General fitness, health and nutrition · Public discussion

spammers?

Started by Guy · · Last activity · 80 posts · 2,187 views

Thread navigation

Jump through the discussion

Go to the original post, the replies on this page, or the latest preserved contribution.

Thread details

What we know about this thread

Original section
General fitness, health and nutrition
Published
1 February 2004
Last activity
11 February 2004
Original author
Guy
Posts
80
Discussion status
Public discussion
Total views
2,187
Views / 30 days
0

The navigation and discussion metadata provide context. Posts remain in their original chronological order.

Showing posts 21–40 of 80
Posts remain in their original chronological order.

Text size
  1. In article <[email hidden]>,

    Jim Dumas !mindspring.com said:
    Alice Faber said:

    I'd flip it around and say that you care less about corresponding with folks than about not
    getting spam.

    True. "Don't bother me unless you're serious." That's the net effect.

    And that's life in a spam-burdened world.

    Quoted message said:

    Mind you, I have a whole set of procmail filters on my mail server, as well as SpamAssassin, and
    the Junk filters in Eudora. I also have a set of files I check for false positives, mostly
    caused by folks who send email in HTML format. I'm accepting the burden of making my email
    usable, not foisting it off on others.

    I decided I was wasting too much of my time looking at spam email headers and writing rules to
    catch this moving target. Earthlink has simplified my life with challenge-response. As spam
    continues to grow, it will consume your free time with all the maintenance your layered filters
    require. But if this is an educational exercise, then that's wonderful. But I've concluded that
    until some change is made in email header tracability, (verified originator ID for example), then
    it's useless to chase spammers.

    Now that I have SpamAssassin configured, I'd estimate I spend less than 2 minutes per day worrying
    about this. When it was procmail alone, yeah, it took a bit of fooling around, but SpamAssassin has
    rendered all that superfluous.

    --
    AF

  2. Alice Faber said:

    Now that I have SpamAssassin configured, I'd estimate I spend less than 2 minutes per day worrying
    about this. When it was procmail alone, yeah, it took a bit of fooling around, but SpamAssassin
    has rendered all that superfluous.

    I still have SpamAssassin loaded on this linux box (mailfilter and others as well). But have decided
    the Earthlink approach is better. Let my ISP deal with it and give me the ones that pass the tests.
    My maintanence time is 0 now. If you want to be a sys admin, then that's wonderful. But I'd rather
    spend my time on other things.

    So for the end-user, the Earthlink system works fine,
    --
    Jim Dumas T1 4/86, background retinopathy, rarely hypoglycemic: <1/mo. lispro+R+U+NPH daily,
    moderate exercise, typically <6% HbA1c

  3. In article <[email hidden]>,

    Jim Dumas !mindspring.com said:
    Alice Faber said:

    Now that I have SpamAssassin configured, I'd estimate I spend less than 2 minutes per day
    worrying about this. When it was procmail alone, yeah, it took a bit of fooling around, but
    SpamAssassin has rendered all that superfluous.

    I still have SpamAssassin loaded on this linux box (mailfilter and others as well). But have
    decided the Earthlink approach is better. Let my ISP deal with it and give me the ones that pass
    the tests. My maintanence time is 0 now. If you want to be a sys admin, then that's wonderful. But
    I'd rather spend my time on other things.

    At panix, SpamAssassin *is* on the server. My goal is to keep spam from being downloaded to my
    computer without inconveniencing actual correspondents. That's my choice; some of my friends are
    happy to "just hit "d"". So I see no reason to create any extra burden for people who've made
    different choices.

    --
    AF

  4. On Tue, 03 Feb 2004 18:21:17 GMT, Jim Dumas

    !mindspring.com said:
    Alice Faber said:

    Now that I have SpamAssassin configured, I'd estimate I spend less than 2 minutes per day
    worrying about this. When it was procmail alone, yeah, it took a bit of fooling around, but
    SpamAssassin has rendered all that superfluous.

