Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

Wednesday, September 17, 2014

the PayPal pot calling the Apple Pay kettle black

so if you haven't heard yet, PayPal took out a full page ad in the New York Times trying to drag Apple Pay's name through the mud based on Apple's unfortunate celebrity nude selfie leak. This despite the fact that PayPal happily hands out your email address to anyone you have a transaction with. In essence, PayPal has been leaking email addresses for years and not doing anything about it, so they shouldn't get to criticize others for leaking personal information.

what's the big deal about email addresses? while it's true that we often have to give every site we do a transaction on an email address, we don't have to give them all the same address. in fact, giving each site a different email address happens to be a pretty good way to avoid spam, but more importantly it's a good way to avoid phishing emails, and that's important where PayPal is concerned because PayPal one of the most phished brands in existence.

unfortunately, because PayPal wants all parties in a transaction to be able to communicate with each other, they do the laziest, most brain-dead thing one can imagine to accomplish this: they hand out your PayPal email address to others, which is pretty much the worst email address to do that with. i have actually had to change the disposable email address i use with PayPal because they are apparently incapable of keeping that address out of the hands of spammers, phishers, and other email-based miscreants. furthermore, i also use their service less because i don't want to have to clean up after their mess.

at some point i may have to start creating disposable PayPal accounts and use prepaid debt cards with them. certainly if i were trying to hide from massive spy agencies then that would be the way to go, but if i'm only concerned with mitigating email-borne threats i really shouldn't have to go to that much trouble. there are other, more intelligent things that PayPal could, even should be doing.

  • they could share the email address of your choosing, rather than the one you registered with their service unconditionally. that way you could provide the same address you probably already provided that other party when you created an account on their site. it shouldn't be too difficult for them to verify that address before sharing it with the other party since they already verify the one you register with.
  • they could offer their own private messaging service so that communication could be done through their servers (which would no doubt aid in conflict resolution).
  • they could provide a disposable email forwarding service such that the party you're interacting with gets a unique {something}@paypalmail.com address that forwards the mail on to the email address you registered on PayPal with, and once the transaction is completed to everyone's satisfaction the address is deactivated.
they don't do anything like that, however. here's what you can do right now with the facilities PayPal makes available. it's a more painful and less intuitive process than anything proposed above, but it does work.
  1. before you choose to pay for something with PayPal, log into PayPal and add an email address (the one you want shared with the party you're doing a transaction with) to your profile. PayPal limits you to 8 addresses.
  2. confirm the address by opening the confirmation link that was sent to that address
  3. make that address the primary email address for your account
  4. confirm the change in primary email address (if you have a card associated with your PayPal account, PayPal may ask you to enter the full card number)
  5. at this point you can use PayPal to pay for something and the email address that will be shared with the other party is the one you just added to your PayPal account
  6. once you've paid with PayPal you will probably want to log back into PayPal, change the primary email address back to what it originally was (and confirm the change once again) and then remove the address you added for the purposes of your purchase. the reason you'll likely want to do this is because PayPal sends emails to every address it has on record for you, and those duplicate emails will get old fast.
most people aren't even going to be aware that they can do this to keep their real PayPal email address a secret from 3rd parties. as a result all manner of email-borne threats can and eventually will wind up in what would otherwise have been a trusted email inbox. make no mistake, this isn't PayPal providing a way to keep that email address private, this is a way of manipulating PayPal's features to achieve that effect. there are too many unnecessary steps involved for this to be the intended use scenario.

as such, PayPal is leaking a valuable email address by default every time you pay for something. yes Apple's selfie SNAFU was embarrassing to people, and yes if Apple doesn't do something about that now that they're becoming a payment platform it could be not just embarrassing but financially costly for victims, but PayPal is already assisting in similarly costly outcomes right now (not to mention potential malware outcomes) so they really have no right to be criticizing Apple. Apple, at least, is taking steps to correct their problems - what is PayPal doing?

