Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

Wednesday, 25 May 2011

Is Email Dead? Or Just Pinin’ for the Fjords?

  (HP Input Output)

No, email’s neither dead, deceased, nor demised. But neither is it, as Monty Python’s Michael Palin would have said, homesick for the geographical features of its native Norway. You don’t need me to tell you that email is alive and well inside your organization. Beautiful plumage.

But some would say it’s too alive. In many organizations, email is used as a dumping ground for information that doesn’t belong there; email can also be used for certain collaborative tasks for which it’s simply not suited.

Read more...

Tuesday, 24 May 2011

Everything You Know about Spam Filters is Wrong

  (HP Input Output)

Filtering spam email is all about looking in the content of the message, trying to find certain dodgy words or phrases, right? Well... no. Not so much. While that was certainly true in the email Dark Ages of ten years ago, today’s filters are completely different.

Spam filters need to sift through your incoming email stream and automatically decide which are spam and which are legitimate—or ham. It’s a tremendously difficult job to get right; to reach today’s levels of filter accuracy, anti-spam technologists over the years have invested huge amounts of financial and intellectual capital.

To decode the mysteries, read on...

Tuesday, 15 February 2011

JCPenney's Google spamming: Don't let it happen to you

Richi Jennings's picture   The Long View (Computerworld)

You may have seen the news over the weekend that the uber-retailer JCPenney was slapped on the wrist by Google. It would appear that the store's been boosting its position in search results, via some nefarious practices. Could this happen to your employer? Yes! How can IT people help protect their marketing department from making a similar mistake? Find out in The Long View...

...Read more

Monday, 24 January 2011

Avoid huge CAN-SPAM fines, don't be like Virgin Blue

Richi Jennings's picture   The Long View (Computerworld)

Australian airline Virgin Blue was recently fined more than US$100,000 for spamming. What did it do? It failed to unsubscribe people who requested removal from the mailing list. How can you prevent it happening to you? Let's find out, in The Long View...

...Read more

Monday, 17 January 2011

Keep Your Newsletter out of Spam Traps

Richi Jennings's picture   The CMO Site

So you've put your newsletter together and submitted it to the email gods for delivery. But how many of those messages will actually make it through to people's inboxes? Let's talk deliverability.

Tuesday, 14 December 2010

Why not use same password everywhere? Gawker shows us.

Richi Jennings's picture   The Long View (Computerworld)

Gawker Media hack causes my friends to receive scammy begging email "from" me. Moral: don't forget about old email accounts when managing password risk.
The recent hack of Gawker Media's user database had a few people tsk-tsk'ing at that publication's security skills. Or lack of them. But that's just a pile of low-value blog comment accounts -- is there a greater worry we're missing? Are high-value enterprise accounts also at risk as a result? Here's a personal story of being hacked as a direct result of the Gawker compromise, in The Long View...

...Read more

Wednesday, 1 December 2010

Enterprise email: News of its death greatly exaggerated

Richi Jennings's picture   The Long View (Computerworld)

Email is dying, say the pundits. It's being replaced by social media and texting, they claim. Balderdash, say I. Email is alive and thriving in the enterprise. Even if Robert X. Cringely disagrees with me. See what I mean, in The Long View...

...Read more

Tuesday, 5 October 2010

Should ISPs cut off bot-infected users?

Richi Jennings's picture   The Long View (Computerworld)

Scissors (Ivy Dawned @ Flickr)There's no doubt that botnets are a major threat to the safety and stability of the internet -- not to mention the cleanliness of your inbox. After years of failure to act, could we finally be seeing ISPs waking up to their responsibilities? Let's take The Long View...

...Read more

Friday, 1 October 2010

Spam wars: the inbox is ground zero

Richi Jennings's picture   The Long View (Computerworld)

Spam! (freezelight@Flickr)In continuing this series about the war against spam, I want to address a concern raised by my Computerworld blogging colleague, David A. Milman. Experience tells him that -- despite advances in spam filtering -- SMB and consumer users are experiencing worsening spam problems. Let's dive into the first The Long View of the month...

...Read more

Thursday, 30 September 2010

No, we're not losing the spam war

Richi Jennings's picture   The Long View (Computerworld)

Forgive me, but I simply can't let David A. Milman's post from yesterday go unchallenged. We're not losing the spam war; the sky isn't falling. I say this not to criticize my fellow CW blogger, but to illustrate several common misconceptions about spam and how the anti-spam community fights it. Let's take The Long View...

...Read more

Friday, 13 August 2010

Twitter spam test: we caught some spammers!

Richi Jennings's picture   The Long View (Computerworld)

You may remember a couple of weeks ago, I baited a trap for Twitter spammers. Let's see how that experiment turned out, in The Long View.