    I still have SpamAssassin loaded on this linux box (mailfilter and others as well). But have
    decided the Earthlink approach is better. Let my ISP deal with it and give me the ones that pass
    the tests. My maintanence time is 0 now. If you want to be a sys admin, then that's wonderful. But
    I'd rather spend my time on other things.

    So for the end-user, the Earthlink system works fine,

    I use an ISP filter plus others. The problem is with high speed computing where the spammers can try
    many combinations and broadcast. This increases the traffic greatly but a few of these shotgun
    things get through. Greedy abusive people can use technology to their advantage. People that do not
    have to work for a living can write virus and hack routines that exploit the present systems. The
    very things that are used to gather business data are found by hackers and used. I see that Bill
    Gates is a bit upset. Good. Warning were available years ago. Guy

  5. Alice Faber said:

    At panix, SpamAssassin is on the server. My goal is to keep spam from being downloaded to my
    computer without inconveniencing actual correspondents. That's my choice; some of my friends are
    happy to "just hit "d"". So I see no reason to create any extra burden for people who've made
    different choices.

    That's fine. But any two-way conversation requires a response. So your system still requires a test
    for a human sender. You've decided to leave this to the end-user. The test has been done by
    Earthlink for me.

    So I'll stick with Earthlink,
    --
    Jim Dumas T1 4/86, background retinopathy, rarely hypoglycemic: <1/mo. lispro+R+U+NPH daily,
    moderate exercise, typically <6% HbA1c

  6. 3 Feb 2004 17:08:25 GMT said:

    Wes Groleau wrote

    Quoted message said:
    Quoted message said:

    You mistakenly assume I'm as stupid as the spammer.

    Quoted message said:

    I assume nothing. You assume that they are too dumb to understand that your countermeasures
    indicate that they should stop sending _you_.

    Quoted message said:
    Quoted message said:

    Anyone want to do a controlled study?

    Quoted message said:

    The fact that we're all still spammed to death no matter all your ingenious schemes and thoughts
    might make that study very superfluous.

    imo, the spammers who send out these new spam messages to many (all?) of the newsgroups NEVER read
    any responses to their spam post(s)

    so replying to those mass spam postings is a total waste of time

    instead, write to your Federal representatives (House and Senate if you are in the USA)

    bill

  7. Jim Dumas said:

    I decided I was wasting too much of my time looking at spam email headers and writing rules to
    catch this moving target. Earthlink has simplified my life with challenge-response. As spam
    continues to grow, it will consume your free time with all the maintenance your layered filters
    require. But

    I can't speak for anyone else, but _statistical_filters_ have "simplified my life." I almost never
    look at headers. When I get a false positive or false negative, I tell the program it was wrong. It
    scans the message again and rewrites the "rules" automagically.

    Haven't had a false classification in ages, though.

    Only time I look at headers is when I see a subject line that I think is worth notifying legal
    authorities over.

    I use challenge-response only for messages over a certain size limit. (And that has only happened
    once in months because a message that big is almost certainly dumped by the virus recipes.)

  8. On Tue, 03 Feb 2004 15:59:28 GMT, Jim Dumas

    !mindspring.com said:
    Wes Groleau said:

    Problem with challenge-response is that it magnifies the abuse of the network. Spam and virus
    loads down the wires. Response queries either dump on the poor guy whose address was picked by
    the virus, or generate a load of bounce messages when a spammer has used a non-existent address.

    Far better to use methods that discard the stuff.

    Only if you know it's 100% spam.

    The Earthlink BrightMail filter removes known spam first. Then new contacts are given a chance to
    start a two way dialogue by the challenge post. This is exactly what we do in life, try to start a
    two way conversation.

    If the challenge goes unanswered, then nobody is home and it must be spam. The challenge is less
    than 1 KB and is just one network packet. This is peanuts relative to DVD/CDROM/music downloads
    going on all the time. So it's the price of starting a conversation with an unknown person. It has
    to be done to make 100% sure it's not spam.

