Re: False positives (was Re: [Asrg] Re: RMX Records)

"David F. Skoll" <dfs@roaringpenguin.com> Wed, 05 March 2003 22:02 UTC

Received: from www1.ietf.org (ietf.org [132.151.1.19] (may be forged)) by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA02066 for <asrg-archive@odin.ietf.org>; Wed, 5 Mar 2003 17:02:25 -0500 (EST)
Received: (from mailnull@localhost) by www1.ietf.org (8.11.6/8.11.6) id h25MD8M27482 for asrg-archive@odin.ietf.org; Wed, 5 Mar 2003 17:13:08 -0500
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h25MD8O27479 for <asrg-web-archive@optimus.ietf.org>; Wed, 5 Mar 2003 17:13:08 -0500
Received: from www1.ietf.org (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id RAA02051 for <asrg-web-archive@ietf.org>; Wed, 5 Mar 2003 17:01:54 -0500 (EST)
Received: from www1.ietf.org (localhost.localdomain [127.0.0.1]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h25MB5O27370; Wed, 5 Mar 2003 17:11:05 -0500
Received: from ietf.org (odin.ietf.org [132.151.1.176]) by www1.ietf.org (8.11.6/8.11.6) with ESMTP id h25MAQO27274 for <asrg@optimus.ietf.org>; Wed, 5 Mar 2003 17:10:26 -0500
Received: from ottawa-hs-209-217-122-117.s-ip.magma.ca (ietf-mx.ietf.org [132.151.6.1]) by ietf.org (8.9.1a/8.9.1a) with ESMTP id QAA01867 for <asrg@ietf.org>; Wed, 5 Mar 2003 16:59:03 -0500 (EST)
Received: from shishi.roaringpenguin.com (shishi.roaringpenguin.com [192.168.2.3]) by shevy.roaringpenguin.com (8.12.8/8.12.8) with ESMTP id h25M16BD032752 for <asrg@ietf.org>; Wed, 5 Mar 2003 17:01:06 -0500
From: "David F. Skoll" <dfs@roaringpenguin.com>
To: asrg@ietf.org
Subject: Re: False positives (was Re: [Asrg] Re: RMX Records)
In-Reply-To: <43978.207.127.152.83.1046899521.squirrel@www.newfrontiersw.com>
Message-ID: <Pine.LNX.4.53.0303051655250.6837@shishi.roaringpenguin.com>
References: <E18qYqt-0003gY-00@mail.nitros9.org> <Pine.LNX.4.53.0303051448220.4869@shishi.roaringpenguin.com> <43978.207.127.152.83.1046899521.squirrel@www.newfrontiersw.com>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
Sender: asrg-admin@ietf.org
Errors-To: asrg-admin@ietf.org
X-BeenThere: asrg@ietf.org
X-Mailman-Version: 2.0.12
Precedence: bulk
List-Unsubscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=unsubscribe>
List-Id: Anti-Spam Research Group - IRTF <asrg.ietf.org>
List-Post: <mailto:asrg@ietf.org>
List-Help: <mailto:asrg-request@ietf.org?subject=help>
List-Subscribe: <https://www1.ietf.org/mailman/listinfo/asrg>, <mailto:asrg-request@ietf.org?subject=subscribe>
List-Archive: <https://www1.ietf.org/pipermail/asrg/>
Date: Wed, 05 Mar 2003 17:01:06 -0500

On Wed, 5 Mar 2003, Terry Carmen wrote:

> Small companies routinely get several hundred, up to several thousand
> spams/day.

That's manageable, and a couple of orders of magnitude less than what
Alan gets.

> I found the biggest improvement by blacklisting Korea and China.

Yes, that works pretty well.  Nigeria and Brazil too.

> Unfortunately, this still wastes my bandwidth.

To the point where you actually have to pay more money?

> At some point in the world of spam, there is a network operator who has
> allowed a spammer a connection. This may be an ISP, Network Provider or
> simply an open relay. It really doesn't matter. The place where the mail
> enters the netwok should feel pain for polluting our space.

Right; I agree.  And there are ways to do that even now:

- Tempfail suspected spam until it is accepted or rejected by a
person.  This works well for small organizations with spare bandwidth.
It won't work for large organizations, unfortunately, but if enough
small people do it, the open-relay or spam server will feel the pain.
Each recipient will pay for a little bit more bandwidth; the relay will
pay for a lot more bandwidth plus clogged queues.

- Litigate.  The US is lawsuit-happy; even the threat of being sued
would probably make an ISP crack down on spammers or an open relay
mend its ways.

- Blacklist.  If ISP's refuse to play ball, blacklist them.

--
David.
_______________________________________________
Asrg mailing list
Asrg@ietf.org
https://www1.ietf.org/mailman/listinfo/asrg