...Read more

Friday, 30 July 2010

A Twitter spam test, not an Apple iPhone 4 post ... #FF @richi

Richi Jennings's picture   The Long View (Computerworld)

If you're anything like me, you're heartily sick of Twitter spammers. It's Friday, so might I crave your indulgence for a little experiment here in The Long View? (I promise: there's nothing here about the Apple iPhone 4.) The microblogging service seems to be plagued with thousands of bots, mindlessly tweeting gibberish. Any search for a popular term -- such as, ohhh I don't know, Apple iPhone 4 -- seems to throw up a huge, steaming pile of automated tweets from an army of fake Twitter users. But what's really going on here?

...Read more

Wednesday, 30 June 2010

10 ways spam is like vuvuzelas (the World Cup horns)

Amir Lev's picture   Security Levity (Computerworld)

If you've been glued to the World Cup, you'll know that there's more to the matches than soccer (football for our international audience). I'm talking about those incessant horns -- the vuvuzelas. They're really catching people's attention, for all the wrong reasons. It got me thinking... In this week's Security Levity, how is a vuvuzela just like spam?

Vuvuzelas and spam? Have I gone mad? Never fear, dear reader, let me count the ways...

...Read more

Friday, 15 May 2009

FAQ: Suffering Backscatter

Dear Richi, I have about 20-30 returned emails from some entity/person who is somehow using my domain to send out bulk email. How is that even possible?

Sadly, it's trivial for a spammer to forge your address. It's not your Web host's fault.

Some badly configured email servers auto-reply to spam. That's what you're seeing.

If you want to complain to anyone, complain to the people running the servers who are auto-replying to you. Here's a template complaint I've used before...
Hello. You are sending spam to me by bouncing spam to an unrelated person. I did not send the spam to your server: spammers forge the message sender. Hence, your reply goes to an innocent third party.

Perhaps you sent an unsolicited bounce because your mail server is incorrectly configured. Please don't do that. You should *reject* during the SMTP conversation, not *bounce* after accepting the spam message. It is not necessary for your MTA to send a non-delivery DSN -- you should reject at the point of SMTP RCPT with a 553 error or equivalent.

Or perhaps you're auto-replying to spam. Presumably you filter spam before delivering inbound email. In which case, this reply shows that spam is getting through those filters.

It's bad practice to accept a message for a non-existent user. If you accept and then bounce, you're sending spam. For more information, please see http://www.spamcop.net/fom-serve/cache/329.html

If this was an isolated error, there's no need to be concerned that you will be blacklisted as a spam source. It usually takes several complaints to illustrate a pattern of email abuse.

However, I urge you to correctly configure your mail servers.
More info at an old post of mine: I Got 25,000 Spam Messages in Two Days!

Saturday, 2 May 2009

CNN: carbon footprint of spam

Finally, I have the CNN footage.

Amusingly, they mixed up the captions, so Woody got my title...


No video? Click here for the carbon footprint of spam video.

Wednesday, 29 April 2009

A "Monster" Spammer (NYSE:MWW)

Update May 1 3.30 UTC: several listwashing requests.

Dear Monster.com (NYSE:MWW),

You are spamming me. Stop it. Please.

You're sending marketing email to an address that has never given informed consent to receive it.

Not only that, but you're even breaking the spirit, if not the letter, of the U.S. CAN-SPAM Act. While your unwelcome missive does include the proscribed physical address and unsubscribe link, they are displayed in white text on a white background.

Yes, really. (I dare say they'd be more visible if my email client displayed HTML images by default, but like many clients, it doesn't.)

Naturally, it's also in violation of the law in which your UK subsidiary operates. There was no "prior consent" given, within the meaning of the Privacy and Electronic Communications (EC Directive) Regulations 2003. Offenders are liable to a fine of up to £5,000 in a magistrate's court, or an unlimited fine if the trial is before a jury.

Update May 1 3.30 UTC:
I've received a couple of email messages and a Twitter DM from Monster, expressing apologies for the situation. Sadly, these expressions of regret don't extend to actually fixing the spam problem; they appear to be an attempt to listwash.

Sorry, Monster; listwashing is bad practice. My standard operating procedure is to never unsubscribe from a list that I did not subscribe to.

If Monster wishes to solve this problem, it would stop sending email to addresses of people who did not subscribe. I'm open to a public dialogue on this subject: feel free to tweet or comment here, rather than privately emailing or DM'ing.

Friday, 24 April 2009

BoxSentry Ditches Challenge/Response; Fights False Positives

Update Apr 25 6.30am UTC: fix name of product (thanks, Meng)

Singapore-based BoxSentry has historically been known as a challenge/response spam filter vendor. Readers will probably be aware that I'm no fan of C/R.

As time goes by, BoxSentry has gradually de-emphasized C/R, but until recently it was still sending challenges for a small but significant proportion of the spam it received -- and hence was sending unsolicited "replies" to people who had never sent email to the BoxSentry user.