    I thought it was wasteful of bandwidth when I first started to use it last June. But I've changed
    my mind, as it's very effective at testing for a human at the sending end. The response is a
    necessary requirement to start a two way dialogue. So let's automate it.

    It works and it's simple. And I get my share of bandwidth as well,

    I don't know how many of you are on broadband. So maybe earthlink works well that way. But for dial-
    up, I had it briefly when my local ISP was bought by them, but couldn't wait to get it off my
    computer. I now have another local ISP for 10 bucks a month less than earthlink, and I am happy with
    it. My ISP e-mail never gets any spam. I have only used it for a very few select people. My main
    mail acct., that I have used for 7 years now, is a yahoo acct. As I have yet to find a workable web
    based spam filter app, I just use the freebie yahoo filters. So when I check my e-mail first thing,
    I may find 150 spams, but they are all directed to my bulk mail filter. One click, Empty Bulk, and
    pfft. gone forever. I have 100 blocked addys, and 15 general filters to use for free. When I get
    motivated, I am going to redo my filters, and knock that bulk mail folder down to a minimal amount.
    I have *never* gotten any of the latest worms, and e-mail virii. Of course I do a couple of thing to
    minimize my odds on that too. Outlook isn't even allowed on my computer. My e-mail is mudged on
    Usenet, and I never open anything foolish. JMO.

    Sleepy

    ----------------------------------------------------
    If you don't disagree with me, how will I know I'm right?
    ----------------------------------------------------

  9. Sleepyman said:


    I don't know how many of you are on broadband. So maybe earthlink works well that way. But for dial-
    up, I had it briefly when my local ISP was bought by them, but couldn't wait to get it off my
    computer. I now have another local ISP for 10 bucks a month less than earthlink, and I am happy
    with it. My ISP e-mail never gets any spam. I have only used it for a very few select people. My
    main mail acct., that I have used for 7 years now, is a yahoo acct. As I have yet to find a
    workable web based spam filter app, I just use the freebie yahoo filters. So when I check my e-mail
    first thing, I may find 150 spams, but they are all directed to my bulk mail filter. One click,
    Empty Bulk, and pfft. gone forever. I have 100 blocked addys, and 15 general filters to use for
    free. When I get motivated, I am going to redo my filters, and knock that bulk mail folder down to
    a minimal amount. I have *never* gotten any of the latest worms, and e-mail virii. Of course I do a
    couple of thing to minimize my odds on that too. Outlook isn't even allowed on my computer. My e-
    mail is mudged on Usenet, and I never open anything foolish. JMO.

    Sleepy


    And a couple of things I forgot. I know how to use IRC safely, I use proxies in my browser when I
    feel it necessary. I don't use ICQ, AIM, Yahoo messeger, or the rest of the IM apps. I used to use
    them, but once the blackhats started messing with them, adios. I keep my AV definitions updated,
    plus I run my AV every night while "sleeping" I use Windows Update, whenever it needs it, and I run
    Spybot S&D daily too. I clean my cache very regularly, set my history file to save 1day only, and I
    have applications to dump cookies that I don't want. Msconfig only allows the startup apps that I
    feel necessary to run. And it all runs automaticly in the background using minimal resources. But
    thats just me.

    Sleepy

    ----------------------------------------------------
    If you don't disagree with me, how will I know I'm right?
    ----------------------------------------------------

  10. Wes Groleau said:

    I use challenge-response only for messages over a certain size limit.

    Then you still don't know if the addresses, that passed your filters, are valid. You must challenge
    them to find out if they are real. You may save a few challenges with spam filters, but eventually
    all roads lead to Rome and a challenge must be sent.

