Re: Water tight opt-in (yet another FUSSP)

Barry Shein <[email protected]> Sun, 12 Jan 2014 23:29:42 -0500
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
From: "Neil Schwartzman" <[email protected]>
>HISTORICAL
>The problem of botnet spam hitting recipient mailboxes has been solved, =
>or at least remediated to the point that it is pretty much a non-issue.

Hitting the wire continues to be a problem.

We still see headlines about "huge botnet shut down", why do they
operate?

Althought botnets are a particularly pernicious vector they seem to
move on to other methods also such as exploiting holes in web site
software in large numbers.

>CURRENT
>Affiliate spam is a problem. the follow-the-money r=E9gime of Canada=92s =
>Anti-Spam Legislation will have a very chilling effect on such programs. =
>DirecTV will be held accountable for spam sent in their name; at =
>$10,000,000 per email. Problem solved.

Well, potentially solved, but good news.

>Account-take over (tickling tiny amounts of spam out over illicit =
>accounts and accounts with compromised credentials)=20
>Still a problem=20

I guess a form of snowshoe-ing and probably related to my earlier
comment about exploiting those zillions of web sites at hosting
companies whenever they find a hole in some popular web site package.

>Spam from legitimate companies
>As noted before CANSPAM, the EU Privacy Directive and CASL cover this =
>well, CASL gives enforcement agencies the tools, and the threat to use =
>them. FYI, I am conducting a statistical study to see the effect of the =
>law for the Canadian Government.

One of my interests is more in the realm of what happens when you're
just overwhelmed by email which is reasonably legitimate under current
definitions.

But I can't argue the future if others don't see it that way.

I suppose we'll have to wait and see and perhaps I'll get to say "I
told you so!" in a few years.

But "free" has always had a certain appeal, even among those with
honorable intentions.

>Phishing/Spear Phishing
>Big problem

Indeed.

We can throw in email with embedded viruses which very lately seems to
have gained a burst in popularity, some gang I assume.

Anyone see the incessant "Your Court Date" and similar in the past few
weeks with embedded zip files with viruses?

I believe popular anti-virus programs warned/blocked, they weren't
particularly sophisticated.

But of course they're fishing (not phishing) for vulnerable sites.

I assume for botnets.

But botnets is solved? Confusing.

>Mobile Spam
>Huge in Asia/Africa, we=92ve only seen the leading edge of it in North =
>America. The spam is about to hit the fan bigtime.

I agree.

>FUTURE
>Social media spam
>Big problem now, will become a huge problem over the next three years

I agree, it's a greenfield.

>IPv6 mail
>John says it is a thing, Richard says it isn=92t.
>
>I think it is a thing and will become a huge thing as developing nations =
>decide they don=92t want to grovel for IPv4 IP space.

I think it's a thing.

It's likely to provide more address mobility and that's the
stock-in-trade of a lot of the worst spammers.

Related is CGN, commercial grade NAT, which covers a lot of the mobile
world.

I suspect it helps as much as it hurts, it forces gazillions of
devices through an ISP's NAT architecture where it can be inspected
and filtered.

Merely unusually high traffic patterns might in a perfect world
attract attention -- a phone no matter how smart sending out many
emails per minute for many minutes ought to raise a flag.

OTOH it provides amplification opportunities. Those CGNs are attached
to big honking pipes at places like Verizon or NTT et al.

Although not spam per se we just saw NTP ampification DDoS attacks in
the past few weeks:

  http://arstechnica.com/security/2014/01/dos-attacks-that-took-down-big-game-sites-abused-webs-time-synch-protocol/

or

  http://tinyurl.com/ojmfbts

>I personally believe we will go to an all-whitelist world, wherein most =
>IPv6 space will be in deny ACL tables.

It's a big space and will probably get very complicated.

As an aside, that's why simple address expansions like IPv6 are
doomed, they become segmented, this many bits devoted to this and that
many bits devoted to that de facto or de (um, standardo?)

So any white list might have to understand an ever growing
efflorescence of, for example, service providers and sub-service
providers carving up of address space as roles get farmed out
globally.

>Bottom line for me? If you want to be talking about anything at all =
>forward thinking - social, mobile, and IPv6. Everything else has the =
>benefit of almost 20 years work on it, and is well fixed, or at least =
>fixed to as best a point as we can hope to do (yes, of course both =
>spammers and spam filter makers will innovate).

Really only if you limit the discussion to what's hitting the mailbox
and technical or sledgehammer legal approaches which no doubt work for
some things (if spam is outlawed only outlaws will spam.)

What ties them all together, potentially, is any economic ecology
which shifts the game. But that's a hard row to hoe.

-- 
        -Barry Shein

The World              | [email protected]           | http://www.TheWorld.com
Purveyors to the Trade | Voice: 800-THE-WRLD        | Dial-Up: US, PR, Canada
Software Tool & Die    | Public Access Internet     | SINCE 1989     *oo*
-
This is the asrg mailing list.  To change your subscription settings, see
http://lists.services.net/cgi-bin/mj_wwwusr/domain=lists.gurus.org