Slashdot Mirror


User: Just+some+bastard

Just+some+bastard's activity in the archive.

Stories
0
Comments
48
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 48

  1. AKA: HashCash on Novel Method for Universal Email Authentication · · Score: 1

    Hashcash isn't a viable solution once you have a couple of mailing lists, it'd hit legitimate senders harder than the botnet operators. Our current mail servers are a mix of dual 2.4GHz Xeons and older 1.2GHz PIII machines. Planned upgrades will see us cutting costs by consolidating servers on ESX. Meanwhile even todays lowend desktop machines are able to match our servers for compute and botnet operators have access to plenty of them.

  2. Re:Greylisting and SMTP TLS on Novel Method for Universal Email Authentication · · Score: 1

    We implemented greylisting. It is the answer.

    The answer is zombies retrying indefinitely? I have a "legitimate bulk mailer" who effectively tarpits himself by retrying every 4 mins for 5 days on 45x for each message. Multiply that by the amount of zombies out there - and welcome to DOS city! If botnet operators are going to give up because of greylists, is my "legitimate bulk emailer" going to monitor his mail queue or prune his address lists? These people are spammers, we already know they don't care.

    TLS won't stop the botnet operators either, modern desktop PCs are powerful enough to do the certificate exchange. It's our servers that would struggle with TLS and some (most?) SME servers are in fact NAT'd behind the dedicated IP.

  3. Re:Still barking up the wrong f'ing tree... on Novel Method for Universal Email Authentication · · Score: 1

    1. Implement Greylisting. Spammers don't retry

    Nearly all MTA software is configured to reattempt delivery. Now, thanks to greylisting even Zombies are beginning to retry on temporary failure. This sucks if (like me) you always thought greylisting was pointless but are rejecting clients for lack of forward resolvable rDNS.

  4. Re:Fails to account for SMTP farms... on Novel Method for Universal Email Authentication · · Score: 1

    I'm not sure I want that to automatically give the go-ahead so that anyone can send spam from "Need-Viagra@mydomain.com" and "refinance-your-house@mydomain.com", etc..., from those domains.

    SPF authorizes outbound mail servers for a domain, it doesn't authenticate anything. Preventing cross user forgery is a matter of policy for 3rd party relay providers, there's nothing schemes like SPF can do about it.

  5. FUSSP on Novel Method for Universal Email Authentication · · Score: 4, Insightful
    Basically this guy is proposing an automated whitelist (for domains without SPF records) via a local database. At least I think what the paper is about, I gave up reading it earlier. It lacks a concise summary, doesn't read like a well researched paper and the diagrams don't even display without javascript.

    The author may be an anti-spam kook but the paper is so badly written I can't be bothered identifying which.

  6. Re:Development on Is Apple Doing All It Can to Beat Vista? · · Score: 1

    I wouldn't call BT a rich client app

    No but it is the widest known example (use rtorrent myself), there's also skencil and a multitrack recording app using gstreamer. I should also add that Microsoft seem to agree we'll be seeing more of these apps if their work on the DLR is anything to go by.

    You have a really good point about advertising though. Microsoft have a scorched earth style ad campaign for their dev tools. They even worked to counter the possibility that windows devs would be exposed to open source tools by creating their own me-too shared/open source community sites. I'm not at all sure how the Microsoft advertising spend could be countered in a way that'd appeal to the Microsoft faithful.

  7. Re:Development on Is Apple Doing All It Can to Beat Vista? · · Score: 1

    Both languages may have been established, but even today you don't see many "rich client" applications using either language

    Except the official bit-torrent client etc..? I suspect we'll be seeing more as powerful multi-core machines become commonplace.

    Java apps feel sluggish

    Java is cross platform, naturally it's going to be slower than .NET. Performance is at least comparable and it's perfectly possible to write bloated, poorly performing code in C/C++ (hello acrobat reader).

    the OP is an example of how well entrenched MS languages are with many developers.

    That's kind of the point I was making. Not just that the MSDN mentality is entrenched, that Microsoft devs are often woefully ignorant of the alternatives. "developers, developers, developers" was afterall about getting developers to target Microsoft platforms exclusively. Terrifying concept :-(

  8. Re:Development on Is Apple Doing All It Can to Beat Vista? · · Score: 1

    Microsoft has secured a very strong foothold in the programming world. Using the .net framework, you can create powerful, attractive, large applications very rapidly.

    Oh come on! Java and python and were already well established when .NET was vaporware.

    While, it hasn't taken hold so much in the gaming development world, xna and directx 10 may change this.

    More Microsoft proprietary technologies? The problem here is your mindset and nothing else.

  9. Re:Open Office Allows Free PDF Generation! on Word 2007 Vs. Open Office 2.3 Writer · · Score: 1

    OO.org may have rasterized the text, can you zoom in and see if the OO.org PDF pixelates?

  10. Re:Open Office Allows Free PDF Generation! on Word 2007 Vs. Open Office 2.3 Writer · · Score: 2, Insightful

    Any application can print to postscript using good old lpd, ps2pdf does the rest. If you're on Windows you can install PDFCreator and again, print to PDF from any app.

    Once a month my consulting invoices are output as PDFs using enscript, a tiny shell script pulls the data from sqlite (previously Berkeley DB), converts to PDF and emails the client.

    Is having a save as PDF button really a big deal?

