The Imminent Demise of SORBS
An anonymous reader lets us know about the dire straits the SORBS anti-spam blacklist finds itself in. According to a notice posted on the top page, long-time host the University of Queensland has "decided not to honor their agreement with... SORBS and terminate the hosting contract." The post, signed "Michelle Sullivan (Previously known as Matthew Sullivan)," says that the project needs either to "find alternative hosting for a 42RU rack in the Brisbane area of Queensland Australia" or to find a buyer. Offers are solicited for the assets of SORBS as an ongoing anti-spam service — it's now handling over 30 billion DNS queries per day. An update to the post says "A number of offers have already been made, we are evaluating each on their own merits." Failing a successful resolution, SORBS will cease operations on July 20, 2009 at 12 noon Brisbane time. Such a shutdown could slow or disrupt anti-spam efforts for large numbers of mail hosts worldwide.
And before anyone starts to give me any guff about being soft on spam -
I've been known to nuke accounts, and not bother asking questions. I chased down the Empire Towers group and helped put an end to them. I spent 18 months cleaning up the -very- tarnished reputation of a now bought out web host almost 10 years ago, and have the scars to prove it. I hunted a spammer down and ratted him out to his own mother in Vancouver, BC, Canada.
The news regarding Ralsky had me drop a shot in celebration.
Believe me - I -detest- spam. At the same time, the methods utilized by SORBS were ineffective, and most legitimate hosts and providers stopped using them years ago.
Selective DNSRBL systems, as a practical method, WORK. Blocking residential cable from sending email? Hella good idea, for example. Blocking known dial-up ranges, as well. Blocking webhosts in an attempt to get their customer base to force them into canceling contracts that may cost the web host hundreds of thousands, if not millions of dollars? Nuh-uh.
When 'collateral damage' was useful, losses MIGHT have hit 10k. Now? Talking millions? Businesses will buy a new IP block and move the affected customers, and call it a day. Especially if they're blocked not because a customer has been an idiot, per se, but because the customer was hacked and used as a bot.
So, yeah. Rock on with your bad selves.
The -smart- people are doing precisely that.
The problem is that there really are still people out there who are using lists, such as SORBS, as absolute arbiters in what is, or is not, from a spam source.
Thankfully, this number is shrinking daily as they realize just how broken some of these lists have been as a matter of policy.
Any mail admin who's depending in any significant way on the anti-spam wasteland of SORBS should be on their way to apply for jobs at local fast food restaurants as soon as possible. Even if someone handling spam control for a decent size business actually believed in SORBS' accuracy or effectiveness, the only effect of SORBS disappearing from the face of the Earth should have is a slight uptick in spam being caught by filters slightly further down the path to their users' mailboxes.
Seriously, is there anyone out there who isn't use a multi-tiered, inter-connected array of spam filtering methods at this stage of the game? ~96% of the mail going to my users is spam. My worst offender has some ~5300 messages a day of spam being filtered prior to reaching their inbox. If my best filter were rendered worthless tomorrow, I wouldn't expect to hear any complaints from users. (of course, I'd be pretty unhappy.)
I think honeypots are probably my best weapon again spammers at the moment, followed by my keyword blacklists.
-- "Government is the great fiction through which everybody endeavors to live at the expense of everybody else."
A lot of people have had their lives turn into a living hell because of some listing on SORBS. Thus if it wasn't me who chewed you out, somebody else probably would have :-)
Spamhaus's PBL?* I filter on that... the friggen ISP's make up most of that list. I'm pretty damn sure AOL and friends filter off that list too and my motto is "if AOL or Yahoo filters mail based on XYZ policy, I will too". Plus, you can get off that list on a web page.
It is SORBS that I have an issue with. SORBS was created out of pure spite. So my apologies random internet person :-)
* Excepting Godaddy who is fucking insane. Those assholes filter *URL's pointing to a PBL'd IP that are embedded in a message*!!! Worse, they dont tell you. Had fun learning that.
In their words, "it's not extortion as *we* don't see any of the money." It's still bullshit.
I've had issue with them for many years... their "spamtrap" list is 100% untrustable. It only takes one email EVER to get on the list. They provide zero evidence of how you got on the list, just that you are on it. Enties never, ever, expire. And to get off the list... you have to "make a donation." (But if you're google, you get removed without ever knowing you were listed.)
The reason SORBS is so universally reviled by a lot of the anti-spam crowd is because the creator and the whole cadre of folks that maintained (and I use that word hesitantly) really didn't seem nearly as interested in battling spam as in enforcing their own bizarre view of who should and should not be sending email. The entire ethos was abusive and ego-stroking. The last time I had problems, the one thing I noticed that was different than my old battles with this pack of scumbags was just how few mail servers seem to be using it now. Hotmail was what forced me to even bother dealing with it, because my employer does a lot of correspondence with people on Hotmail addresses (another cancer on SMTP). My general attitude about mail admins who reject messages because SORBS blacklists my IP address is "fuck you", because those admins, as I've said elsewhere, are either morons or just lazy and don't want to put the effort into building a good, solid, rugged SMTP server.
What I can't believe is that SORBS still has some defenders, when my experience from the years when I was working most of my days as an admin for a few hundred domains was that SORBS was just as bad as spam. I really do hope that it is allowed to die, and maybe a few more retarded mail admins finally get the hint and start implementing measures that don't essentially poison SMTP.
The world's burning. Moped Jesus spotted on I50. Details at 11.
SourceForge isn't the sister company, SourceForge is Slashdot's owner. The PARENT company.
But I think it's only listed because Sorbs has a project on sourceforge.net, in which case Sourceforge "sponsors" eleventy bajillion people and companies anyway.
For a site about things like basic rights, Slashdot users sure do like to censor "dissent".