Re: Am I right to blame SORBS?
Daniel Schroder <[email protected]>
| Newsgroups | gmane.org.operators.ioz |
|---|---|
| Message-ID | <[email protected]> |
On Wed, Apr 6, 2011 at 10:19 PM, William Francis Stucke <[email protected]> wrote: > Brian Bakker asked: - > >> is my understanding of the situation correct? >> is it fair to call ISPs who use SORBS idiots? > > In my never-very-humble-opinion: Yes, and Yes[1]. > > [1] At least, those who use SORBS as decisive. Use it to adjust scoring, if you like, but don't rely on it. > > Before I get flamed, let me back this opinion up with some evidence ... > > >From this page: > http://forum.spamcop.net/forums/lofiversion/index.php/t1862.html > > " Let me quote Alden Bates: QUOTE > SORBS is basically the spam-fighting equivalent of hanging all your suspects just to make sure you get the criminal " > > And from this site: > http://www.sputcorp.com/IT/SORBS.aspx > > " If you operate a mail server utilising realtime blackhole lookups, please do not use SORBS. > You may lose legitimate mail by using it. > > For alternate RBLs that work well try the following: > www.spamcop.net (bl.spamcop.net) > www.msrbl.com (combined.rbl.msrbl.net) > www.spamhaus.org/xbl (zen.spamhaus.org) (May overblock in my experience but not bad). " > > Or from here: - > http://inboxrevenge.wordpress.com/2009/06/25/blacklist-service-sorbs-shutting-down-in-july-2009/ > > " On Monday, 22 June [2009], it was announced by Michelle Sullivan[2], owner of SORBS (IP: 203.15.51.39 at ASN2764 AAPT), on the SORBS homepage that she would shut the blacklisting services down by July 21st. > <snip> ... > > The following day, the SORBS story was posted on the "News for Nerds" site, Slashdot, which resulted in many posts with an angry tone by slashdot participants. The anti-spam groups, mail admins and ISP operators were abuzz about how much most of them disliked SORBS' tactics. There were only a few defenders of the DNSBL. > > One of the more kinder comments from Slashdot: > > "Such a shutdown could slow or disrupt anti-spam efforts for large numbers of mail hosts worldwide. " > > You're kidding, right? > > They have done more to give legitimate anti-spam efforts a black eye than ANY legislative attempts to 'solve' the problem ever could. > > I -used- to believe that 'collateral damage' was a legitimate 'tactic' in the fight against spammers. I've grown up since then. > > or this post: > > A lot of people have had their lives turn into a living hell because of some listing on SORBS. Thus if it wasn't me who chewed you out, somebody else probably would have " > > And finally, from slashdot: - > > " Who uses SORBS anyways? (Score:2) > Not me. There are far better ones out there. " > > [2] Michelle Sullivan used to be Michael Sullivan. Name and gender changed, but arrogance and vigilante attitude seem unchanged. > > SORBS has now been sold, for $451K. Yep, it was a "non profit" operation. Dunno what effect that has had on the quality of service, but I'm not optimistic. > > Long before I ceased operating an ISP, I stopped using SORBS. > > Justification: > 1 They actively probed for vulnerable servers and misconfigured RDNS, rather than relying on reports and honeypots. This results in excessive listings > 2 They often arbitrarily listed a whole range instead of a single IP > 3 They list IP addresses with a RDNS that "looks like" a dynamic range, even if it isn't. That's right, including a /17 or larger! > 4 Getting unlisted is difficult, time consuming, expensive and may involve personal abuse. > > All these factors make relying on SORBS as an absolute metric for blocking spam highly unreliable - in that false positives are far too high. In the real world, customers are willing to receive a few spam messages that slip through, but will hit the roof if that tender worth R500,000 is accidentally blocked as a false positive. > > My answers to your questions therefore remain: "Yes", and "Yes". > > While you're at it, I suggest avoiding RFC-Ignorant.Org, too. They list the entire CO.ZA zone! > > Finally (again!), I couldn't resist this, from www.sorbs.net itself: - > > " The Spam and Open Relay Blocking System (SORBS) was conceived as an anti-spam project where a daemon would check "on-the-fly", all servers from which it received email to determine if that email was sent via various types of proxy and open-relay servers. The daemon was not particularly well written and served as a lesson in programming for its original author, Michelle Sullivan. " > > ... not particularly well written ... > > Eish! A long post. Sorry, guys. HTH, Brian. > > Kind regards, > > William Stucke Just a thought, if there is a will to hang all the suspects just to stamp out the criminal, why not go after the criminal ? Are criminals just simply cleverer than sysadmins ? Who then then resort to hanging all the suspects. Is this the caliber of mail administration , or systems admin in general ? I mean really, outsourcing mail to third trusted parties is really working for the Internet at large, clearly </sarcasm> My cynical take is that stupid admins who operate large mail networks subject the rest of the net to their ineptitude. William makes very valid points. Daniel _______________________________________________ IOZ mailing list [email protected] http://lists.internet.org.za/mailman/listinfo/ioz