Re: dsbl.org SERIOUS problem

"Christopher Hill" <[email protected]>
Newsgroups gmane.mail.spam.spamcop.email
Organization SpamCop
Message-ID <[email protected]>
OK, this sucks. Turns out that dsbl.org now blocks people for using Internet 
Explorer to visit their site.

Let me qualify that. It blocks people for using any version of IE that has a 
particular vulnerability. Trouble is, there's no patch for that 
vulnerability yet. So you visit dsbl.org with IE and images enabled, even if 
you're totally patched up - you get your email blocked.

Does that sound really really stupid to anyone else?

Here is what I got back from dsbl.org:

> Your browser has a vulnerability that can be exploited by websites you
> visit to send mail from your machine. Try turning off image loading in
> your browser and see if that helps.

And my reply is below. If anyone else thinks this is a bad idea, please tell 
dsbl.org as well. Maybe enough voices will get this through...

Regards,

Chris
--
'Therefore, if anyone is in Christ, he is a new creation;
the old has gone, the new has come!' - 2 Corinthians 5v17
[email protected]

(Reply to dsbl.org quoted:)

OK, so what you've done is set up a policy where anyone that goes to your 
website using ANY version of Internet Explorer (mine is patched with the 
latest available patches), is going to start having problems sending emails 
to certain servers.

That is, you have made it so that 95% of the people who are browsing the 
World Wide Web are going to have problems sending emails, just because they 
visited your site, and 94% of them aren't going to have a clue:
1) That it's even happened, and
2) What to do about it, and
3) If they do know and they are able, they can't fix it yet because the 
patch hasn't been released.

Way to go, man.

Please don't give me yadda yadda yadda about using FireFox or something 
instead. You and I both know that is going to take a *loooong* time. Yes, 
let's say that I switch, but what about the millions of people who are quite 
happy with their insecure Internet Explorer and are too *afraid* to switch? 
And the millions more who think that Internet Explorer *is* the Internet? 
<self appointed NetCop>Well they'll have to learn that Internet Explorer is 
not an option</> Great attitude. How dare these people try to use the 
Internet without a clue? How dare they think it can be as helpful and useful 
and troublefree as switching on a TV or driving their car? I agree that 
there needs to be more education, and people need to learn to patch and 
maintain their computers. Do we really have to make things so difficult for 
them in the mean time by making them have loads of problems with their 
emails that they just don't understand? I say again, people are going to get 
onto dsbl.org and never get off, just because they didn't know.

(By the way, yes it will cause problems for those people, even if they use 
their ISP's SMTP server to send email. I *used* to use dsbl.org for blocking 
on my SpamCop account, and that means that *every* IP address in the 
Received: headers has to be clear of *all* the blocking lists. That includes 
the very first one, the user's computer, not just the SMTP relay server that 
their ISP supplies. So guess what? People visit dsbl.org with the latest 
patched Internet Explorer, and suddenly I don't get their emails any more. 
Great.)

What percentage of poeple will update Internet Explorer when the patch does 
come out? Even with time, you'll be blocking 75% of the people who visit 
your website, just because they happened to visit your website.

Please wake up. That sucks.

How many 'ordinary' users that are visiting your website for *information* 
are never going to get off the dsbl.org list because they don't even know 
they're on it in the first place?

ALL responsible blocklists should ONLY punish people who have been 
negligent - either in configuring their mail server, or in not updating 
their software, or not installing a firewall, or SOMETHING. Not just because 
Microsoft made a programming mistake that we can't even get a patch for yet.

When people hear about this I think they will stop using dsbl.org, unless 
you reverse your policy on this pretty quickly, and unblock the IPs that 
have already been listed in this way. As far as I can see, there's not even 
any mention on your website that you've adopted this policy.

The aim of dsbl.org should *not* be to punish people for using Internet 
Explorer, EVEN WHEN the patch for the vulnerability is released. How much 
spam is actually sent by this method, right now?
Even if you disagree with this, you need to think very, very carefully about 
doing this sort of thing, especially as I was under the impression that 
dsbl.org does NOT do testing of remote computers. This sounds like testing 
of remote computers to me.

Please reconsider. I've done my best in this email to be responsible rather 
than shouting. But what you have done... sucks.

Regards,
Chris
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.