Re: BlueSecurity/Blue Frog
"Vanguard" <[email protected]> Fri, 12 May 2006 02:53:53 -0500
| Newsgroups | gmane.mail.spam.spamcop.user |
|---|---|
| Organization | SpamCop |
| Message-ID | <[email protected]> |
"Geoffrey Hyde" <[email protected]> wrote in message news:[email protected]... > > "Vanguard" <[email protected]> wrote in message > news:[email protected]... > >> Not when you are vicious and attacking someone else and causing >> collateral damage in the process. BS works through a coordinated DOS >> attack from its zombied users. They aren't just hurting the spammer. > > I fail to see where you have offered conclusive proof that BS > computers are "zombied" users. From what I can see, the program is of > a type which the user can uninstall if they choose to do so. If you > have conclusive evidence to the contrary, please post it here. Have you read BS' own FAQ on how their service works? The user installs a client program. The user reports a spam to BS who will supposedly interrogate your mail by their team of specialists. They decide who to attack, not the user. They upload a script to the BS client on your host. BS decides what the script will do, not the user. BS decides when to attack and who to attack, and the user may not even be involved. That is how zombies function. A master zombie tells slave zombies what to do and without having the user involved. A zombie doesn't need to be covertly installed. A zombie doesn't have to be non-uninstallable. In the past, zombies were malicious to someone OTHER than the host that was zombied; i.e., they attacked someone else. And that is what BS' client on your host does at the behest of BS to do whatever BS wants. There is collusion between the user and BS because BS supposedly won't initiate the DOS attack until the user says to. "Users may choose to let the Blue Frog be active at all times, only when their computer is idle or launch it manually at their own discretion." So which mode do you think most BS users will enable? The always-on option (and doing it while idle is still always-on). "Users ... may choose to abort Blue Frog's execution at any time." So does the BS client stop at a prompt and wait forever until the user responds, or does it timeout (i.e., it won't wait indefinitely) and go ahead without user intervention? Since it is supposedly a choice, is the default option to not prompt or to prompt the user? If the default is not to prompt, or if it is to prompt but continue after a timeout, the DOS will occur in the absence of the user. > And they go to an extensive length to identify a spammer - something I > have not seen elsewhere on the net, other than SC, which simply > reports emails and analyzes headers for things like blackhat ISPs, > open relay mail servers, etc. There may be other agenda here. If BS were to attack someone with power and deep pockets, they would be sued just like any other malcontent DOS'ing that domain. AOL, Earthlink, Comcast, and other major ISPs don't give a gnat's fart about the professed intention of BS regarding the DOS attack. A DOS attack is still a DOS attack and harms the resources of the domain. DOS'ing a particular web site still incurs a DOS attack on the domain that has to handle all those connect requests. Other sites using the same webhost provider will have problems with users or visitors getting access to them when the webhost provider is being attacked (for one of the other sites on that domain). > While I may appear to be supporting BS users, I do not. However, they > seem to be going to an extraodinary length to get spammers shut down. > Which is in the final analysis a good thing. The method hurts others. Collateral damage is never condoned. You aren't allowed, even when granted police authority, to shotgun through a crowd to catch a fleeing criminal. The end does not NOT always justify the means, especially when other methods are available. I'm sure women afflicted with breast cancer would prefer a procedure that doesn't hack off part of their body. Fortunately there other procedures for handling spam that are less drastic and don't hurt innocents. The argument that the end justifies the means is used by extremists, terrorists, vigilantes, and children - but only if they are not the collateral damage (i.e., unless highly altruistic or sacrificial, their story and opinion changes drastically when *they* are the innocent victims of the assault). > If you are going to post a blatant attack without offering some > conclusive proof to offer it up (in this case that BS users have > zombied machines) please remember that your attack brings with it > consequences, and it also means you have the responsibility to back > your claims up to other posters in this newgroup. Actually I didn't mean to make it an attack, especially since this is the only group and only thread in which I am responding to BS' behavior and tactics. It just strikes me as a childish, petulant, and egotistic approach. As said, those who see it as a great solution are those that proclaim "works for me" without concern what it does to others and where those others include innocents. I see problems with C-R and bogus bounces, and I see problems with BS, too. Just because spam is a problem doesn't mean that I want another problem in addition to spam. > At the moment you are little better than a troll which posts in order > to gain pleasure. If you wish to continue this futile method of > posting unsubstantiated claims please be aware that other intelligent > users of this newsgroup may start to ignore you. Okay, so now it is time to substantiate your claims. "They have gone to extreme length to identify a spammer." Actually, as with SpamCop, they fall back on that it was the *user* that claimed the mail was spam. If they target an innocent, it was the users' fault, not theirs. Spamcop's parsing isn't perfect. Note that Spamcop DOES NOT send any spam notice to the targets that it determines until after the user decides to send that message (I am not familiar with the Spamcop e-mail service but only with their spam reporting service). It is the responsibility of the user to know that the recipients of the spam abuse message are the correct recipients. It is BS that is deciding who to DOS using the zombies on their customers hosts after the BS user reports a mail as spam. If BS is using something similar to SpamCop, there is no extreme length taken unless they are personally inspecting every spam. There aren't that many employees at BS to handle all those spam reports so they must be using scripts to parse out the spamvert URLs. They claim to have something like 450,000 users. If only 5% got spammed one unique message per day, they would have to personally inspect 22,500 suspect mails per day. With coffee, lunch, and restroom breaks, they might have 6 hours a day. Let's say they were really good and could open, visually inspect, manually parse, and database about 4 suspect mails per minute so they could "expertly analyze" maybe 1,440 suspect mails