Manish GoelManish Goel, BoxSentry's CEO, confirmed to me that his company no longer uses C/R. That's great news for Internet users. Well done, Manish; I know that I and others have been thorns in your side for a while about this; I appreciate your good humour in our occasional, heated debates!


Manish also brought other news. While beefing up their technology base -- in part to compensate for the loss of the C/R layer -- the company has developed new techniques to better identify false positives.

BoxSentry has wrapped the new techniques in a product it's calling LogiQ. The idea is that it can run alongside a traditional spam filter and automatically retrieve any false positives it finds.

As an illustration, Manish offered a "typical" example: over the test period, a deployed spam filter from one of the well-known vendors delivered 11,500 legitimate messages, but LogicQ found an additional 680 false positives in the filter's quarantine. That's a roughly average false positive rate, in my experience. Not the exactly state-of-the-art, but pretty representative of deployed spam filters. It might equate to one false positive every week per user.

Manish says that 100% of the false positives identified with these new techniques really are false positives -- although they may not catch all of them.

A bold claim; I'm looking forward to digging into the details of the techniques under NDA...

Thursday, 23 April 2009

Astaro drops its R&D-led roadmap

This is Angelo Comazzetto. A Canadian, of Italian heritage, living in the U.S., working for a German company.

When I met him last year, his business card said something like Evangelist. These days, he's the product manager for Astaro's line of low-cost Unified Threat Protection appliances. Dspite his title change, he's not lost his passionate, high-energy, rapid-fire delivery style ;-)

Some notes from our meeting:
  • "600 new features" in the past year
    • based on win/loss analysis and other customer requests
    • no longer R&D-led roadmap!
    • Versions 7.2, 7.3, 7.4 all "major" releases
  • Now uses Commtouch for anti-spam, Astaro loves them
  • Astaro has dropped Kaspersky: too expensive and inaccurate
  • Moved to Postgres from MySQL
  • Added full https content inspection
    • Several options for deploying the proxy certificates to user PCs
  • Network balancing across several connections
  • Supports the proprietary Cisco IPsec client
    • So can have people move from obsolete Cisco PIX and ASA to Astaro
    • Supports iPhone VPN client (nice demo)

Wednesday, 22 April 2009

Commtouch's new OEM Web security business

At the RSA Conference yesterday, I sat down for a friendly chat with Amir Lev, the CTO of Commtouch.

Commtouch is best known for its OEM anti-spam engine, which is licensed by a long list of well-known email security vendors.

In January, the company launched a Web security service, using a similar architecture and business model as its anti-spam technology. In other words, it's a hybrid of a managed service—cloud-based, if you insist—that maintains a database of known Web pages, plus an OEM engine that queries the database and intelligently caches the results.

Why do it in the cloud? Amir argues that it's hard to categorize the whole Internet, as the database gets huge and the changes are too big to push the updates in a timely manner.

The service categorizes the known threats so that OEMs can produce different types of products. For example, an product focussed on anti-phishing, which will major on the web pages categorized as fake bank portals, etc.

Amir argues that being an OEM is a good place to be, as the industry continues to move to a "soup-to-nuts" UTP model. Commtouch's vendor customers will often specialize in one or two areas and license the rest conventionally.

More controversially, Amir also argues that it's risky to build a strategice relationship with a small, niche company that offers an OEM solution, because if they're bought out, they may lose the OEM strategic focus.

Well, he would say that, wouldn't he?

Tuesday, 21 April 2009

Abaca's radical anti-spam tech wins at Yahoo!

At the RSA Conference, I was almost blinded by the huge grins on the faces of the Abaca reps.

As you may recall, Abaca has a really interesting spin on the spam filtering problem. Finely-tuned mathematics and a big database of receiver statistics give back up some truly impressive claims. As I said last year, I'm reasonably convinced that it's not just a silly FUSSP.

For over a year, Abaca has been working on a deal with Yahoo! to add the technology—which they now call CLX—to the spam filtering mix. A few months ago, I heard unofficially that Yahoo! agreed to roll it out.

Now, Abaca is announcing that the rollout has been hugely successful, and Yahoo! is extremely satisfied with the result. Nice going.

As an update, here's the (claimed) highlights of the Abaca technology:
  • Guaranteed accuracy of at least 99% catch rate (with money-back contract terms)
  • Claimed false positive rate is infinitesimal (I calculate their claims equate to one in a million messages)
  • After bootstrapping with recipient email statistics, no user training is required, but can be individualized by users clicking the Spam/Not-spam buttons
  • By its nature, it's extremely scalable—a single small server can handle 90 million messages per hour
Of course, I can't verify these claims, but it would appear that Yahoo! effectively has.

Equally, I don't know how close to reality the false positive figures are -- at best they're based on user reports alone, which usually tend to significantly under-state the reality. But, again, if the Yahoo! user reports are anything close to 1:1,000,000, then Abaca has something really worth shouting about.