    So what bandwidth are we really wasting?
    --
    Jim Dumas T1 4/86, background retinopathy, rarely hypoglycemic: <1/mo. lispro+R+U+NPH daily,
    moderate exercise, typically <6% HbA1c

  11. On Tue, 03 Feb 2004 13:35:51 -0600, Guy <[email hidden]>

    Quoted message said:
    Jim Dumas !mindspring.com said:

    Alice Faber wrote:

    [snip]

    Quoted message said:

    People that do not have to work for a living can write virus and hack routines that exploit the
    present systems.

    [snip]

    Quoted message said:

    Guy

    That is not necessarily the case. Now is it? I think you might find the reverse could be true.

    Diagnosed 20/03/03 Type II D&E + Metformin + Gliclazide
    + Asprin 210lbs at Dx to BMI 166lbs achieved. To mail: aspen at freeuk.com

  12. Wes Groleau said:
    Jim Dumas said:

    I decided I was wasting too much of my time looking at spam email headers and writing rules to
    catch this moving target. Earthlink has simplified my life with challenge-response. As spam
    continues to grow, it will consume your free time with all the maintenance your layered filters
    require. But

    Quoted message said:

    I can't speak for anyone else, but _statistical_filters_ have "simplified my life." I almost never
    look at headers. When I get a false positive or false negative, I tell the program it was wrong. It
    scans the message again and rewrites the "rules" automagically.

    Quoted message said:

    Haven't had a false classification in ages, though.

    Quoted message said:

    Only time I look at headers is when I see a subject line that I think is worth notifying legal
    authorities over.

    Quoted message said:

    I use challenge-response only for messages over a certain size limit. (And that has only happened
    once in months because a message that big is almost certainly dumped by the virus recipes.)

    I have only received 3 spam mails in the last three weeks and not a single incidence of a virus for
    over 8 months. I am begining to find this subject quite amusing.

    The only way to be spam free is to adopt the recommended techniques. As soon as you do - then you
    will see the difference almost immediately. And the best thing of all, there is no way for the
    spammers to get arround it.

    1] Have two or three mail accounts that you can access, if you wish, either by pop3 or web based
    interface. Select one [the one provided as a matter of course by your access provider] as your
    main mail facillity. With this one - adopt the following policies:

    [a] Never ever quote it either on the web, usenet or any other electronic communication medium.
    Allow access to it only to friends, relatives and trusted business contacts but never quote it
    in a direct e-mail in the body. Not even munged.
    [b] Never quote it on commercial forms or surveys.

    2] The other mail accounts - should be:

    [c] Used when it is necessary to have a vailid mail account as a means of validating entitlement or
    identity to acquire internet service facillities.

    [d] Use one only for use on usenet and do not do so without munging unless it is a throw away
    account. You can access this via the web interface or pop3 but the former is better.

    [e] Use one for web based applications such as form filling on the web and do so without munging. Do
    not set this mail account for access via pop3 in your mail client but access only via a web
    interface.

    3] Mail addresses - with the exception of your 'primary' mail account, all others should not
    reflect your real identity completely unless you are completely confident that your operating
    procedure affords you the necessary minimum security.

    4] Never set your mail program to auto download the mail body. Set to recieve header only.

    5] Never use 'Rich Text' or HTML format for creating or responding to mail.

    6] Never download or accept an attachment unless you can positively identify the sender by name.

    7] Never download a mail unless you can positively identify the sender by name.

    8] Avoid using clients that are the most popular. These are taken into account by those determined
    to exploit weaknesses. Such as OE, Netscape and Eudora to name a few. There are plenty of others
    which are less attractive to hackers and less vulnerable as well as free, such as Calypso, BB
    and others.

    9] Never ever use the Windoze Address Book facility or any other address book that is 'built into'
    your mail client. Use a standalone software and copy/paste addresses. There are a lot of free
    ones available. Or create your own.

    10] Never ever use the 'REPLY' facillity in your client. Most automatically insert 'Re:' as the
    first characters in the subject line. If you do then ammend the subject line to delete 'Re'
    before sending.

