RE: ISP outbound SMTP filtering
"Blake Pfankuch" <[email protected]>
| Newsgroups | gmane.org.operators.internet-access |
|---|---|
| Message-ID | <CAA027ED18E2A047AEEB2F9412D94AB24BB2@optimusprime.shenrons-house.local> |
> That's awfully lenient. If one of your customers is spewing spam at > a rate of 1000 messages per hour, 48 hours is an eternity. Also, > business class DSL is different. Typically business class customers > pay more, sign contracts, and accept a certain amount of liability. > Joe's grandma at home is a different story. The average linux > weenie trying to operate a mail server in his kitchen cupboard should > be relaying his outbound mail through his ISP or through some other > third party mail server. He's not going to get much traction on a > dynamic address that's in some RBL... The only reason I give that much time is to take into account that people have jobs, and other responsibilities. Also take on the fact that if you have a mail worm spewing, how do you get a fix for it if I just shut off your internet? > I'm all about helping people to learn, but you people are ISP's. You > are supposed to be a paragon of responsible netizen. You are not > supposed to let spam emanate from your network. Out of about 1000 clients I have, I have really only had 3 or 4 zombie machines on there. Never have they lasted for more than a week. So you see a dsl line spewing to the internet. Send a 72 hour request and filter port 25 for that time. If it's not fixed by then shut them off. 72 hours is fairly strict compared to what Comcast, Cox and Verizon have as their policies. Last time I checked Comcast had 2 weeks in their contract. > You'd rather force a huge spam problem on the rest of the world than > answer a simple question for your customer? Id rather force the common person who represents our clients the basic things that could easily prevent a mail worm from showing up on their windows machine as it's common sense anyway. Good passwords, use Microsoft updates, keep an up to date AV client installed... > Well, you are wrong. As a net admin, it is your responsibility to > ensure that your network is not a menace to the rest of the world. > If you choose to let your customers have outbound port 25 with no > restrictions, then it is your subsesquent responsibility to ensure > that none of your customers are sending spam on that port. I don't > care how you do it, but that is your contract with the world. You > have another contract with the world, don't let your routes flap. If > they do, you get attenuated until you fix it. You accept that and > know it as a fundamental truth. Why is it not likewise with spam? > Is it because, at present, the world doesn't have an RBL with your > name in it? So cant we try to accomplish both? Keep the spam off our networks, but not filter everything? I mean turn off the occasional customer who has a zombie. Call them and say "hey you have a machine that is sending spam. You need to fix this before we can turn your internet back on." If you explain to them how serious it is, I have found that you usually get a decent response out of it. Shoot even just shut off their service. They will call you when they notice. So you get yelled at 1 in 10 times. Whoopee they will fix it, or they won't be on your network. If you run a good service, and people are coming to your network for a reason I would assume that they wouldn't have a problem spending 10-15 minutes cleaning up their machine a bit and staying on your network. Put it in your TOS that they need to make sure their computer is free of virus' and mail worms. > Oh please. Spare me the blue skies. While you're in there teaching > them, teach them how to configure their mail client to send mail to > you using auth with TLS on port 587. While you are at it, explain to me how to do that from a mobile device. Yes Windows Mobile 5 devices and blackberries have ssl support, but what about all the people using pop on Motorola phones? Last time I checked, they didn't have support for SSL on SMTP unless you had a krazr. What about the Palm smart phones? > Again, you're reading into what I said. I was talking about how many > messages a person can send in some period of time. I don't care how > many messages you receive. Completely uninteresting to me. And I > didn't say "500 messages a day". What limits you establish are > between you and your customer. Remember, you're all about education. That's a hypothetical, reasonable limit. 500 messages a day is more than any normal person should be sending. So you do it your way and block smtp connections for 5 minutes after you send 10 email in less than 30 seconds. > People like you two are exactly why we have a spam problem these days. I'd go more with the fact that we have a spam problem because the general populous believes computers just work. They have no idea how or why. They are amazed by joke forwards that promise to pop something up if you send the message to 50 people, and then are equally disappointed when it doesn't work. We need a higher understanding among the average user of basic functions like this. Im sure 80 years ago there was the same type of thing with cars in "man we have to check the oil in the engine? And we have to fill it with gas?" I don't see many people complaining about their cars anymore (aside from gas prices). So why can't we give some information and help stop spam? If you approach people right, and try to be friendly, you get people who generally want to learn. You spend 5 minutes telling them how to prevent a virus or Trojan or worm on their machine. Boom you just saved a zombie. If 1 in 5 people you tell that stuff to happens to mention it to someone else you are doing pretty good, and it's not a huge impact. You can't change the whole world, but why not try to affect your little corner of it positively? Call me overly optimistic, but I would rather not picture the world being flushed down the drain while everyone screams its not their fault. _______________________________________________ "Eat sushi frequently". - Avi [email protected] is the human contact address. [email protected] is the list posting address. See below URL for subscribe/unsubscribe and list options: http://inet-access.net/mailman/listinfo/list