Re: BlueSecurity/Blue Frog

"Vanguard" <[email protected]> Fri, 12 May 2006 16:42:25 -0500
Newsgroups gmane.mail.spam.spamcop.user
Organization SpamCop
Message-ID <[email protected]>
Say BlueSecurity (BS) does what they claim to do.  That is, say BS' 
function is to actually automate the process of submitting opt-out 
requests from its users to the source of a spam mail (or any undesirable 
mailing that provides for opt-out).  That means users of BS must 
subscribe to the concept that opt-outs work; i.e., the user of BS must 
truly believe that opt-outs by themselves and singly will work to get 
them off a mailing list (that the spammer actually honors those opt-out 
requests) because, after all and according to BS' claims, BS will only 
send the single opt-out request from the user for a particular spam 
mail.  That's not how BS is used or intended to be used but just let's 
say BS and its users are good netizens practicing their right to opt-out 
from a mailing list and that the spammers are also good netizens (which 
is made impossible by the fact that they spam) by honoring the opt-outs 
and have somewhere for all those opt-outs to go (to the spammer and not 
somewhere else).  If BS users do not believe that single opt-outs work 
(which seems to be why they are using BS to provide a coordinated 
attack) or that the spam source does not honor those requests then BS 
and its users are hiding behind a cloak to disguise their punitive DOS 
attack as an opt-out process.  Okay, so assuming BS and its users are 
good netizens exercising their right to opt-out and that they really 
believe the spammers will honor opt-outs (okay, okay, you can stop 
laughing now) then that means the opt-outs would be generated by the 
recipients of spam as fast as they got the spam or very soon thereafter. 
The precept of opt-outs is that you opt-out right after getting the 
undesirable mail (which may or may not be spam).  No user goes 
collecting their spams over a period of hours, days, weeks, or months to 
then collate them so they are grouped by the same spam source and only 
after a long time later then goes submitting opt-outs.  If they submit 
opt-outs, they do so right after getting the undesirable mail.  You just 
know that is not how BS works simply because individuals separately 
submitting opt-outs as they receive the undesirable mails has not worked 
in the past to reduce spam traffic.  The flood of single request opt-out 
traffic engendered by spam mails from a particular source from one 
recipient has not been sufficient to punish that source.  If that had 
worked, no one would need BS.

While getting a graph of the volume of mail traffic generated for a 
particular spam sent by the source is probably not available, BS has its 
database from which could be graphed the rate of reports and which can 
also be tracked for a particular spam (or for all spams for a particular 
source).  That way you could see how fast recipients were reporting a 
particular mail as spam.  If BS and its users were really the good 
netizens they claim to be then the rate of opt-out submissions from BS 
(by them uploading their script to their zombied hosts) would be a 
mirror image of the incidence graph (i.e., the reports from BS users). 
Okay, so there would be a shift in the graph to the right to reflect the 
delay in BS supposedly analyzing the spam to determine to which targets 
to send the opt-outs and write the script to have their zombied user 
hosts do the HTTP process to fill out the opt-out forms (which assumes 
spammers even have one - which brings up the point of what does BS do 
with their supposed opt-out requests when a site has no opt-out 
procedure).  If BS were really just helping its users to automate the 
opt-out requests, you'd have the graph of the the users' reports for a 
particular spam - and the graph of BS' opt-out request traffic would be 
a near match to it.  The users report a particular spam, there is a 
small delay before BS takes action so there is a short overspike when BS 
finally starts to send out opt-outs due the the pent up reports 
previously submitted, and then the spike immediately drops to match the 
incidence graph.  Obviously that is not how BS works because that is how 
the volume of opt-out traffic would've occurred before BS even existed, 
and that volume was trivial and didn't impact spammers.