per day. That means they would need 16 employees dedicated to only that task. >From what I've read, BS is a pretty small company, and I was being very conservative on the volume of suspect mails that they would have to analyze and how fast they could analyze a suspect mail. So they are very likely using scripts to parse out URLs in the body of the mails, just like SpamCop does, to find spamvertized sites. I don't consider that to be "extensive lengths to identify a spammer". If BS is going to such great length to prevent their customers from getting spam, please explain their statement, "[Coordinated opt-out] Requests are not posted by Businesses and organizations that added their e-mail domains to the Do Not Intrude Registry through Blue Security's paid business offering." I suspect "posted by" is really "posted to" as there would be no reason that any entity that subscribed to BS would not want to report spam. If you were a business that subscribed to BS, why would you suddenly also decide to cease reporting spam? So if you want to spam and not bother with getting DOS'ed by BS then bribe BS to exclude your "business". Wow, now there is a conflict of interest. I could not find a description of the "paid business offering" from BS. It sounds eerily reminiscent of some ISP's scheme to let businesses to pay them for guaranteed delivery of spam; i.e., if the spammer is willing to pay the ISP then the ISP will guarantee that source gets their mail past all filters and user-defined blacklists. The spammer then can force spam down your throat if they choose to pay for that privilege (much like Phillips idea to not allow you to change your television channel when the commercial comes on unless you paid for the commercial-free version of the show). "Blue Security provides a set of Registry Compliance Tools allowing merchants, spammers and direct e-mail marketers to easily clean their mailing lists of addresses registered in the Do Not Intrude Registry. These tools hash the spammer's original mailing list and compare each entry with the hashed entries in the Registry. A new, registry-compliant, mailing list is then created by removing entries from the original mailing list that matched entries in the Do Not Intrude Registry." Gee, now think about it. You're a spammer. You have your full list of spamees in your original list. You then sanitize that list to remove the BS users in the BS registry. Now all you have to do is compare your original list with the sanitized one to see which e-mail addresses were removed. Duh! No rocket science needed at all to use a file diff tool. That's how the spammer probably got the e-mails of the BS users to send them the harassing mails. If you subscribe to BS, your e-mail address WILL be known as a BS subscriber to anyone that gets their mailing list sanitized. "When a spammer notices that an e-mail address has been deleted from his list, he has no way of knowing if it was filtered because it was a legitimate user's e-mail address, a honeypot address or a random entry in the hashed Registry." So what? Spammers already don't care if they send to random entries (i.e., invalid e-mail addresses). Spammers usually don't care about honeypots since they will eventually change to a different domain, especially if proxied, and why blacklists get outdated so they must be dynamic enough to reflect the current state of spam sources. Someone that wants to harass BS users doesn't mind sending their assault mails to invalid e-mail addresses or honeypots because they know the BS users are also included in the entries that were removed. How well BS works in providing a responsible anti-spam solution depends on how well they manage to NOT hurt innocents. I don't see how any DOS attack against a domain cannot hurt innocents. The level of their DOS attack depends on the number of reported spams. The more users that report a particular spam then the bigger the size of the DOS attack against the spamvertised site. So as their customer size grows so does the size of their attack. Eventually BS may exceed a threshold beyond which ISPs will no longer tolerate the abuse from BS. If BS follows its claim that only 1 opt-out gets sent per user reporting the spam then the spamvertised site should expect to receive, at a maximum, as many opt-outs as then send in spam mails. Well, that assumes the sender is a marketer that wants to protect their permanent site rather than a spammer that doesn't care about the domain where they are temporarily hosting their spamvertized site. The spammer doesn't care about their recipients of their spew but you expect them to care about their webhost provider? The 1 opt-out request per BS user per spam sounds great but it still accrues to a DOS attack against the site from the aggregate and concerted attack from all BS users, and that hurts others than just the spamvertised site. Since the spammer doesn't care about opt-outs, what is to force the spammer to even provide for opt-outs? Why couldn't the spammer redirect those requests to someone else, like to BS's host provider or to some innocents postmaster? I'm not saying the BS hasn't tried to install some safeguards into their scheme. I've read their FAQs and, if true, then they are trying to ensure their DOS attack targets only valid spam sources. They may have a handle on how to accurately identify spam sources, but then so do some (but not all) of the DNSBLs. However, I don't condone DOS attacks for any purpose because others will be hurt by it besides the targeted site. Right now, the effects and results of BS are merely interesting but as they grow and their DOS attacks become larger they will become just another pest on the Net. If, like Spamcop, it is the user that is required to decide if the recipients of the opt-out request are the valid recipients then BS isn't much worse than SpamCop (since stupid users using SpamCop end up sending invalid abuse reports to already overtaxed mail admins). However, from what I've read, that is NOT the kind of expert user that BS is lulling into their customerbase. The BS user claims the mail is spam (and too many users lump undesirable mails into the spam category) so BS doesn't have a choice after that other than to somehow yank out the spamverts and then tell the user's zombied host to go participate in the DOS attack. The BS user simply wants to push a button to tag a mail as spam and not bother with having to do anything thereafter. An uneducated and lazy mob is probably not the best tool to accurately identify spam sources. I wasn't impressed with SpamNet's voting scheme, either, but their action was to block rather than attack. Spraying the air above the kitchen or dining table while eating to get rid of the flies that are bothering you will probably work very well, but then the dead flies and insecticide fall into your food. So you killed the flies and poisoned your food. With BS, and assuming they are effective, you get rid of or hurt the spammer but you've harmed more than just that site.