  11. As seen on phonejacker on Music Industry Set To Introduce the "Ringle" · · Score: 1

    Free ring-ding?

  12. Irony on Vista Pirates To Get "Black Screen of Darkness" · · Score: 5, Funny

    anyone who has a pirated copy of Vista will experience:

    A black screen after one hour of browsing
    No start menu or task bar
    No desktop

    Vista may actually be usable like that. Why aren't Microsoft sharing this upgrade with their paying customers?
  13. Re:Follow the money on Storm Worm More Powerful Than Top Supercomputers · · Score: 1

    If they performed proper authentication, then you could be sure to send your bounce messages to the person actually responsible for the spam.
    spam is rarely relayed, it's coming directly from infected customer machines with a forged return path.
  14. Re:Follow the money on Storm Worm More Powerful Than Top Supercomputers · · Score: 1

    Perhaps now is a good time to push for better adoption of SPF


    That just forces the spammers to register short lived domains. We need registrars to start validating registrant details, then it really is game over for the spammers.

    The current answer is to reject connections to a mail server if the connecting host lacks a forward resolvable RDNS, has a bad (non FQDN / your domain) helo string or is a known dynamic IP. Unfortunately, once you begin doing this you also have to manually whitelist the occasional site who are incapable of configuring DNS for their outbound servers correctly. My users don't see any storm emails and the only place I see storm is in the server logs.

  15. Re:Miguel must be happy today on Silverlight Released, Linux Version Coming · · Score: 2, Interesting

    I hope to see more collaborations between Microsoft and the Linux community in the future, not limited to Mono, but going beyond that.

    Beyond that into more threats of patent litigation, more ghost lawsuits, more FUD and even more heavy handed lobbying? Here's what I hope to see; Microsoft competing in the market without abusing its monopoly position (Re Java, flash, pdf ...).

    Most of us get Microsoft loud and clear, how strange that you do not.

  16. Vatican history on Will the Pope Declare Google Evil? · · Score: 0, Flamebait

    I'll have to watch the popes speech so I can laugh at the hypocrisy.

  17. Re:A contrarian view on Adobe May Launch Office Rival · · Score: 1

    MS Office will always win as long as the standard document format is *.doc (or the new equivalent).

    That's what I mean, you don't change the de-facto file format of a monopoly by supporting it.

    If the document standard can be changed to an open one, then whether it's the next day or the next year, MS Office is history because the product itself is just not that good technically.

    +1

  18. A contrarian view on Adobe May Launch Office Rival · · Score: 1

    I hope they don't support .doc or blob-in-XML. That would really dint Microsoft format lock-in, even with a moderate user base.

  19. Re:A day? For an email? While you're in the office on British Report Details the Stress of Email Communication · · Score: 1

    A bigger question is: Who polls their email client at work anymore?


    Guilty, I use pine and miss or ignore delivery notices. Not just if I'm away from my desk, also if I have the (xfce) terminal minimized or I'm working in an alternate tab.

    Admittedly, I'm not the typical user; I'd prefer to use telnet than a so-called 'modern client'.

  20. Confusing story on Judge Orders TorrentSpy to Turn Over RAM · · Score: 1

    The issue appears to be that a dump of the servers physical RAM would contain connected IP addresses. Removing the addresses from a RAM dump would be much more complex than removing or obscuring such data in a system log file. TFA is gibberish.

  21. Re:I'm not surprised on ISPs Starting To Charge for 'Guaranteed' Email Delivery · · Score: 1

    there really isn't any filtering that can be done on reverse DNS without MASSIVE false-positives.

    Anything below res.rr.com or adsl.tpnet.pl [east|dsl-w|fios].verizon.net (for example) are residential dynamic IP allocations.

    Many, many valid businesses are running mailservers without rDNS or with generic rDNS based on their IP number.

    And they can expect to have mail rejected until they find an admin who has enough of a clue to comply with widely praticed receiver policies.

    Also, manu valid servers send bogus names in their EHLO/HELO, including domain names ending in .local or servernames not present in external DNS.

    Which is wrong according to RFC2821:

    The domain name given in the EHLO command MUST BE either a primary
    host name (a domain name that resolves to an A RR) or, if the host
    has no name, an address literal as described in section 4.1.1.1.
    HTH.
  22. Re:Google already does this on ISPs Starting To Charge for 'Guaranteed' Email Delivery · · Score: 2, Informative

    Our machines are supposed to be able to connect to one another.
    An unfortunate side effect of zombies is that mail obviously sent using dynamic addresses is rejected. It's wrong to blame receivers for their policies, the blame lies with botnet operators and users who fail to take adequate security precautions. Neither can you expect receivers to whitelist dynamic addresses, the solutions are:
    1. Relay through your providers smarthost
    2. Get a static IP
    3. Get a VPS and relay through that
    It sucks much less than expecting receivers to accept spam.
  23. Re:I'm not surprised on ISPs Starting To Charge for 'Guaranteed' Email Delivery · · Score: 2, Informative

    If you are running a simple SMTP server on a cheap DSL or cable connection, chances are your reverse DNS lookup isn't going to match your intended host name.

    If you're running an MTA on a cheap connection you need to use your ISP's smarthost, mail that appears to come from dynamic addresses is increasingly rejected due to zombies.

    Matching forward & reverse DNS (and sometimes helo) is an additional requirement for delivery to certain servers.