RE: ISP outbound SMTP filtering

"Blake Pfankuch" <[email protected]>
Newsgroups gmane.org.operators.internet-access
Message-ID <CAA027ED18E2A047AEEB2F9412D94AB24BB2@optimusprime.shenrons-house.local>
> That's awfully lenient.  If one of your customers is spewing spam at  
> a rate of 1000 messages per hour, 48 hours is an eternity.  Also,  
> business class DSL is different.  Typically business class customers  
> pay more, sign contracts, and accept a certain amount of liability.   
> Joe's grandma at home is a different story.   The average linux  
> weenie trying to operate a mail server in his kitchen cupboard should

> be relaying his outbound mail through his ISP or through some other  
> third party mail server.   He's not going to get much traction on a  
> dynamic address that's in some RBL...

The only reason I give that much time is to take into account that
people have jobs, and other responsibilities.  Also take on the fact
that if you have a mail worm spewing, how do you get a fix for it if I
just shut off your internet? 

> I'm all about helping people to learn, but you people are ISP's.  You

> are supposed to be a paragon of responsible netizen.  You are not  
> supposed to let spam emanate from your network.

Out of about 1000 clients I have, I have really only had 3 or 4 zombie
machines on there.  Never have they lasted for more than a week.  So you
see a dsl line spewing to the internet.  Send a 72 hour request and
filter port 25 for that time.  If it's not fixed by then shut them off.
72 hours is fairly strict compared to what Comcast, Cox and Verizon have
as their policies.  Last time I checked Comcast had 2 weeks in their
contract.

> You'd rather force a huge spam problem on the rest of the world than  
> answer a simple question for your customer?

Id rather force the common person who represents our clients the basic
things that could easily prevent a mail worm from showing up on their
windows machine as it's common sense anyway.  Good passwords, use
Microsoft updates, keep an up to date AV client installed...

> Well, you are wrong.  As a net admin, it is your responsibility to  
> ensure that your network is not a menace to the rest of the world.   
> If you choose to let your customers have outbound port 25 with no  
> restrictions, then it is your subsesquent responsibility to ensure  
> that none of your customers are sending spam on that port.  I don't  
> care how you do it, but that is your contract with the world.  You  
> have another contract with the world, don't let your routes flap.  If

> they do, you get attenuated until you fix it.  You accept that and  
> know it as a fundamental truth.  Why is it not likewise with spam?   
> Is it because, at present, the world doesn't have an RBL with your  
> name in it?

So cant we try to accomplish both?  Keep the spam off our networks, but
not filter everything?  I mean turn off the occasional customer who has
a zombie.  Call them and say "hey you have a machine that is sending
spam.  You need to fix this before we can turn your internet back on."
If you explain to them how serious it is, I have found that you usually
get a decent response out of it.  Shoot even just shut off their
service.  They will call you when they notice.  So you get yelled at 1
in 10 times.  Whoopee they will fix it, or they won't be on your
network.  If you run a good service, and people are coming to your
network for a reason I would assume that they wouldn't have a problem
spending 10-15 minutes cleaning up their machine a bit and staying on
your network.  Put it in your TOS that they need to make sure their
computer is free of virus' and mail worms.

> Oh please. Spare me the blue skies.  While you're in there teaching  
> them, teach them how to configure their mail client to send mail to  
> you using auth with TLS on port 587.

While you are at it, explain to me how to do that from a mobile device.
Yes Windows Mobile 5 devices and blackberries have ssl support, but what
about all the people using pop on Motorola phones?  Last time I checked,
they didn't have support for SSL on SMTP unless you had a krazr.  What
about the Palm smart phones?

> Again, you're reading into what I said.  I was talking about how many

> messages a person can send in some period of time.  I don't care how  
> many messages you receive.  Completely uninteresting to me.  And I  
> didn't say "500 messages a day".  What limits you establish are  
> between you and your customer.  Remember, you're all about education.

That's a hypothetical, reasonable limit.  500 messages a day is more
than any normal person should be sending.  So you do it your way and
block smtp connections for 5 minutes after you send 10 email in less
than 30 seconds.

> People like you two are exactly why we have a spam problem these days.

I'd go more with the fact that we have a spam problem because the
general populous believes computers just work.  They have no idea how or
why.  They are amazed by joke forwards that promise to pop something up
if you send the message to 50 people, and then are equally disappointed
when it doesn't work.  We need a higher understanding among the average
user of basic functions like this.  Im sure 80 years ago there was the
same type of thing with cars in "man we have to check the oil in the
engine?  And we have to fill it with gas?"  I don't see many people
complaining about their cars anymore (aside from gas prices).  So why
can't we give some information and help stop spam?  If you approach
people right, and try to be friendly, you get people who generally want
to learn.  You spend 5 minutes telling them how to prevent a virus or
Trojan or worm on their machine.   Boom you just saved a zombie.  If 1
in 5 people you tell that stuff to happens to mention it to someone else
you are doing pretty good, and it's not a huge impact.  You can't change
the whole world, but why not try to affect your little corner of it
positively?  Call me overly optimistic, but I would rather not picture
the world being flushed down the drain while everyone screams its not
their fault.  

_______________________________________________
"Eat sushi frequently". - Avi
[email protected] is the human contact address.
[email protected] is the list posting address.
See below URL for subscribe/unsubscribe and list options:
http://inet-access.net/mailman/listinfo/list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.