Monday, 8 January 2007

More About Why Cisco Bought IronPort

As I mentioned last week, Cisco bought IronPort for $830 million.

Clearly IronPort's reputation data is part of the prize for Cisco. Perhaps also, the PostX email encryption technology will possibly be useful (IronPort bought PostX last year). Perhaps some enhanced competition for Identum and Voltage? Alternatively, I fear that Cisco may let this stuff wither on the vine -- PostX customers should be concerned and watch closely.

An interesting question is what will happen (if anything) with SpamCop. IronPort deliberately ran SpamCop at arm's length as a matter of policy. It's not clear whether Cisco will maintain that policy. SpamCop is of course part of the raw data feeding into IronPort's reputation database, along with the data phoned home by the IronPort boxes.

As we saw with the BlackSpider acquisition by SurfControl, spam control companies that aggregate lots of data about spam sources are valuable, for reasons in addition to spam control. For example, if a zombie is sending spam, it's also probably a potential source of other bad stuff, such as worms and distributed denial of service attacks.

See also: my roundup of blogger reaction to this story in Friday's IT Blowatch.

Thursday, 4 January 2007

Anti-Spam Market Consolidation Continues -- Cisco Buys IronPort

Today, Cisco announced that it has acquired IronPort Systems for $830m in cash and stock.

Cisco is of course well-known for its "growth by acquisition" strategy, and was notably lacking in solutions for email hygiene. It makes sense for it to buy an appliance vendor.

IronPort and Ciphertrust have been the appliance market leaders for some time (albeit challenged by the appliances launched by large, conventional software vendors such as Sophos and Symantec). Ciphertrust was of course bought by Secure Computing in 2006, thus leaving Cisco with an obvious choice.

Will we look back at 2007 as the year of spam control market consolidation? We've certainly seen some significant M&A activity in previous years, but there's still plenty of scope for your vendor to be acquired or run out of VC money.

[Edit: it's now officially $830m, not $850m as I was originally advised by IronPort]

Sender Authentication Doesn't Fix Challenge/Response

Happy new year. Sorry that the first post of January is about challenge/response (again), but surprisingly few people seem to get it.

There's this idea floating around that challenge/response filters are OK if they check SPF, SenderID, or DomainKeys -- only challenging messages that pass those checks.

Twaddle. This idea that SPF or SIDF or DKIM can tell you whether a message is forged is naive.

Firstly, implementation on the sender side is spotty. If there's no SPF record or DKIM header to check, you're back to square one.

Secondly, don't forget that most spam is sent by virus-infected computers (corralled into a botnet). There's nothing to stop virus writers from sending spam that passes an SPF/PRA/DK check at the receiving end.


Tuesday, 19 December 2006

Oh Bum. I got Tagged.

Ann Elisabeth Nordbø (aka The Spamhuntress) tagged me earlier. That means I am duty-bound, dear reader, to tell you three things you may not know. Hmmm...

  1. My first real job was at Thorpe Park -- a theme park in an old gravel pit near Staines. I was a pirate on Treasure Island. 1983.
  2. I first used email and IM in 1985. God bless JANET, BSD, PDP11s, and VT100s.
  3. I've never had measles or mumps. As you may know, I recently got chickenpox (don't follow link if you're of a nervous disposition).
  4. I actually get paid to blog -- by Computerworld (where I write IT Blogwatch) and Ferris Research (where I edit/manage the weblog and occasionally write).
  5. I'm an only child (does it show?)
  6. You are number 6.
My other duty is to blog tag five other poor unfortunates. How about: the Notes-tastic Ed Brill, Karma-chameleon Meng Weng Wong, poly-mathematical Ian Lamont, Irish assassin Justin Mason, and the most mysterious "Ravelox".

Another Challenge/Response Datapoint

Sorry to harp on about challenge/response, but on the topic of C/R causing many false positives, I just noticed this post on The Admin Zone:

I HATE challenge-response spam blocking with a passion. All the time, I get Earthlink members signing up on my message board, but not putting the domain name in their whitelist. When vBulletin sends out a validation email, the following bounces back into my mailbox ... As a matter of principle, the mods and I NEVER respond to email challenges; we NEVER "click the link below" to be added to a whitelist.

If an existing user starts using challenge-response spamblocking, forget to put my domain in their whitelist, subscribe to threads, and as a result fill my mailbox with challenges, they're suspended for a week. Behind spam, it is my number two pet peeve.