    11] Never download a mail with 'Re' 'Hello' Adv Fwd [to mention a few] in the subject line and avoid
    doing so yourself.

    12] Never ever respond to a spammer or follow a link provided in the body of the mail if you have
    inadvertantly downloaded it.

    13] If you complain to a spammer then do not use youe main mail address to send the complaint. Use
    one of the others and either munge or remove your remove your mail detail from the header of the
    mail you send in as part of the complaint.

    14] Never CC or Fwd mail.

    15] Never send unsolicited mail yourself - to private individuals and do not use your main account
    for 'cold mailing' to others. Not even reputable businesses.

    16] Use an AV product - and there are free ones about - which will scan boot up and all mail inbound
    and outbound.

    17] Use a browser cleaner such as Spybot/Adaware every other day to remove trackers etc. Also remove
    Cookies/History every week.

    18] Disable or remove all internet protocols from your system tha are not essential. Such as
    IPS/SPX and remove Netbios from Networking if you do not need it. For usenet/web and mail you
    only need TCP/IP

    19] Use a firewall - there are free ones available such as Kerio.

    20] Use a 'Port Listener' - again free - to monitor what ports are bing accessed.

    21] Never leave your equipment unattended, on and connected.

    22] Unload all Network capability if not in use.

    These are some of the items you should be looking at to ensure your security and privacy. There are
    more but I consider this the minimum.

    HTH

    [Now ducking]

    Pete

    Diagnosed 20/03/03 Type II D&E + Metformin + Gliclazide
    + Asprin 210lbs at Dx to BMI 166lbs achieved. To mail: aspen at freeuk.com

  13. Jim Dumas said:

    Then you still don't know if the addresses, that passed your filters, are valid. You must
    challenge them to find out if they are real. You may save

    If they passed my filters, either they aren't spam or the filters need tweaking.

    Quoted message said:

    a few challenges with spam filters, but eventually all roads lead to Rome and a challenge must
    be sent.

    A few? I don't need to challenge a message I wanted to receive. The size limit is the _last_ of the
    defenses, and it has only triggered once.

  14. Wes Groleau said:
    Jim Dumas said:

    Then you still don't know if the addresses, that passed your filters, are valid. You must
    challenge them to find out if they are real. You may save

    If they passed my filters, either they aren't spam or the filters need tweaking.

    But you still don't know if the sender's address is valid. You _must_ send an email to do this. So
    my requirement for spammers is a two-way dialog. I want some personal attention or I ain't gonna
    look. If it's one-way (with bogus return address) then I discard everything at the ISP level on the
    mail server. So I never see the advertisement. The spammer _must_ respond to the challenge to get
    the ad to me. They obviously can't do this. More importantly, the challenge-response method
    prequalifies the address as valid before I get involved.

    Quoted message said:


    Quoted message said:

    a few challenges with spam filters, but eventually all roads lead to Rome and a challenge must
    be sent.

    A few? I don't need to challenge a message I wanted to receive. The size limit is the _last_ of
    the defenses, and it has only triggered once.

    Even at 50% of incoming spam, it's a deal. What incentive do the spammers have to conserve
    bandwidth? Then why should I bother as well?

    Let's buy a Hummer to get my share of gasoline, right? The American way,
    --
    Jim Dumas T1 4/86, background retinopathy, rarely hypoglycemic: <1/mo. lispro+R+U+NPH daily,
    moderate exercise, typically <6% HbA1c

  15. Pete said:

    14] Never CC or Fwd mail.

    *Errrernt!* You just got the _buzzer_ and hooked off the stage, Pete.

    You're only as good as the weakest link in your circle of trusted friends.

    Moreover, what happens when someone in this circle of friends gets a virus with email harvester.
    You're SOL.

