Wednesday, 1 March 2006

Free Speech is No Excuse to Spam

It seems that some bulk email senders are getting spun up about developments such as Goodmail and Bonded Sender. For example, MoveOn.org says it's, "Threatening the Internet as we know it ... The very existence of online civic participation and the free Internet as we know it are under attack."

Balderdash and piffle, say I. Nothing's really changed -- if users are complaining about some email, service providers will block the sender, whether or not they pay some sort of a bond or fee. There's no substantive change here. If you're an existing sender with a good reputation, you should have nothing to worry about -- well, nothing new anyway.

I suspect there's an underlying agenda to some of the moaning. There are some quasi-political and religious groups emailing indiscriminately, and hiding under the flag of Free Speech. That's no excuse -- people will still click the This Is Spam button, and so future mail will get blocked. Just because the message isn't commercial, it doesn't mean that users won't perceive it as spam. I've no sympathy for senders who use those tactics.

My advice to groups who are concerned about their continued ability to communicate legitimately is this: if you find that your email's being blocked, work with your email service provider and that of the recipient to figure out how you should act in the future. Don't act as if it's your deity-given right to send email to whomever you wish. Those that run email services are perfectly entitled to act on user spam complaints. As the saying goes, "My server -- my rules."

Saturday, 25 February 2006

Additional Thought on Phishing Complaints

Last week, I wrote about what brand owners should do about phishing. You may recall me saying that owners should have a mailbox where they can receive copies of phishing spam forwarded to them by consumers and (ahem) security researchers. I also said that owners could run spamtraps to pick up phishing attacks as they happen.

One aspect of this that I didn't mention, but perhaps it's not obvious -- the mailboxes used should not be spam filtered. A surprising number of banks and other brand owners get this detail wrong (cough Barclays cough). This causes them to ignore complaints and under-estimate the scale of the problem.

Friday, 17 February 2006

What brand owners should do about phishing

If you're a bank, or other organization that's worried about having your brand spoofed in a phishing attack, first you need to detect the attacks, and then you need to act. Here are some of the things you can do:

  1. Receive complaints from consumers -- publish an email address for consumers to forward suspected phishing emails to. The abuse desk can reply to the consumer to confirm whether this was a legitimate message or a phishing attempt (e.g. spoof@paypal.com, internetsecurity@barclays.co.uk).
  2. Run spamtraps -- publish email addresses for the sole purpose of receiving spam. Scan the incoming spam for phishing attempts on your brand.
  3. Detect remote image loading -- scan your web server logs for the telltale signs of your images being displayed in web sites that don't belong to you.
  4. Takedown -- get the phishing web sites removed from the Internet. Work with:
    1. The ISP responsible for the email sender
    2. The hosting company hosting the phishing website
    3. The domain registrar responsible for a bogus copycat domain (e.g. paypalverify.com)
  5. Block -- inform consumer protection services to protect consumers while the sites are still available. For example:
    • Google's anti-phishing toolbar
    • Cloudmark's anti-fraud toolbar
    • Microsoft's anti-phishing protection in IE7
If you're worried about your brand's vulnerability to phishing, contact me. I can help.

Tuesday, 14 February 2006

RSA here we come

This week, I shaaall mostly be at the RSA Conference. Hanging out in the press room quite a bit of the time for Ferris Research, more's the pity. Do say hi.

Friday, 10 February 2006

BlackBerry? BlackCherry? StealthBerry? -- Workaround or death rattle?

RIM -- Canadian maker of the seminal BlackBerry wireless email-and-other-things device -- has been talking about its proposed workarounds for alleged patent infringement issues. (Quick summary: patent holding company NTP seeks injunction preventing RIM offering BlackBerry service in U.S., cites patent infringements on "push" email.)

There are confused reports, but it seems there are two separate issues, each with their own workaround:

  1. What happens when the user is out of coverage -- where is the incoming message queued? Workaround #1 queues the message at the server on the customer premises. Currently, messages are queued at RIM's network operations centers (NOCs).
  2. What happens when a message arrives -- does the user need to do anything to receive it? Workaround #2 involves turning the BlackBerry "push" model into a "push/pull" model. Users will only get the message headers pushed to them. Some reports indicate that users will need to press a button to request that the message body be downloaded.

RIM's public position is that NTP's patents are invalid. However, in case of legal injunction, workaround #1 is all that is necessary. However, it looks like RIM is also secretly readying workaround #2 just in case. I've not been briefed by RIM on #2 -- this information is coming from anonymous RIM customers.

The user isn't likely to perceive any impact from workaround #1 -- it will simply delay some messages by a few seconds. However, workaround #2 is a different matter. If the anonymous reports are to be believed, #2 basically breaks the BlackBerry secret sauce. If the user needs to think about receiving messages, it isn't a BlackBerry any more -- it's just a wireless email device just like any other, except with a rather ugly on-screen graphic design. Users who are, say, riding the subway won't be able to read messages unless they explicitly pulled them before moving out of the coverage area.

RIM needs to avoid workaround #2 at all costs.