Re: Let's try to be productive...

Steve Atkins <[email protected]> Sun, 5 Jan 2014 20:13:58 -0800
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On Jan 5, 2014, at 7:26 PM, Barry Shein <[email protected]> wrote:

>=20
> Ok, if we do these tit-for-tats nothing will be accomplished.
>=20
> It's too easy to take some overly literal interpretation of someone
> else's words and spin a rebuttal. And paragraphs of anecdotes from
> one's own mailbox really isn't useful either, maybe you're just lucky?
>=20
> That said:
>=20
> What's a current taxonomy of what we're trying to deal with?
>=20
> If I may be so bold, what can we agree on, where should effort be
> expended:
>=20
> 1. High volume "bulk" mailers with no discernible business
>   relationship with intended recipients whose intentions may or may
>   not be per se malicious.
>=20
>   e.g., Hawking herbal viagra -- if that's really what you get it's
>   not necessarily malicious. Doing it to a billion mailboxes per day
>   unsolicited is a problem. Hawking what appears to be a product
>   which is in high rotation on late night TV (e.g., those expandable
>   hoses) when all you want is a credit card number to abuse is
>   malicious and a problem.
>=20
> 2. Phishers -- those who specifically create deceptive email intended
>   to lure recipients into a position of trust soas to defraud them.
>=20
> 3. Direct fraudulent or trust appeals such as 419 ("Nigerian Scam".)
>   Also falsely appearing to be a legitimate charity and similar (or
>   is that a separate category?)
>=20
> 4. High volume unsolicited or questionably solicited (according to
>   CAN-SPAM or other similar standards) email even if from a
>   verifiably legitimate source (green card type spam.) Let's call
>   this spam by unscrupulousness.
>=20
> 5. What about email dictionary attacks and similar?
>=20
>   e.g., I'll see connections for [email protected],
>   [email protected] etc, hundreds per minute, or just what looks
>   like pick-a-random-mailbox or next in a large list and attach
>   @theworld.com, again hundreds per minute.
>=20
> 6. What appears to be purely malicious or hard to discern very high
>   volume email.
>=20
>   e.g., empty or indecipherable or trite ("hello!") bodies and/or
>   subjects.

(5) I consider to be a net-positive rather than a problem. It=92s
miscreants providing you, at no cost, with a list of their compromised
or spamming machines.

Other than that, all of the above. I=92d add malware emails, as a higher
urgency than any of the above, as they=92re part of the positive feedback
loop that makes more bots, which send more problematic mail.

(On a personal level, I don=92t care as much about (2) or (3) unless it lea=
ds
to the recipients machines being compromised, as anyone who
falls prey for phishes will probably fall prey to some other scam
even we eliminate phishing altogether. But when I=92m trying to be
professional they=92re still a concern.)

I have more concern about mail that=92s coming from senders
who send a mix of wanted and unwanted email, as opposed
to senders of 99%+ unwanted email, as it=92s much harder to
reliably mechanically mitigate. They=92re not really a large
fraction of the problem right now, though (other than exceptions
like Amazon, Yahoo and Google).

>=20
> What am I missing? Assuming one needs to start somewhere where would
> we start?
>=20
> There's also a broader category implied by the above:
>=20
>  A. Spam which hits end-users' mailboxes.
>=20
>  B. Spam which is blocked but represents bandwidth and storage problems
>     to service providers and the net in general.
>=20
> Those last two, A & B, are in my experience on lists like this very
> important because they tend to separate people on these lists.

They=92re both issues. (B) is more painful in the short term to anyone runn=
ing
an email system (but of negligible interest to anyone else) if
you include the effort and resources expended on spam filtering and associa=
ted
issues; (A) is more damaging to email in the medium to long term, and
a higher pain point to anyone at an ISP who isn=92t running the email syste=
m.

Cheers,
  Steve

>=20
> Those not particularly concerned with (B) tend to only want to focus
> on (A), if it doesn't hit my box it's not important.
>=20
> Those concerned with (B) tend to be interested in both as they tend to
> be service providers.
>=20
> Wikipedia has an article on "Email spam" which lists some of these but
> tends to be more descriptive (e.g., talks about legality and countries
> of origin.)
>=20
>    http://en.wikipedia.org/wiki/Email_spam
>=20
> --=20
>        -Barry Shein
>=20
> The World              | [email protected]           | http://www.TheWorld=
.com
> Purveyors to the Trade | Voice: 800-THE-WRLD        | Dial-Up: US, PR, Ca=
nada
> Software Tool & Die    | Public Access Internet     | SINCE 1989     *oo*
> -
> This is the asrg mailing list.  To change your subscription settings, see
> http://lists.services.net/cgi-bin/mj_wwwusr/domain=3Dlists.gurus.org

-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=3Dlists.gurus.org