Re: Am I right to blame SORBS?

William Francis Stucke <[email protected]>
Newsgroups gmane.org.operators.ioz
Message-ID <CE47256D74A915449FA1A181FB094A694AC0AB99@ICASASTNMB01.icasa.local>
Brian Bakker asked: -

> is my understanding of the situation correct?
> is it fair to call ISPs who use SORBS idiots?

In my never-very-humble-opinion: Yes, and Yes[1].

[1] At least, those who use SORBS as decisive. Use it to adjust scoring, if you like, but don't rely on it.

Before I get flamed, let me back this opinion up with some evidence ...

>From this page:
http://forum.spamcop.net/forums/lofiversion/index.php/t1862.html

" Let me quote Alden Bates: QUOTE
SORBS is basically the spam-fighting equivalent of hanging all your suspects just to make sure you get the criminal "

And from this site:
http://www.sputcorp.com/IT/SORBS.aspx

" If you operate a mail server utilising realtime blackhole lookups, please do not use SORBS.
You may lose legitimate mail by using it.
 
For alternate RBLs that work well try the following:
www.spamcop.net (bl.spamcop.net)
www.msrbl.com (combined.rbl.msrbl.net)
www.spamhaus.org/xbl (zen.spamhaus.org) (May overblock in my experience but not bad). "

Or from here: -
http://inboxrevenge.wordpress.com/2009/06/25/blacklist-service-sorbs-shutting-down-in-july-2009/

" On Monday, 22 June [2009], it was announced by Michelle Sullivan[2], owner of SORBS (IP: 203.15.51.39 at ASN2764 AAPT), on the SORBS homepage that she would shut the blacklisting services down by July 21st. 
<snip> ...

The following day, the SORBS story was posted on the "News for Nerds" site, Slashdot, which resulted in many posts with an angry tone by slashdot participants. The anti-spam groups, mail admins and ISP operators were abuzz about how much most of them disliked SORBS' tactics. There were only a few defenders of the DNSBL.

One of the more kinder comments from Slashdot:

"Such a shutdown could slow or disrupt anti-spam efforts for large numbers of mail hosts worldwide. "

You're kidding, right?

They have done more to give legitimate anti-spam efforts a black eye than ANY legislative attempts to 'solve' the problem ever could.

I -used- to believe that 'collateral damage' was a legitimate 'tactic' in the fight against spammers. I've grown up since then.

or this post:

A lot of people have had their lives turn into a living hell because of some listing on SORBS. Thus if it wasn't me who chewed you out, somebody else probably would have "

And finally, from slashdot: -

" Who uses SORBS anyways? (Score:2)
Not me. There are far better ones out there. "

[2] Michelle Sullivan used to be Michael Sullivan. Name and gender changed, but arrogance and vigilante attitude seem unchanged.

SORBS has now been sold, for $451K. Yep, it was a "non profit" operation. Dunno what effect that has had on the quality of service, but I'm not optimistic.

Long before I ceased operating an ISP, I stopped using SORBS. 

Justification:
1	They actively probed for vulnerable servers and misconfigured RDNS, rather than relying on reports and honeypots. This results in excessive listings
2	They often arbitrarily listed a whole range instead of a single IP
3	They list IP addresses with a RDNS that "looks like" a dynamic range, even if it isn't. That's right, including a /17 or larger!
4	Getting unlisted is difficult, time consuming, expensive and may involve personal abuse.

All these factors make relying on SORBS as an absolute metric for blocking spam highly unreliable - in that false positives are far too high. In the real world, customers are willing to receive a few spam messages that slip through, but will hit the roof if that tender worth R500,000 is accidentally blocked as a false positive.

My answers to your questions therefore remain: "Yes", and "Yes".

While you're at it, I suggest avoiding RFC-Ignorant.Org, too. They list the entire CO.ZA zone!

Finally (again!), I couldn't resist this, from www.sorbs.net itself: -

" The Spam and Open Relay Blocking System (SORBS) was conceived as an anti-spam project where a daemon would check "on-the-fly", all servers from which it received email to determine if that email was sent via various types of proxy and open-relay servers. The daemon was not particularly well written and served as a lesson in programming for its original author, Michelle Sullivan. " 

... not particularly well written ...

Eish! A long post. Sorry, guys. HTH, Brian.

Kind regards,

William Stucke


_______________________________________________
IOZ mailing list
[email protected]
http://lists.internet.org.za/mailman/listinfo/ioz
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.