Re: BlueSecurity/Blue Frog

"Vanguard" <[email protected]> Fri, 12 May 2006 20:03:05 -0500
Newsgroups gmane.mail.spam.spamcop.user
Organization SpamCop
Message-ID <[email protected]>
"POP" <[email protected]> wrote in message 
news:[email protected]...
> If you're not a tech-writer, you should be!  Well, assuming you could 
> assemble a bulleted list now and again  <[;-).


I do software QA.  So I'm used to digging into products and breaking 
them which lets me know their weaknesses.  There is much that I cannot 
decipher from the limited amount of info on the BS web site and too many 
questions unanswered about how their service and product functions and 
its effects.  It looks like they are trying to come up with an effective 
solution (so they can charge for it) but, so far, it is not yet a 
Net-responsible one.  It definitely appears to be a work in progress.  I 
suspect their effect on e-mail or HTTP traffic volume is still so small 
that it goes under the radar of ISPs, webhost providers, and businesses 
running web sites so, for now, BS remains safe from litigation for 
recompense of damages caused by their coordinated DOS attack using the 
zombies installed on all their users' hosts.

If BS enlarges their volume by getting more users and becomes emboldened 
to be more agressive in their tactic (like scaling up the number of 
opt-out requests upon recurrence of the same spam to their users' 
mailboxes rather than sticking with the one-per-user-opt-out-request 
quota), they could end up in a world of hurt in court when they harm 
innocents with deeper pockets who can afford the lawyers.  Some ISPs 
already incur added expense to incorporate resources (manpower, devices, 
software) to avoid [D]DOS attacks or reduce their effects and since that 
is a direct cause of expense due to the DOS attack then the ISP could 
sue on civil charges for those damages (in addition to losses of 
[normal] use of their resources).  If a entity is large enough and rich 
enough, they have a bevy of lawyers on retainer or employed, and they 
want something for all that cost, and lawyers want to earn more, so they 
are inclined to use the lawyers to sue the attacker provided they have 
reasonable proof of the attacker.  Well, BS may be easily identified by 
their opt-out mails and the bogus mailboxes they use for their users.

In fact, that may be why BS uses zombied user hosts rather than send the 
opt-out mails directly from their own server host(s): the victim of 
their DOS attack (and the innocents, too, that were the collateral 
damage) would see the coordinated mob of users as the "attacker" 
committing the DOS attack rather than of the attack emanating from BS 
(after all, traditionally that is why zombies are used so the 
perpetrator can hide behind the zombied hosts).  However, should any of 
those users be confronted with a subpoena that were tracked as a 
participant in the DOS attack, I'm sure they would quickly give up BS. 
BS can't hide as well as other malcontents who hide that a zombie got 
installed on the user's host.  From what I've read or heard, often ISPs 
don't know the identity of the attacker in a DOS attack (and even less 
so in a distributed DOS), but a user-instigated, BS-originated flood 
seems more traceable.

If you hunt around the web site, you won't find any real information 
about the company.  There is no mission statement.  They never mention 
when they established their "company".  I found articles back to June 
2005 talking about BS 
(http://securitypronews.com/news/securitynews/spn-45-20050722SpamWarsBlueSecurityStrikesBack.html), 
Oct 2005 looks to be the earliest post in their forums (the Welcome 
post), but 
http://www.thewhir.com/features/Blue_Security_Unveils_Anti_Spam_Registry.cfm 
makes it appear their do-not-intrude registry started back around Jan 
2005.  They don't even have a complete web site yet (lots of links take 
you to an "under maintenance" page).  "Eran Reshef, founder and CEO of 
Blue Security, says that according to the first amendment, every US 
citizen is entitled to be left alone" (from last link above to 
articles).  A warm glows encompasses me knowing an Israeli company is 
concerned with the first amendment rights of Americans (but then that is 
NOT what the first amendment is about which actually seems to favor the 
spammer and not those trying to squelch the spammer; see 
http://www.usconstitution.net/const.html#Am1).

So their effect and harm may still be too new, too short, and their 
volume still too small to be of concern to anyone yet (i.e., they are 
under the radar).  If they take off like they think they will, and when 
they start becoming enough of a pest, the harmed (spammers and 
non-spammers alike) will probably take legal action (rather than just 
criticizing or retaliating against their web site).  When you have 
people suing McDonalds when they themself dump hot coffee in their own 
lap (by using their thighs as a vise) or because they were too stupid to 
know that eating fatty food makes them fat, I really doubt there won't 
be lawsuits over the DOS attacks by BS since BS can be identified as the 
one that is coordinating the attack.

According to some BS users (well, from reading articles from folks 
claiming to be BS users), the intent of BS is to make their now-free 
service to be a pay service.  So, like Cloudmark did with SpamNet, BS is 
using/abusing their current free acccount users as unpaid, uninformed, 
and voluntary beta testers while they tweak their product or service to 
then later yank it away and make money on the spam problem.  Their 
intent may not be as altruistic as current BS users believe, and the 
current BS users may find themself without that service later when BS 
goes commercial.  There is mention that if you signup now for free that 
you will continue to get the service for free.  However, as with any 
*free* service, the provider always reserves the right to change the 
terms of use and whatever implied contract, if any, exists between them 
and user (i.e., they can change their minds however they want and do 
whatever they want with their service).  They need those free-account 
users so they can produce a commercially viable anti-spam service 
(provided they don't get stopped in their tracks by those afflicted by 
their DOS attacks).