Re: BlueSecurity/Blue Frog

"Vanguard" <[email protected]> Fri, 12 May 2006 02:53:53 -0500
Newsgroups gmane.mail.spam.spamcop.user
Organization SpamCop
Message-ID <[email protected]>
"Geoffrey Hyde" <[email protected]> wrote in message 
news:[email protected]...
>
> "Vanguard" <[email protected]> wrote in message 
> news:[email protected]...
>
>> Not when you are vicious and attacking someone else and causing 
>> collateral damage in the process.  BS works through a coordinated DOS 
>> attack from its zombied users.  They aren't just hurting the spammer.
>
> I fail to see where you have offered conclusive proof that BS 
> computers are "zombied" users.  From what I can see, the program is of 
> a type which the user can uninstall if they choose to do so.  If you 
> have conclusive evidence to the contrary, please post it here.

Have you read BS' own FAQ on how their service works?  The user installs 
a client program.  The user reports a spam to BS who will supposedly 
interrogate your mail by their team of specialists.  They decide who to 
attack, not the user.  They upload a script to the BS client on your 
host.  BS decides what the script will do, not the user.  BS decides 
when to attack and who to attack, and the user may not even be involved. 
That is how zombies function.  A master zombie tells slave zombies what 
to do and without having the user involved.  A zombie doesn't need to be 
covertly installed.  A zombie doesn't have to be non-uninstallable.  In 
the past, zombies were malicious to someone OTHER than the host that was 
zombied; i.e., they attacked someone else.  And that is what BS' client 
on your host does at the behest of BS to do whatever BS wants.  There is 
collusion between the user and BS because BS supposedly won't initiate 
the DOS attack until the user says to.

"Users may choose to let the Blue Frog be active at all times, only when 
their computer is idle or launch it manually at their own discretion." 
So which mode do you think most BS users will enable?  The always-on 
option (and doing it while idle is still always-on). "Users ... may 
choose to abort Blue Frog's execution at any time."  So does the BS 
client stop at a prompt and wait forever until the user responds, or 
does it timeout (i.e., it won't wait indefinitely) and go ahead without 
user intervention?  Since it is supposedly a choice, is the default 
option to not prompt or to prompt the user?  If the default is not to 
prompt, or if it is to prompt but continue after a timeout, the DOS will 
occur in the absence of the user.

> And they go to an extensive length to identify a spammer - something I 
> have not seen elsewhere on the net, other than SC, which simply 
> reports emails and analyzes headers for things like blackhat ISPs, 
> open relay mail servers, etc.

There may be other agenda here.  If BS were to attack someone with power 
and deep pockets, they would be sued just like any other malcontent 
DOS'ing that domain.  AOL, Earthlink, Comcast, and other major ISPs 
don't give a gnat's fart about the professed intention of BS regarding 
the DOS attack.  A DOS attack is still a DOS attack and harms the 
resources of the domain.  DOS'ing a particular web site still incurs a 
DOS attack on the domain that has to handle all those connect requests. 
Other sites using the same webhost provider will have problems with 
users or visitors getting access to them when the webhost provider is 
being attacked (for one of the other sites on that domain).

> While I may appear to be supporting BS users, I do not.  However, they 
> seem to be going to an extraodinary length to get spammers shut down. 
> Which is in the final analysis a good thing.

The method hurts others.  Collateral damage is never condoned.  You 
aren't allowed, even when granted police authority, to shotgun through a 
crowd to catch a fleeing criminal.  The end does not NOT always justify 
the means, especially when other methods are available.  I'm sure women 
afflicted with breast cancer would prefer a procedure that doesn't hack 
off part of their body.  Fortunately there other procedures for handling 
spam that are less drastic and don't hurt innocents.  The argument that 
the end justifies the means is used by extremists, terrorists, 
vigilantes, and children - but only if they are not the collateral 
damage (i.e., unless highly altruistic or sacrificial, their story and 
opinion changes drastically when *they* are the innocent victims of the 
assault).

> If you are going to post a blatant attack without offering some 
> conclusive proof to offer it up (in this case that BS users have 
> zombied machines) please remember that your attack brings with it 
> consequences, and it also means you have the responsibility to back 
> your claims up to other posters in this newgroup.