    With all those rules, you better just buy stamps and forget it,
    --
    Jim Dumas T1 4/86, background retinopathy, rarely hypoglycemic: <1/mo. lispro+R+U+NPH daily,
    moderate exercise, typically <6% HbA1c

  16. Pete said:

    I have only received 3 spam mails in the last three weeks

    Then you are fortunate enough to have an address that doesn't fit any of the 'guessing' algorithms
    that spammers use.

    Quoted message said:

    and not a single incidence of a virus for over 8 months. I

    Then either your ISP is filtering them or you have NO acquaintances using Windows.

    Quoted message said:

    The only way to be spam free is to adopt the recommended techniques. As soon as you do - then you
    will see the difference almost immediately. And the best thing of all, there is no way for the
    spammers to get arround it.

    I've used all these techniques. They make a big difference but they don't make one spam-free. And
    they all have disadvantages. Some of the disadvantages are worth it (to me) and some are not. For
    the latter, I gave up that particular technique.

    Quoted message said:

    1] Have two or three mail accounts that you can access, if you wish, either by pop3 or web based
    interface. Select one [the one provided as a matter of course by your access provider] as your
    main mail facillity. With this one - adopt the following policies:

    Indeed. I had three. I gave NO ONE the "main" address. I gave friends a despammed.com address which
    forwarded to the 'real' address (after the filtering set up by them). I used myrealbox.com on Usenet
    because that one had some filtering but still (allegedly) allowed me to write my own rules for what
    their conservative filters didn't catch. Dropped them because the rule mechanism didn't work.

    Quoted message said:

    [a] Never ever quote it either on the web, usenet or any other electronic communication medium.
    Allow access to it only to friends, relatives and trusted business contacts but never quote it
    in a direct e-mail in the body. Not even

    If you give your "real" address to ONE novice Windows user, in three months hundreds of them will
    have it. Half of those will be forwarding urban legends that they received WITH your address inside
    in an unsnipped header from an earlier forwarding.

    [quote="Quoted message"][b] Never quote it on commercial forms or surveys.[/quote]

    Bingo! On the paper side, I still get junk mail where the second address line is literally "NO
    JUNK MAIL"

    Quoted message said:

    2] The other mail accounts - should be:

    [c] Used when it is necessary to have a vailid mail account as a means of validating entitlement
    or identity to acquire internet service facillities.



    See www.sneakemail.com

    Quoted message said:

    [d] Use one only for use on usenet and do not do so without [snip]
    [e] Use one for web based applications such as form filling



    Currently I have a Unix account that allows me to do things like [email hidden] AFAIK (I
    don't look at most of the spam) address-harvesters don't pick those up. Only the almost certainly
    NOT spam or viruses are forwarded to my 'real' address.

    Quoted message said:

    5] Never use 'Rich Text' or HTML format for creating or responding to mail.



    That doesn't help me at all. But I sure wish the rest of the world would comply.

    Quoted message said:

    6] Never download or accept an attachment unless you can positively identify the sender by name.



    Obviously. However, if you need this rule, then you ARE getting spam or viruses to apply
    this rule to.

    Quoted message said:

    7] Never download a mail unless you can positively identify the sender by name.



    i.e., never accept help with technical questions or diabetes questions from anyone except your face-to-
    face acquaintances. Require all your customers (if you have any) to use snail mail for support.

    Quoted message said:

    8] Avoid using clients that are the most popular. ....



    Even if that means giving up techniques you have mentioned that aren't supported by what's available
    for your O.S. ? (or do you suggest I give up all my anti-hacker features just so I can use a Windoze
    e-mail client?)

    Quoted message said:

    9] Never ever use the Windoze Address Book facility or any other address book that is 'built
    into' your mail client. Use a standalone software and copy/paste addresses. There



    I don't use an address book at all. If I did, I certainly would not pick one that is inconvenient in
    order to avoid seeing spam that I already never see.

    Quoted message said:

    are a lot of free ones available. Or create your own.