So does anyone know if that is how the volume of opt-outs flow from BS 
(using the "good" graph where opt-out traffic from BS matches the 
incidence report traffic)?  From what I read at their site, it is up to 
BS to decide when to send their opt-out requests, and it appears they 
are storing them up so they can then flood the target(s) all at once 
rather than accurately reflect the incoming volume of reports from the 
BS users.  Recipients have the right to opt-out from mailing lists. 
Apparently BS users believe that opt-outs from spammers actually work. 
That is, opt-ing out from a spammer is, according to the BS user, a 
solution.  Fact is, opting out has NOT been an effective solution 
because a single opt-out sent from a single recipient for a single 
incidence of a particular spam mail has no effect on a spammer and their 
spamvertised web site.  So BS users work collectively to punish the 
spammer but their opt-out traffic has to be pent up so a flood of it can 
be slammed at the spamvertized site rather than the normal flood from 
users opting out that never had BS before.  If the volume of opt-out 
requests from BS doesn't match the volume of incidence reports from BS 
users then BS' intent is NOT to automate the opt-out process.  If the 
graph of BS' opt-out volume, with a small catch up spike due to the 
delay to analyze and script, doesn't mirror the graph of incidence 
reports from BS users then BS is *not* being the good netizen in helping 
to automate those opt-out requests.  They are instead abusing opt-outs 
by storing them until enough are available to perform a shorter term and 
even larger flood against the spam source that is higher than any rate 
at which users would have been opting out over a longer term.

Also, perhaps a BS user can clarify how the prompting works with the BS 
client.  Does that prompt actually provide a copy of the spam (to remind 
the user as to what they reported to BS as spam)?  Does it list the 
target(s) to receive the opt-out requests (so the user is the final 
authority in deciding who gets the opt-out requests)?  Does the user get 
to select which one of multiple targets get the opt-out requests?  How 
long after submitting the slam, er, opt-out request to BS does the BS 
user then get this prompt showing what BS has determined to be the 
targets (i.e., after pushing the button, how long before the user gets 
prompted whether or not to send the opt-out that BS crafted in its 
script)?  Is this prompting enabled by default so the user must turn it 
off, or is the BS client preconfigured to perform the opt-out request 
without any user intervention (so it behaves as an uninterrupted zombied 
host)?  With SpamCop, it is the *user* that is deciding to whom the 
abuse reports are sent, and it is sent immediately rather than being 
pent up to then flood the abuse desks.  Even if SpamCop were enlarged to 
perform opt-out requests (rather then send abuse reports to the 
spamvertised site's webhost provider), the user is still required to 
validate the targets of those reports and those reports gets sent 
immediately.  Like BS, SpamCop provides a convenience is trying to help 
in identifying who to contact with the abuse report, but SpamCop doesn't 
make the final decision.  The user makes the final decision (so stupid 
and/or lazy users do not help SpamCop in its cause).  If you opt-out, 
you are supposed to do so immediately for a particular mailing, not some 
days, weeks, or months later after piling up a bunch for a particular 
source and which covers many different spam mails from the same source. 
You opt-out when you get the mail from which you want to opt-out.  In 
fact, marketers that do honor opt-outs (whereas spammers don't) could 
simply put a requirement that you MUST opt-out from their list within a 
short number of days after receiving their mailing (and enter a code 
that you must include but that code expires after so many days).  So the 
marketer could provide an opt-out procedure but you are required to use 
that procedure immediately after receiving their mail and deciding that 
you don't want to get any more of them from that source.  That would be 
like the in-store rebates that you must mail before 7 days elapse from 
when you purchase an item from that store (as opposed to the 
manufacturer's rebate that gives you months to mail the rebate).  I've 
seen something about some guidelines that marketers are supposed to use 
but since they are establishing the guidelines then they would simply 
make the opt-out deadline pretty short, like a day or two.  Yeah, they 
are conforming to the good netizen standard of providing an opt-out 
procedure but YOU have to exercise that opt-out within a couple days of 
getting their undesired mail, and any flooding of opt-outs after that 
point mean they will get rejected because they use-period has expired. 
Then any flood of opt-outs that are deliberately pent up and sent 
deliberately too late will obviously be perceived as a DOS attack and 
not simply as some attempt to cloak the DOS attack as a convenience 
service to submit opt-outs.  The cloak gets stripped when the DOS attack 
is obviously flooding the webhost service long after the opt-outs have 
expired.  That would then require BS to modify their behavior to submit 
the opt-outs immediately rather then store them up, and that means the 
flood of opt-outs that impinge the spamvertized site is no larger than 
the flood of opt-outs that would've have been received before BS 
existed.