Saturday, March 20, 2010

fooled by spam

march has really not been my month. first i find out that not only have i finally had my very first malware incident but that it had also been present for nearly a year, and then i get fooled into approving a comment that is in actuality spam.

cdman83 has a writeup on the spam campaign, and gunter ollmann got the final word from sophos that it really was someone loosely associated with them (an employee of a company they hired) who was responsible and who they intend to take to task over the fiasco.

perhaps i'm losing my touch in my old age and becoming too trusting, too willing to give the benefit of the doubt. then again, if i'd had the multiple comments that gunter ollmann had i would have had a far less ambiguous dataset from which to draw conclusions from. i guess i shouldn't feel too bad about being fooled, after all i was only fooled into approving a relatively benign comment - sophos was fooled into hiring the company in question in the first place and giving them money.

Thursday, February 11, 2010

user database breach at instructables?

many have at least heard the advice to use unique passwords at every site they visit. well i go a few steps beyond that. not only do i use unique randomly generated passwords at every site, i use unique randomly generated email addresses at each site too.

that probably sounds like overkill, but consequence for me (besides knowing exactly which sites are spammy) is that the older identities collectively form a kind of honeypot for detecting user database breaches.

it was as a result of my address for ethicalhacker.net receiving spam that i realized (and later verified) that something untoward had happened there and so it is that today i'm going to come out and say that something fishy is going on over at instructables.com.

a unique, randomly generated email address (basically a secret shared between only myself and instructables) that is unguessable (there are approximately 4.7x10^18 possible values so the chance of them guessing one of my 200 or so addresses is so small that if they guessed 1 million times a second it would still take on average 375 years before they got one) should only be usable by those who know it, so the fact that i'm receiving drug spam at this email address tells me that somehow the user information they had in their database for my account has been leaked.

*update*: it appears i miscounted the number of characters in the email address and thus my probability calculations are off. there's only 1x10^14 combinations, which means that at a million guesses a second someone could get expect to guess one of mine in (on average) about 3 days. i'm not convinced that sort of brute forcing operation is going on, however (it seems like it would be too much work for too little benefit).

Sunday, December 06, 2009

sneakemail is no longer free

well, y'know what they say, all good things must come to an end and the free ride at sneakemail.com appears to be one of those things. as of sometime earlier this month sneakemail.com moved to a paid service and existing accounts were switched over to the one month trial setup.

if you're using sneakemail then this is probably something you want to know about (i found out quite by accident) because when the trial is over your emails won't get forwarded to your real email address anymore.

i've been using sneakemail for years now, and directing others their way. it's a great service and it's helped me keep spam in check so i don't want to say that their service isn't worth the $2 a month fee, but recurring charges are the bane of my existence so i'm not sure what i'm going to do. this is complicated by the fact that i have so many addresses with them (most of which get no traffic, but still). switching to another service would be a pain due to a several years long habit of using sneakemail as well as all the existing addresses i'd have to switch over. plus there's no guarantee that the next one will turn out any better in the long run. paying the fee would also be a pain, and an ongoing one at that.

but enough of my griping - you're now forewarned, go do something about your account if you're a sneakemail user. you have less than 30 days.

Wednesday, July 01, 2009

live by the sword, die by the sword

so yesterday i got a rather rude surprise by email. google, in their infinite wisdom, had decided to label this blog as spam and had locked it, preventing me from publishing what i had planned to publish. if i hadn't acted within 20 days the blog would have been deleted, apparently.

yes, it was the real google and not a spear phishing campaign (it would have made for good social engineering but who'd spear phish me?). they used the exact email address that i only gave to google for my blogger account, and furthermore, when i visited my blogger dashboard (not following the link in the email) it showed the warning about it there plain as day so it was definitely for real.

according to the literature i was seeing, the system by which they identify splogs is automated. they mentioned fuzzy logic, but we know what that means - heuristics (though not the same heuristics used in anti-malware, obviously). although i'm not exactly some hardcore heuristic fanboy i can't help but feel there's a bit of irony in me (or more specifically this particular blog) catching the business end of a heuristic false positive.

there is, of course, an appeal process they give you (so that your blog doesn't get deleted after the 20 day grace period) but i found it a little annoying that there was no indication anywhere that i'd successfully initiated that process and it was only when i checked again today and found the splog notification gone that i had any clue that anything had gone through. the real test, of course, is publishing and that's part of what this post is meant to achieve - if you're seeing this then the blog is back to normal.

