Re: Bouncing Spam
Bert Driehuis <[email protected]>
| Newsgroups | gmane.mail.pine.general |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 21 Mar 2007, Jason wrote: > If you're going to do that I would suggest a challenge-response system > instead, like TMDA. That way once someone confirms their address they > never go through that process again. There's no password to remember to > include - all they do is respond to the automatic message and they are > whitelisted indefinitely. So far I've never had a spammer bother to > get through TMDA. It's not worth their trouble and my friends haven't > had a problem with it either, though I only use it on my more spam-prone > addresses. TMDA seems to send a fresh e-mail containing a challenge to the (often forged) sender of the spam, contributing to the spam problem. If one uses TMDA, it would be highly advantageous to also implement SPF in paranoid mode. Fortunately, not too many people use TMDA. As soon as even just a small percentage of users switch to solutions like TMDA, e-mail will simply grind to a halt -- one system will quaranteen the others challenges (and, as you may have guessed, my response to that situation would be: good riddance :-) At best, C/R is a stopgap, but even today misdirected C/R challenges outnumber legitimate challenges by a vast margin. The only more-or-less correct way to implement Challenge/Response is to do it in-protocol. In other words, to reject the message in SMTP using a rejection such as 5.7.1 Please visit http://cr.example.com/id=123456 to unlock My perspective may be a bit different than that of many Pine users -- I'm Postmaster for a large corporation that operates worldwide, so I get to see more crap than most. Due to a significant number of complaints, I have already had to block one commercial challenge/response vendor (not a tough decision; they were also spamming my users). Some Postmasters, usually for smaller sites, go one step further and say that even a single misdirected challenge is grounds for blacklisting -- after all, your spam problem shouldn't have to become their spam problem. There are no easy solutions to the spam problem. _______________________________________________ Pine-info mailing list [email protected] http://mailman1.u.washington.edu/mailman/listinfo/pine-info