Because BS is supposedly automating the opt-out request process (which 
is only providing a convenience to obtain the target site(s) contained 
within the body of the e-mail because the user could already do that), 
then BS is not just for reporting spam.  It is to provide a convenience 
tool for reporting all opt-outs.  After all, BS says they are sending 
opt-out requests.  So if only a single BS user reports a mail to have BS 
automate the opt-out request, does BS actually ever send that one-time, 
single-incidence opt-out request?  Or does BS wait until some threshold 
count of reports for a particular mail arrive after which they then 
*flood* the targets with opt-outs?  If BS is not submitting *every* 
opt-out request, even for the one-instance mails for which the user 
wants to opt-out, then BS is intentionally abusing the opt-out process.

If BS was truly providing a convenience service to automate the 
submission of opt-out requests then their opt-out traffic would nearly 
match the incidence report traffic.  Users have the right to submit 
opt-out requests so I have no problem with them using a tool that helps 
them pick out and validate the targets to where they submit those 
opt-out requests (and why I use SpamCop) *provided* that user is not 
taken out of the loop (i.e., it still remains the user's responsibility 
to validate the targets for their opt-out requests).  However, that is 
not what I construe how BS is being used or how it is intended to be 
used.  In order to flood a domain that is hosting a spamvertised web 
site, BS would have to pent up all those requests from the BS users and 
then release them all at once to perform a DOS attack against the target 
(and inflict harm to others in the process).  While sending the opt-outs 
as fast as BS users requested them would also still be a flood, it 
probably won't be of a volume sufficient to harm the source because not 
all recipients of the spam are going to opt-out (only a few percentage 
of a spam's recipients are BS users and not all BS users are going to 
opt-out of every spam they receive), and BS wants to harm the source. 
BS wants their opt-out flood to be far larger than the normal opt-out 
flood from users doing their own opt-outs.

Since they are capturing only a portion of all spam afflicted users that 
want to use the opt-out process under the belief that such a method is 
actually effective against spam, they need to produce a volume of 
traffic that is higher than when using the normal process.  They would 
need to be sending out more than the one-opt-out-per-report quota that 
they claim or they need to bunch them up to slam the site within a 
period that is much shorter than the normal rate of opt-outs.  If they 
don't do either then their volume is no greater than what would occur 
normally, anyway (and would, in fact, be smaller since they are only 
capturing a portion of the user that submit opt-outs).  If they are the 
good netizen they claim to be and if they are issuing opt-outs at the 
same rate and volume as users are requesting BS to send opt-outs then 
the only benefit of BS is that is promotes users to actually submit 
opt-outs at all.  Few users will bother opting out from a mailing list. 
Most fear that the opt-out will be used in reverse: instead of getting 
them off the spam lists, it will get them more spam because the opt-out 
is used by the spammer to validate correct and active e-mail addresses.

While marketers want to protect their permanent site (and would honor 
opt-outs), spammers move around a lot, their sites are temporary, they 
have a huge queue of web sites ready to replace the ones that they lose 
(i.e., they understand and prepare for rapid attrition), and they do NOT 
provide an opt-out procedure (unless to validate e-mail addresses which 
ups the priority in spamming those).  With marketers, at most BS is 
providing a convenience tool to determine where to submit the opt-outs 
(which is the same as SpamCop).  With spammers, BS can cloak their 
action as an opt-out flood when in fact is really is just a DOS attack. 
If BS doesn't immediately submit the opt-outs that are reported them by 
BS users then BS isn't even a convenience tool against marketers who do 
honor opt-outs but simply degrades into a malcontent wanting to DOS a 
site.