Re: BlueSecurity/Blue Frog
"Vanguard" <[email protected]> Fri, 12 May 2006 16:42:25 -0500
| Newsgroups | gmane.mail.spam.spamcop.user |
|---|---|
| Organization | SpamCop |
| Message-ID | <[email protected]> |
Say BlueSecurity (BS) does what they claim to do. That is, say BS' function is to actually automate the process of submitting opt-out requests from its users to the source of a spam mail (or any undesirable mailing that provides for opt-out). That means users of BS must subscribe to the concept that opt-outs work; i.e., the user of BS must truly believe that opt-outs by themselves and singly will work to get them off a mailing list (that the spammer actually honors those opt-out requests) because, after all and according to BS' claims, BS will only send the single opt-out request from the user for a particular spam mail. That's not how BS is used or intended to be used but just let's say BS and its users are good netizens practicing their right to opt-out from a mailing list and that the spammers are also good netizens (which is made impossible by the fact that they spam) by honoring the opt-outs and have somewhere for all those opt-outs to go (to the spammer and not somewhere else). If BS users do not believe that single opt-outs work (which seems to be why they are using BS to provide a coordinated attack) or that the spam source does not honor those requests then BS and its users are hiding behind a cloak to disguise their punitive DOS attack as an opt-out process. Okay, so assuming BS and its users are good netizens exercising their right to opt-out and that they really believe the spammers will honor opt-outs (okay, okay, you can stop laughing now) then that means the opt-outs would be generated by the recipients of spam as fast as they got the spam or very soon thereafter. The precept of opt-outs is that you opt-out right after getting the undesirable mail (which may or may not be spam). No user goes collecting their spams over a period of hours, days, weeks, or months to then collate them so they are grouped by the same spam source and only after a long time later then goes submitting opt-outs. If they submit opt-outs, they do so right after getting the undesirable mail. You just know that is not how BS works simply because individuals separately submitting opt-outs as they receive the undesirable mails has not worked in the past to reduce spam traffic. The flood of single request opt-out traffic engendered by spam mails from a particular source from one recipient has not been sufficient to punish that source. If that had worked, no one would need BS. While getting a graph of the volume of mail traffic generated for a particular spam sent by the source is probably not available, BS has its database from which could be graphed the rate of reports and which can also be tracked for a particular spam (or for all spams for a particular source). That way you could see how fast recipients were reporting a particular mail as spam. If BS and its users were really the good netizens they claim to be then the rate of opt-out submissions from BS (by them uploading their script to their zombied hosts) would be a mirror image of the incidence graph (i.e., the reports from BS users). Okay, so there would be a shift in the graph to the right to reflect the delay in BS supposedly analyzing the spam to determine to which targets to send the opt-outs and write the script to have their zombied user hosts do the HTTP process to fill out the opt-out forms (which assumes spammers even have one - which brings up the point of what does BS do with their supposed opt-out requests when a site has no opt-out procedure). If BS were really just helping its users to automate the opt-out requests, you'd have the graph of the the users' reports for a particular spam - and the graph of BS' opt-out request traffic would be a near match to it. The users report a particular spam, there is a small delay before BS takes action so there is a short overspike when BS finally starts to send out opt-outs due the the pent up reports previously submitted, and then the spike immediately drops to match the incidence graph. Obviously that is not how BS works because that is how the volume of opt-out traffic would've occurred before BS even existed, and that volume was trivial and didn't impact spammers. So does anyone know if that is how the volume of opt-outs flow from BS (using the "good" graph where opt-out traffic from BS matches the incidence report traffic)? From what I read at their site, it is up to BS to decide when to send their opt-out requests, and it appears they are storing them up so they can then flood the target(s) all at once rather than accurately reflect the incoming volume of reports from the BS users. Recipients have the right to opt-out from mailing lists. Apparently BS users believe that opt-outs from spammers actually work. That is, opt-ing out from a spammer is, according to the BS user, a solution. Fact is, opting out has NOT been an effective solution because a single opt-out sent from a single recipient for a single incidence of a particular spam mail has no effect on a spammer and their spamvertised web site. So BS users work collectively to punish the spammer but their opt-out traffic has to be pent up so a flood of it can be slammed at the spamvertized site rather than the normal flood from users opting out that never had BS before. If the volume of opt-out requests from BS doesn't match the volume of incidence reports from BS users then BS' intent is NOT to automate the opt-out process. If the graph of BS' opt-out volume, with a small catch up spike due to the delay to analyze and script, doesn't mirror the graph of incidence reports from BS users then BS is *not* being the good netizen in helping to automate those opt-out requests. They are instead abusing opt-outs by storing them until enough are available to perform a shorter term and even larger flood against the spam source that is higher than any rate at which users would have been opting out over a longer term. Also, perhaps a BS user can clarify how the prompting works with the BS client. Does that prompt actually provide a copy of the spam (to remind the user as to what they reported to BS as spam)? Does it list the target(s) to receive the opt-out requests (so the user is the final authority in deciding who gets the opt-out requests)? Does the user get to select which one of multiple targets get the opt-out requests? How long after submitting the slam, er, opt-out request to BS does the BS user then get this prompt showing what BS has determined to be the targets (i.e., after pushing the button, how long before the user gets prompted whether or not to send the opt-out that BS crafted in its script)? Is this prompting enabled by default so the user must turn it off, or is the BS client preconfigured to perform the opt-out request without any user intervention (so it behaves as an uninterrupted zombied host)? With SpamCop, it is the *user* that is deciding to whom the abuse reports are sent, and it is sent immediately rather than being pent up to then flood the abuse desks. Even if SpamCop were enlarged to perform opt-out requests (rather then send abuse reports to the spamvertised site's webhost provider), the user is still required to validate the targets of those reports and those reports gets sent immediately. Like BS, SpamCop provides a convenience is trying to help in identifying who to contact with the abuse report, but SpamCop doesn't make the final decision. The user makes the final decision (so stupid and/or lazy users do not help SpamCop in its cause). If you opt-out, you are supposed to do so immediately for a particular mailing, not some days, weeks, or months later after piling up a bunch for a particular source and which covers many different spam mails from the same source. You opt-out when you get the mail from which you want to opt-out. In fact, marketers that do honor opt-outs (whereas spammers don't) could simply put a requirement that you MUST opt-out from their list within a short number of days after receiving their mailing (and enter a code that you must include but that code expires after so many days). So the marketer could provide an opt-out procedure but you are required to use that procedure immediately after receiving their mail and deciding that you don't want to get any more of them from that source. That would be like the in-store rebates that you must mail before 7 days elapse from when you purchase an item from that store (as opposed to the manufacturer's rebate that gives you months to mail the rebate). I've seen something about some guidelines that marketers are supposed to use but since they are establishing the guidelines then they would simply make the opt-out deadline pretty short, like a day or two. Yeah, they are conforming to the good netizen standard of providing an opt-out procedure but YOU have to exercise that opt-out within a couple days of getting their undesired mail, and any flooding of opt-outs after that point mean they will get rejected because they use-period has expired. Then any flood of opt-outs that are deliberately pent up and sent deliberately too late will obviously be perceived as a DOS attack and not simply as some attempt to cloak the DOS attack as a convenience service to submit opt-outs. The cloak gets stripped when the DOS attack is obviously flooding the webhost service long after the opt-outs have expired. That would then require BS to modify their behavior to submit the opt-outs immediately rather then store them up, and that means the flood of opt-outs that impinge the spamvertized site is no larger than the flood of opt-outs that would've have been received before BS existed. Because BS is supposedly automating the opt-out request process (which is only providing a convenience to obtain the target site(s) contained within the body of the e-mail because the user could already do that), then BS is not just for reporting spam. It is to provide a convenience tool for reporting all opt-outs. After all, BS says they are sending opt-out requests. So if only a single BS user reports a mail to have BS automate the opt-out request, does BS actually ever send that one-time, single-incidence opt-out request? Or does BS wait until some threshold count of reports for a particular mail arrive after which they then *flood* the targets with opt-outs? If BS is not submitting *every* opt-out request, even for the one-instance mails for which the user wants to opt-out, then BS is intentionally abusing the opt-out process. If BS was truly providing a convenience service to automate the submission of opt-out requests then their opt-out traffic would nearly match the incidence report traffic. Users have the right to submit opt-out requests so I have no problem with them using a tool that helps them pick out and validate the targets to where they submit those opt-out requests (and why I use SpamCop) *provided* that user is not taken out of the loop (i.e., it still remains the user's responsibility to validate the targets for their opt-out requests). However, that is not what I construe how BS is being used or how it is intended to be used. In order to flood a domain that is hosting a spamvertised web site, BS would have to pent up all those requests from the BS users and then release them all at once to perform a DOS attack against the target (and inflict harm to others in the process). While sending the opt-outs as fast as BS users requested them would also still be a flood, it probably won't be of a volume sufficient to harm the source because not all recipients of the spam are going to opt-out (only a few percentage of a spam's recipients are BS users and not all BS users are going to opt-out of every spam they receive), and BS wants to harm the source. BS wants their opt-out flood to be far larger than the normal opt-out flood from users doing their own opt-outs. Since they are capturing only a portion of all spam afflicted users that want to use the opt-out process under the belief that such a method is actually effective against spam, they need to produce a volume of traffic that is higher than when using the normal process. They would need to be sending out more than the one-opt-out-per-report quota that they claim or they need to bunch them up to slam the site within a period that is much shorter than the normal rate of opt-outs. If they don't do either then their volume is no greater than what would occur normally, anyway (and would, in fact, be smaller since they are only capturing a portion of the user that submit opt-outs). If they are the good netizen they claim to be and if they are issuing opt-outs at the same rate and volume as users are requesting BS to send opt-outs then the only benefit of BS is that is promotes users to actually submit opt-outs at all. Few users will bother opting out from a mailing list. Most fear that the opt-out will be used in reverse: instead of getting them off the spam lists, it will get them more spam because the opt-out is used by the spammer to validate correct and active e-mail addresses. While marketers want to protect their permanent site (and would honor opt-outs), spammers move around a lot, their sites are temporary, they have a huge queue of web sites ready to replace the ones that they lose (i.e., they understand and prepare for rapid attrition), and they do NOT provide an opt-out procedure (unless to validate e-mail addresses which ups the priority in spamming those). With marketers, at most BS is providing a convenience tool to determine where to submit the opt-outs (which is the same as SpamCop). With spammers, BS can cloak their action as an opt-out flood when in fact is really is just a DOS attack. If BS doesn't immediately submit the opt-outs that are reported them by BS users then BS isn't even a convenience tool against marketers who do honor opt-outs but simply degrades into a malcontent wanting to DOS a site.