Friday, 8 June 2007

Weird Story in Computerworld

Greetings from Vegas.

My chums at Computerworld have put up a very oddly-written story today. It seems that Kingfisher Bay, an Australian resort, was using an "aging" version of Symantec's spam filter. Surprise-surprise, old versions of spam filters don't work very well, letting through a lot of spam.

In fact, it turns out that the resort wasn't using the Symantec Brightmail technology at all. It was still using the old, pre-Brightmail engine. Oddly, Symantec still sells this -- can't see why that's a good idea.

Anyway, it sounds to me like the company decided it wanted to use a managed service, rather than an in-house solution. Many smaller organizations are making this choice. Their obvious targets are MessageLabs, Postini, Microsoft (née FrontBridge), or a bunch of smaller/regional providers.

In the end, they chose MessageLabs. Naturally, MessageLabs is crowing to the press about how it's gained a customer from Symantec.

But hang on, doesn't MessageLabs use Symantec Brightmail anti-spam for its service? How ironic...

Wednesday, 6 June 2007

Greetings from Orlando

Greetings from Tech-Ed, where some enterprising soul pointed a cam at the keynote's opening skit.



Bob [Muglia], meet Bob!

Sunday, 3 June 2007

See You at Microsoft's Tech-Ed or Symantec's Vision?

This week, I shaaall mostly be in Orlando, for Microsoft's Tech-Ed bash.

Next week: Vegas (baby) for Symantec's Vision.

Email or text me (+447789200701) for meetup coordinates.

Friday, 1 June 2007

Zulfikar Ramzan is Correct About Phishing

Zully is right on in his demolition of Mikko Hypponen's idea for a ".bank" TLD.

Writing on Symantec's Security Response weblog, he basically urinates all over Mikko's plan (although he's a lot more diplomatic than that). Some choice cuts:
Phishers don’t have to use the .bank extension and most users will fail to notice ... if you look at almost every phishing site these days, the URL itself is a blatant giveaway that you’re not at an authentic site
...
The proposal will also lull users into a false sense of security for a number of reasons ... The bad guys may still be able to get .bank domains ... won’t stop phishing attacks that exploit cross-site scripting vulnerabilities ... Browsers are sometimes susceptible to address-bar overlay vulnerabilities. [read more]
Or, to put it another way, the problem with this proposal is that roughly half the population have below-average intelligence (hat tip: APHC).

Sure, it's easy to be a critic, but such ideas just waste energy that could be ploughed into useful furrows, such as DKIM and domain-level reputation.

See also: BofA Sitekey, Yahoo! Signin Seal, etc., etc.

Thursday, 31 May 2007

Soloway Arrested

I guess it's OK to call Robert Soloway a spammer -- he's already been convicted in U.S. civil charges of spamming in 2003.

This time though, he's been arrested on criminal charges, brought by the FTC. The list of laws he's alleged to have broken is extensive:
  • 10 counts of mail fraud
  • 5 counts of wire fraud
  • 5 counts of identity theft (aggravated)
  • 13 counts of money laundering
  • 2 counts of email fraud (the only counts related to the CAN-SPAM Act)
If convicted, the possible penalties add up to a very long time in jail. Aunty Beeb thinks 65 years, but that estimate might be on the high side...

Assuming that he didn't give up spamming in 2003, his arrest (so far without bail) should at the very least cause less spam to be sent (i.e. the spam that would have been sent by him while he's under arrest). If he gets jail time, so much the better.

So far, all the high profile civil spammer convictions have involved fines, with the exception of Jeremy Jaynes. These fines seem on the face of it to be large, but in comparison with the money earned by successful spammers, not so much.

While those convictions increased spammers' fear of getting caught, they also served to publicize the amounts that successful spammers can make -- it may have actually encouraged new spammers to enter the game. That's the law of unintended consequences in action.

This is how the law works. Laws encode a society's terms of acceptable behavior. The credible threat of punishment removes the incentive for bad actors to... well... act badly.

The various laws that prohibit spamming just got much more credible.

More: Seattle PI / TechMeme