Re: BlueSecurity/Blue Frog
"Vanguard" <[email protected]> Fri, 12 May 2006 20:03:05 -0500
| Newsgroups | gmane.mail.spam.spamcop.user |
|---|---|
| Organization | SpamCop |
| Message-ID | <[email protected]> |
"POP" <[email protected]> wrote in message news:[email protected]... > If you're not a tech-writer, you should be! Well, assuming you could > assemble a bulleted list now and again <[;-). I do software QA. So I'm used to digging into products and breaking them which lets me know their weaknesses. There is much that I cannot decipher from the limited amount of info on the BS web site and too many questions unanswered about how their service and product functions and its effects. It looks like they are trying to come up with an effective solution (so they can charge for it) but, so far, it is not yet a Net-responsible one. It definitely appears to be a work in progress. I suspect their effect on e-mail or HTTP traffic volume is still so small that it goes under the radar of ISPs, webhost providers, and businesses running web sites so, for now, BS remains safe from litigation for recompense of damages caused by their coordinated DOS attack using the zombies installed on all their users' hosts. If BS enlarges their volume by getting more users and becomes emboldened to be more agressive in their tactic (like scaling up the number of opt-out requests upon recurrence of the same spam to their users' mailboxes rather than sticking with the one-per-user-opt-out-request quota), they could end up in a world of hurt in court when they harm innocents with deeper pockets who can afford the lawyers. Some ISPs already incur added expense to incorporate resources (manpower, devices, software) to avoid [D]DOS attacks or reduce their effects and since that is a direct cause of expense due to the DOS attack then the ISP could sue on civil charges for those damages (in addition to losses of [normal] use of their resources). If a entity is large enough and rich enough, they have a bevy of lawyers on retainer or employed, and they want something for all that cost, and lawyers want to earn more, so they are inclined to use the lawyers to sue the attacker provided they have reasonable proof of the attacker. Well, BS may be easily identified by their opt-out mails and the bogus mailboxes they use for their users. In fact, that may be why BS uses zombied user hosts rather than send the opt-out mails directly from their own server host(s): the victim of their DOS attack (and the innocents, too, that were the collateral damage) would see the coordinated mob of users as the "attacker" committing the DOS attack rather than of the attack emanating from BS (after all, traditionally that is why zombies are used so the perpetrator can hide behind the zombied hosts). However, should any of those users be confronted with a subpoena that were tracked as a participant in the DOS attack, I'm sure they would quickly give up BS. BS can't hide as well as other malcontents who hide that a zombie got installed on the user's host. From what I've read or heard, often ISPs don't know the identity of the attacker in a DOS attack (and even less so in a distributed DOS), but a user-instigated, BS-originated flood seems more traceable. If you hunt around the web site, you won't find any real information about the company. There is no mission statement. They never mention when they established their "company". I found articles back to June 2005 talking about BS (http://securitypronews.com/news/securitynews/spn-45-20050722SpamWarsBlueSecurityStrikesBack.html), Oct 2005 looks to be the earliest post in their forums (the Welcome post), but http://www.thewhir.com/features/Blue_Security_Unveils_Anti_Spam_Registry.cfm makes it appear their do-not-intrude registry started back around Jan 2005. They don't even have a complete web site yet (lots of links take you to an "under maintenance" page). "Eran Reshef, founder and CEO of Blue Security, says that according to the first amendment, every US citizen is entitled to be left alone" (from last link above to articles). A warm glows encompasses me knowing an Israeli company is concerned with the first amendment rights of Americans (but then that is NOT what the first amendment is about which actually seems to favor the spammer and not those trying to squelch the spammer; see http://www.usconstitution.net/const.html#Am1). So their effect and harm may still be too new, too short, and their volume still too small to be of concern to anyone yet (i.e., they are under the radar). If they take off like they think they will, and when they start becoming enough of a pest, the harmed (spammers and non-spammers alike) will probably take legal action (rather than just criticizing or retaliating against their web site). When you have people suing McDonalds when they themself dump hot coffee in their own lap (by using their thighs as a vise) or because they were too stupid to know that eating fatty food makes them fat, I really doubt there won't be lawsuits over the DOS attacks by BS since BS can be identified as the one that is coordinating the attack. According to some BS users (well, from reading articles from folks claiming to be BS users), the intent of BS is to make their now-free service to be a pay service. So, like Cloudmark did with SpamNet, BS is using/abusing their current free acccount users as unpaid, uninformed, and voluntary beta testers while they tweak their product or service to then later yank it away and make money on the spam problem. Their intent may not be as altruistic as current BS users believe, and the current BS users may find themself without that service later when BS goes commercial. There is mention that if you signup now for free that you will continue to get the service for free. However, as with any *free* service, the provider always reserves the right to change the terms of use and whatever implied contract, if any, exists between them and user (i.e., they can change their minds however they want and do whatever they want with their service). They need those free-account users so they can produce a commercially viable anti-spam service (provided they don't get stopped in their tracks by those afflicted by their DOS attacks).