    HA! 99% of the viruses come from computers whose owners are incapable of creating address
    book software.

    Quoted message said:

    10] Never ever use the 'REPLY' facillity in your client. Most automatically insert 'Re:' as the
    first characters in the subject line. If you do then ammend the subject line to delete 'Re'
    before sending.



    Please explain how typing in (or pasting) an address has a greater anti-spam effect than allowing
    the client to auto-paste the SAME address.

    Quoted message said:

    11] Never download a mail with 'Re' 'Hello' Adv Fwd [to mention a few] in the subject line and
    avoid doing so yourself.



    Don't receive "re" or "fwd" ? In other words, tell your friends (if you have any left by now) "Don't
    bother trying to communicate with me unless you're willing to obey all MY anti-spam policies.

    The others go to /dev/null very early in the filtering process.

    Quoted message said:

    12] Never ever respond to a spammer or follow a link provided in the body of the mail if you have
    inadvertantly downloaded it.



    Wise advice.

    Quoted message said:

    13] If you complain to a spammer then do not use youe main mail address to send the complaint. Use
    one of the others



    Don't complain to spammers. Ignore them if you don't have the and talent to complain to someone who
    can actually do something about them.

    Quoted message said:

    14] Never CC or Fwd mail.



    Doesn't stop you from getting spam or viruses. Merely gets you into mailboxes of people who are
    following your rule #11

    Quoted message said:

    15] Never send unsolicited mail yourself - to private individuals and do not use your main account
    for 'cold mailing' to others. Not even reputable businesses.



    Doesn't stop you from receiving the [censored]--but it's certainly the civilized way to behave.

    Quoted message said:

    16] Use an AV product - and there are free ones about - which will scan boot up and all mail
    inbound and outbound.



    If you receive "not a single incidence of a virus for over 8 months", why bother?

    Quoted message said:

    17] Use a browser cleaner such as Spybot/Adaware every other day to remove trackers etc. Also
    remove Cookies/History every week.



    I accept cookies only from specific sites and discard them on browser exit. I never take spy-ware,
    so I don't need to remove it.

    Quoted message said:

    18] Disable or remove all internet protocols from your system tha are not essential. Such as
    IPS/SPX and remove Netbios from Networking if you do not need it. For usenet/web and mail you
    only need TCP/IP
    19] Use a firewall - there are free ones available such as Kerio.
    20] Use a 'Port Listener' - again free - to monitor what ports are bing accessed.



    My firewall blocks everything except protocols specifically allowed. And blocks IP addresses owned
    by outfits that refuse to (or can't) shut down their hackers. It also logs what's going on, in, or
    out. (actually, it's supposed to, but after a recent upgrade, logging seems to be broken.)

    Quoted message said:

    21] Never leave your equipment unattended, on and connected.



    I have my reasons for leaving it on. But since it's dial-up, I don't let it keep the phone busy round-the-
    clock. :-)

    Quoted message said:

    22] Unload all Network capability if not in use.



    See above.

    To make a long story short (he should have said that an hour ago) your "minimum" contains items that
    would be inconvenient for me (and possibly others) with NO benefit. It contains others that would
    definitely help the spam/virus problem--at the cost of telling my parents and siblings "Since you
    are computer illiterate, I don't want to hear from you again."

    To make it even shorter: _Y_M_M_V_

  17. Jim Dumas said:

    But you still don't know if the sender's address is valid. You _must_ send

    If it's a friend, I know.

    Quoted message said:

    an email to do this. So my requirement for spammers is a two-way dialog.

    My requirement for spammers is "Get lost" (aka /dev/null)

    Quoted message said:
    Quoted message said:

    A few? I don't need to challenge a message I wanted to receive. The size limit is the _last_ of
    the defenses, and it has only triggered once.

    Even at 50% of incoming spam, it's a deal. What incentive do the spammers

    I did not say fifty percent. I said, "it has only triggered once"

  18. Wes Groleau said:
    Jim Dumas said:

    But you still don't know if the sender's address is valid. You _must_ send

    If it's a friend, I know.

