL to privacyprotect and was surprised when they actually responded by pulling the spammer's protection, then forwarding the info to his ISP and having the domain itself pulled (the nameserver has been changed to "ns1.suspended-domain.com" and DNS no longer resolves).
WordNet defines "terrorism" as (emphasis mine::
Belonging to a terrorist organization makes one a terrorist too, even if one is not (unlike Ayers) directly involved in any actual terrorism — take Hassan Nasrallah, for example.
Although per the definition above, simply threatening violence to attain certain goals is terrorism, Ayers' organization were planning to blow up an Army NCO club next. Fortunately for most concerned, they blew themselves up instead — the organization changed strategy to try to avoid casualties after this incident... But were also armed robberies (with fatalities) — a revolution always needs cash... (Interestingly, Joseph Stalin's first job in the Communist Party was to "rob the robbers" — what do the owners of "Democracy Now!" have in store for us?).
Just take Ayers' own words, spoken not during an interrogation, and not decades ago, but to the media this year: "I don't regret setting bombs, I feel we didn't do enough."
Whether he actually killed anyone is not relevant to his being a terrorist — only to an additional charge of murder, which, according to his "memoir" he may also have committed, but nobody knows for sure: "''Is this, then, the truth?,'' he writes. ''Not exactly. Although it feels entirely honest to me.''"
But his organization's ideology, as summarized by him back then was: "Kill all the rich people. Break up their cars and apartments. Bring the revolution home, kill your parents, that's where it's really at."
Back to my original point — although the scumbag's guilt is undeniable (and, indeed, not denied), he avoided any punishment, because of government misconduct in collecting evidence against them...
So, yes, Ayers was a member of a terrorist and otherwise criminal organization, and a terrorist himself — committed to this day to terrorism...
In Soviet Washington the swamp drains you.
Your post advocates a
( ) technical ( ) legislative (x) market-based ( ) vigilante
approach to fighting spam. Your idea will not work. Here is why it won't work. (One or more of the following may apply to your particular idea, and it may have other flaws which used to vary from state to state before a bad federal law was passed.)
( ) Spammers can easily use it to harvest email addresses
(x) Mailing lists and other legitimate email uses would be affected
( ) No one will be able to find the guy or collect the money
( ) It is defenseless against brute force attacks
( ) It will stop spam for two weeks and then we'll be stuck with it
( ) Users of email will not put up with it
( ) Microsoft will not put up with it
( ) The police will not put up with it
( ) Requires too much cooperation from spammers
( ) Requires immediate total cooperation from everybody at once
( ) Many email users cannot afford to lose business or alienate potential employers
( ) Spammers don't care about invalid addresses in their lists
(x) Anyone could anonymously destroy anyone else's career or business
Specifically, your plan fails to account for
( ) Laws expressly prohibiting it
( ) Lack of centrally controlling authority for email
(x) Open relays in foreign countries
( ) Ease of searching tiny alphanumeric address space of all email addresses
(x) Asshats
(x) Jurisdictional problems
( ) Unpopularity of weird new taxes
( ) Public reluctance to accept weird new forms of money
( ) Huge existing software investment in SMTP
( ) Susceptibility of protocols other than SMTP to attack
( ) Willingness of users to install OS patches received by email
(x) Armies of worm riddled broadband-connected Windows boxes
( ) Eternal arms race involved in all filtering approaches
(x) Extreme profitability of spam
(x) Joe jobs and/or identity theft
(x) Technically illiterate politicians
(x) Extreme stupidity on the part of people who do business with spammers
(x) Dishonesty on the part of spammers themselves
( ) Bandwidth costs that are unaffected by client filtering
( ) Outlook
and the following philosophical objections may also apply:
(x) Ideas similar to yours are easy to come up with, yet none have ever
been shown practical
( ) Any scheme based on opt-out is unacceptable
( ) SMTP headers should not be the subject of legislation
( ) Blacklists suck
( ) Whitelists suck
( ) We should be able to talk about Viagra without being censored
( ) Countermeasures should not involve wire fraud or credit card fraud
( ) Countermeasures should not involve sabotage of public networks
( ) Countermeasures must work if phased in gradually
( ) Sending email should be free
( ) Why should we have to trust you and your servers?
( ) Incompatiblity with open source or open source licenses
( ) Feel-good measures do nothing to solve the problem
( ) Temporary/one-time email addresses are cumbersome
( ) I don't want the government reading my email
( ) Killing them that way is not slow and painful enough
Furthermore, this is what I think about you:
( ) Sorry dude, but I don't think it would work.
(x) This is a stupid idea, and you're a stupid person for suggesting it.
( ) Nice try, assh0le! I'm going to find out where you live and burn your
house down!
APK quotes people (including myself) without context and should not be trusted. Just thought you should know.