Actually I didn't mean to make it an attack, especially since this is 
the only group and only thread in which I am responding to BS' behavior 
and tactics.  It just strikes me as a childish, petulant, and egotistic 
approach.  As said, those who see it as a great solution are those that 
proclaim "works for me" without concern what it does to others and where 
those others include innocents.  I see problems with C-R and bogus 
bounces, and I see problems with BS, too.  Just because spam is a 
problem doesn't mean that I want another problem in addition to spam.

> At the moment you are little better than a troll which posts in order 
> to gain pleasure.  If you wish to continue this futile method of 
> posting unsubstantiated claims please be aware that other intelligent 
> users of this newsgroup may start to ignore you.

Okay, so now it is time to substantiate your claims.  "They have gone to 
extreme length to identify a spammer."  Actually, as with SpamCop, they 
fall back on that it was the *user* that claimed the mail was spam.  If 
they target an innocent, it was the users' fault, not theirs.  Spamcop's 
parsing isn't perfect.  Note that Spamcop DOES NOT send any spam notice 
to the targets that it determines until after the user decides to send 
that message (I am not familiar with the Spamcop e-mail service but only 
with their spam reporting service).  It is the responsibility of the 
user to know that the recipients of the spam abuse message are the 
correct recipients.  It is BS that is deciding who to DOS using the 
zombies on their customers hosts after the BS user reports a mail as 
spam.  If BS is using something similar to SpamCop, there is no extreme 
length taken unless they are personally inspecting every spam.  There 
aren't that many employees at BS to handle all those spam reports so 
they must be using scripts to parse out the spamvert URLs.  They claim 
to have something like 450,000 users.  If only 5% got spammed one unique 
message per day, they would have to personally inspect 22,500 suspect 
mails per day.  With coffee, lunch, and restroom breaks, they might have 
6 hours a day.  Let's say they were really good and could open, visually 
inspect, manually parse, and database about 4 suspect mails per minute 
so they could "expertly analyze" maybe 1,440 suspect mails per day. 
That means they would need 16 employees dedicated to only that task. 
>From what I've read, BS is a pretty small company, and I was being very 
conservative on the volume of suspect mails that they would have to 
analyze and how fast they could analyze a suspect mail.  So they are 
very likely using scripts to parse out URLs in the body of the mails, 
just like SpamCop does, to find spamvertized sites.  I don't consider 
that to be "extensive lengths to identify a spammer".

If BS is going to such great length to prevent their customers from 
getting spam, please explain their statement, "[Coordinated opt-out] 
Requests are not posted by Businesses and organizations that added their 
e-mail domains to the Do Not Intrude Registry through Blue Security's 
paid business offering."  I suspect "posted by" is really "posted to" as 
there would be no reason that any entity that subscribed to BS would not 
want to report spam.  If you were a business that subscribed to BS, why 
would you suddenly also decide to cease reporting spam?  So if you want 
to spam and not bother with getting DOS'ed by BS then bribe BS to 
exclude your "business".  Wow, now there is a conflict of interest.  I 
could not find a description of the "paid business offering" from BS. 
It sounds eerily reminiscent of some ISP's scheme to let businesses to 
pay them for guaranteed delivery of spam; i.e., if the spammer is 
willing to pay the ISP then the ISP will guarantee that source gets 
their mail past all filters and user-defined blacklists.  The spammer 
then can force spam down your throat if they choose to pay for that 
privilege (much like Phillips idea to not allow you to change your 
television channel when the commercial comes on unless you paid for the 
commercial-free version of the show).

