Thursday, 30 March 2006

Why I've been Quiet

Sorry I've been quiet for a bit. Did you miss me?

It turns out I caught chickenpox on the flight over to the RSA conference (no, I'd not caught it as a child). Once I got home, my body revolted. Don't worry, I'm fine now.

For someone who's never even had the flu, being bedridden for a week was a bit of a culture shock, I can tell you.

disgusting picture of richi

Friday, 17 March 2006

Esther Dyson is Wrong -- Most Email Will Remain Free

I like Esther Dyson. I first met her in the early '90s, and found her thoughtful, insightful, and straight talking. But I can't let her op-ed piece in Friday's New York Times go unchallenged.

Dyson begins with a refreshingly accurate, measured description of Goodmail and its partnerships with AOL and other email providers. She goes on to belittle those who aim to boycott Goodmail and their partners. Those who keep up with my blog will know that I fully agree with her on this point.

However, Dyson goes on to say, "Pretty soon sending most e-mail will cost money, but I think that's only right." I disagree -- it won't and it isn't.

Her argument stands or falls on the assertion that today's spam filters aren't working -- Dyson asserts that, "The senders of 'bad' mail are getting better and better at defeating them." However, it's clear to me that, although the smarter spammers are making their messages trickier to filter, the filters are also getting better.

All in all, today's state of the art in spam control solutions is far ahead of where it was, say, two years ago. Improved spam filters being available to more people -- plus laws that allow the citizenry to penalize spammers -- will cause the scourge of email spam to whither and die.

Tags: .

Wednesday, 1 March 2006

Free Speech is No Excuse to Spam

It seems that some bulk email senders are getting spun up about developments such as Goodmail and Bonded Sender. For example, MoveOn.org says it's, "Threatening the Internet as we know it ... The very existence of online civic participation and the free Internet as we know it are under attack."

Balderdash and piffle, say I. Nothing's really changed -- if users are complaining about some email, service providers will block the sender, whether or not they pay some sort of a bond or fee. There's no substantive change here. If you're an existing sender with a good reputation, you should have nothing to worry about -- well, nothing new anyway.

I suspect there's an underlying agenda to some of the moaning. There are some quasi-political and religious groups emailing indiscriminately, and hiding under the flag of Free Speech. That's no excuse -- people will still click the This Is Spam button, and so future mail will get blocked. Just because the message isn't commercial, it doesn't mean that users won't perceive it as spam. I've no sympathy for senders who use those tactics.

My advice to groups who are concerned about their continued ability to communicate legitimately is this: if you find that your email's being blocked, work with your email service provider and that of the recipient to figure out how you should act in the future. Don't act as if it's your deity-given right to send email to whomever you wish. Those that run email services are perfectly entitled to act on user spam complaints. As the saying goes, "My server -- my rules."

Saturday, 25 February 2006

Additional Thought on Phishing Complaints

Last week, I wrote about what brand owners should do about phishing. You may recall me saying that owners should have a mailbox where they can receive copies of phishing spam forwarded to them by consumers and (ahem) security researchers. I also said that owners could run spamtraps to pick up phishing attacks as they happen.

One aspect of this that I didn't mention, but perhaps it's not obvious -- the mailboxes used should not be spam filtered. A surprising number of banks and other brand owners get this detail wrong (cough Barclays cough). This causes them to ignore complaints and under-estimate the scale of the problem.

Friday, 17 February 2006

What brand owners should do about phishing

If you're a bank, or other organization that's worried about having your brand spoofed in a phishing attack, first you need to detect the attacks, and then you need to act. Here are some of the things you can do:

  1. Receive complaints from consumers -- publish an email address for consumers to forward suspected phishing emails to. The abuse desk can reply to the consumer to confirm whether this was a legitimate message or a phishing attempt (e.g. spoof@paypal.com, internetsecurity@barclays.co.uk).
  2. Run spamtraps -- publish email addresses for the sole purpose of receiving spam. Scan the incoming spam for phishing attempts on your brand.
  3. Detect remote image loading -- scan your web server logs for the telltale signs of your images being displayed in web sites that don't belong to you.
  4. Takedown -- get the phishing web sites removed from the Internet. Work with:
    1. The ISP responsible for the email sender
    2. The hosting company hosting the phishing website
    3. The domain registrar responsible for a bogus copycat domain (e.g. paypalverify.com)
  5. Block -- inform consumer protection services to protect consumers while the sites are still available. For example:
    • Google's anti-phishing toolbar
    • Cloudmark's anti-fraud toolbar
    • Microsoft's anti-phishing protection in IE7
If you're worried about your brand's vulnerability to phishing, contact me. I can help.