    Quoted message said:

    an email to do this. So my requirement for spammers is a two-way dialog.

    My requirement for spammers is "Get lost" (aka /dev/null)

    Quoted message said:
    Quoted message said:

    A few? I don't need to challenge a message I wanted to receive. The size limit is the _last_ of
    the defenses, and it has only triggered once.

    Even at 50% of incoming spam, it's a deal. What incentive do the spammers

    I did not say fifty percent. I said, "it has only triggered once"

    50% is my guess at how much BrightMail catches. I still have 1 email address that only uses
    BrightMail filtering (and Norton AV) from Earthlink. It is my oldest email address from 2/1997. So
    it gets a large amount of spam. From November, 2003, I've noticed an increase in spam that is
    getting through the BrightMail first filter. I thought it was Xmas advertising related, but it has
    been getting worse in the new year. This gets caught in my linux mailfilter rules. But gives me an
    estimate on how bad spam is: ~4 spam emails per hour getting through BrightMail.

    In any case, the only problem I see with challenge-response is when both parties use it. The
    challenge could get stuck in the "suspected spam list" that gets reported weekly or daily (you set
    this switch). If you visually scan this list and miss the counter-challenge, then we have a
    deadlock. I have yet to experience this problem so am watching for it closely. The deadlock is
    broken if the sender places the recipient's address in the online addressbook before initiating
    first contact. This may be an issue.

    But your problem is how to qualify a new contact, not the old ones,
    --
    Jim Dumas T1 4/86, background retinopathy, rarely hypoglycemic: <1/mo. lispro+R+U+NPH daily,
    moderate exercise, typically <6% HbA1c

  19. willbill said:

    3 Feb 2004 17:08:25 GMT, CeeBee wrote:

    Quoted message said:
    Quoted message said:

    Wes Groleau wrote

    Quoted message said:
    Quoted message said:
    Quoted message said:

    You mistakenly assume I'm as stupid as the spammer.

    Quoted message said:

    I assume nothing. You assume that they are too dumb to understand that your countermeasures
    indicate that they should stop sending _you_.

    Quoted message said:
    Quoted message said:

    Anyone want to do a controlled study?

    Quoted message said:

    The fact that we're all still spammed to death no matter all your ingenious schemes and thoughts
    might make that study very superfluous.

    Quoted message said:

    imo, the spammers who send out these new spam messages to many (all?) of the newsgroups NEVER read
    any responses to their spam post(s)

    Quoted message said:

    so replying to those mass spam postings is a total waste of time

    Quoted message said:

    instead, write to your Federal representatives (House and Senate if you are in the USA)

    In my opinion, that would not be the most useful approach, for two reasons:

    1) Those are the very people responsible for enacting the CAN-SPAM bill which legalizes spam that
    was previously illegal. It also makes the onus of stoppage on the victim. 🙁

    2) Direct complaints to the hosts/ISPs seem to be a better approach. It can be painstaking, but it
    can also be effective.

    Randy

  20. Pete <[email hidden]> wrote: [snippage]

    Quoted message said:

    I have only received 3 spam mails in the last three weeks and not a single incidence of a virus
    for over 8 months. I am begining to find this subject quite amusing.

    Quoted message said:

    The only way to be spam free is to adopt the recommended techniques. As soon as you do - then you
    will see the difference almost immediately. And the best thing of all, there is no way for the
    spammers to get arround it.


    [22 rules snipped]

    There is a far superior system. Do not connect your computer to the internet, ever. I say that
    tongue in cheek, but quite frankly, it is the only way to be sure one's email address does not ever
    attract any spams.

    Randy

Active in the last 60 minutes

Active in this thread

0 users · 0 guests ·0 bots ·0 total

No signed-in users are active right now.

No known search crawlers active right now.