"Blue Security provides a set of Registry Compliance Tools allowing 
merchants, spammers and direct e-mail marketers to easily clean their 
mailing lists of addresses registered in the Do Not Intrude Registry. 
These tools hash the spammer's original mailing list and compare each 
entry with the hashed entries in the Registry. A new, 
registry-compliant, mailing list is then created by removing entries 
from the original mailing list that matched entries in the Do Not 
Intrude Registry."  Gee, now think about it.  You're a spammer.  You 
have your full list of spamees in your original list.  You then sanitize 
that list to remove the BS users in the BS registry.  Now all you have 
to do is compare your original list with the sanitized one to see which 
e-mail addresses were removed.  Duh!  No rocket science needed at all to 
use a file diff tool.  That's how the spammer probably got the e-mails 
of the BS users to send them the harassing mails.  If you subscribe to 
BS, your e-mail address WILL be known as a BS subscriber to anyone that 
gets their mailing list sanitized.  "When a spammer notices that an 
e-mail address has been deleted from his list, he has no way of knowing 
if it was filtered because it was a legitimate user's e-mail address, a 
honeypot address or a random entry in the hashed Registry."  So what? 
Spammers already don't care if they send to random entries (i.e., 
invalid e-mail addresses).  Spammers usually don't care about honeypots 
since they will eventually change to a different domain, especially if 
proxied, and why blacklists get outdated so they must be dynamic enough 
to reflect the current state of spam sources.  Someone that wants to 
harass BS users doesn't mind sending their assault mails to invalid 
e-mail addresses or honeypots because they know the BS users are also 
included in the entries that were removed.

How well BS works in providing a responsible anti-spam solution depends 
on how well they manage to NOT hurt innocents.  I don't see how any DOS 
attack against a domain cannot hurt innocents.  The level of their DOS 
attack depends on the number of reported spams.  The more users that 
report a particular spam then the bigger the size of the DOS attack 
against the spamvertised site.  So as their customer size grows so does 
the size of their attack.  Eventually BS may exceed a threshold beyond 
which ISPs will no longer tolerate the abuse from BS.  If BS follows its 
claim that only 1 opt-out gets sent per user reporting the spam then the 
spamvertised site should expect to receive, at a maximum, as many 
opt-outs as then send in spam mails.  Well, that assumes the sender is a 
marketer that wants to protect their permanent site rather than a 
spammer that doesn't care about the domain where they are temporarily 
hosting their spamvertized site.  The spammer doesn't care about their 
recipients of their spew but you expect them to care about their webhost 
provider?  The 1 opt-out request per BS user per spam sounds great but 
it still accrues to a DOS attack against the site from the aggregate and 
concerted attack from all BS users, and that hurts others than just the 
spamvertised site.  Since the spammer doesn't care about opt-outs, what 
is to force the spammer to even provide for opt-outs?  Why couldn't the 
spammer redirect those requests to someone else, like to BS's host 
provider or to some innocents postmaster?

I'm not saying the BS hasn't tried to install some safeguards into their 
scheme.  I've read their FAQs and, if true, then they are trying to 
ensure their DOS attack targets only valid spam sources.  They may have 
a handle on how to accurately identify spam sources, but then so do some 
(but not all) of the DNSBLs.  However, I don't condone DOS attacks for 
any purpose because others will be hurt by it besides the targeted site. 
Right now, the effects and results of BS are merely interesting but as 
they grow and their DOS attacks become larger they will become just 
another pest on the Net.  If, like Spamcop, it is the user that is 
required to decide if the recipients of the opt-out request are the 
valid recipients then BS isn't much worse than SpamCop (since stupid 
users using SpamCop end up sending invalid abuse reports to already 
overtaxed mail admins).  However, from what I've read, that is NOT the 
kind of expert user that BS is lulling into their customerbase.  The BS 
user claims the mail is spam (and too many users lump undesirable mails 
into the spam category) so BS doesn't have a choice after that other 
than to somehow yank out the spamverts and then tell the user's zombied 
host to go participate in the DOS attack.  The BS user simply wants to 
push a button to tag a mail as spam and not bother with having to do 
anything thereafter.  An uneducated and lazy mob is probably not the 
best tool to accurately identify spam sources.  I wasn't impressed with 
SpamNet's voting scheme, either, but their action was to block rather 
than attack.

Spraying the air above the kitchen or dining table while eating to get 
rid of the flies that are bothering you will probably work very well, 
but then the dead flies and insecticide fall into your food.  So you 
killed the flies and poisoned your food.  With BS, and assuming they are 
effective, you get rid of or hurt the spammer but you've harmed more 
than just that site.