Monday, December 01, 2008

unexpected spam

you may recall me saying here or there that i have a 100% spam free email address... it's an address that i don't give out to people or sites... it's not that the address is unused - i actually use it a lot, but i use it in conjunction with sneakemail.com so it's not my real email address getting spammed - and because i use a different sneakemail address at every site it's no problem to just deactivate or even delete the address and not deal with that site anymore (see my post on avoiding spam)...

so as a result i don't check the spam folder very often - it's almost always empty and when it's not the messages in it are almost always in there erroneously... it's so rare that i actually hand out any address to an organization that will compromise it to spammers (or spam it themselves) that i see more false alarms from the spam filter than i see true alarms...

that all changed with a vengeance today as i found over 50 messages in my spam folder and almost all of them were correctly classified... and wouldn't you know it, the majority were addressed to the sneakemail address that i used for demonstration purposes in this post on phish detection... it certainly took a while for the spammers to find that one (i wonder if they liked the spam poison i laid out as well)...

unfortunately that wasn't the only address that was receiving spam... i don't pretend to know what exactly happened here, but the unique, randomly generated, unguessable address i used to sign up to for ethicalhacker.net has also started receiving spam... the chances of spammers finding that address by enumerating the sneakemail address space are incredibly low (it's a 7 digit base36 number) especially since i have quite a few sneakemail addresses and this is the only one getting spammed by this particular person using the freetellafriend.com service... somehow the folks at ethicalhacker.net let my email address get compromised so you can bet i won't be dealing with them any further (not that i did much there in the first place)...

so anyways, it was quite a shock to see so many spam messages in the spam folder of my spam free email account, but they were all sent to disposable addresses (not the real one) that are no longer reachable so it's all good...

Tuesday, May 06, 2008

harnessing the power of spam

one of the things i really like is the concept of using the bad guy's tactics against them... i enjoy the subtle irony, so when dmitry chan mentioned the possibility of harnessing the power of spam over on the securiteam blog my creative juices started to flow... i thought i'd share the idea i came up with if for no other reason than because i think it's kind of funny...

the idea is that you use spam emails in CAPTCHAs... if you can pick the ham out of the spam then you pass the test... as the bad guys make advances to beat such spam-based CAPTCHA systems, we use their advances in our spam filters and remove the now detectable spams from the spam-based CAPTCHA so that the bad guys have to keep advancing the art of spam detection in order to bust the CAPTCHAs that stand between them and the ability to produce more spam...

this may well not be workable in practice (i imagine it may simply get too hard for real people to identify the ham) but it's still fun to imagine spammers working against themselves (or more likely against each other since it offers them a new way to compete against each other)...

Thursday, August 23, 2007

who doesn't love bacn?

seems a new meme was born recently involving an email classification called bacn... it seems it's become important to classify notification and other emails that you actually want to receive but don't have time to look at right now...

it also seems that some people see a problem here... frankly, i don't... bacn isn't spam, it isn't anything like spam... it's sent by cooperative parties more or less at your request - if you don't want to receive it anymore you can ask for it to stop and it should actually stop... and since it isn't being sent maliciously it's not going to mutate and evolve rapidly in order to avoid filters that move it into folders specifically made to hold it and organize it and keep it from making your inbox unmanagable...

basically, everything we learned not to do with spam actually works on bacn because bacners (got a better term for bacn senders?) are cooperative rather than malicious...

Wednesday, August 15, 2007

what is comment spam?

comment spam is spam that appears in blog comments instead of in email...

traditionally the idea behind comment spam was to add links a spamvertised (advertised by spam) site to various other sites so that a) people would follow those links and visit the spamvertised site and b) search engines like google would rank the spamvertised site higher since there were more links to it and so it would be more likely to show up on the first page of search results (basically a kind of search engine optimization scheme)...

different blogs have different means of coping with comment spam: some have a CAPTCHA, some require a moderator to approve the comment before it can appear on the blog, some use moderation after the fact (so that for a while the spam will actually appear there), some require the commenter to create an account, and some even have advanced content or IP-based filtering... not all blog owners implement anti-spam functionality for their comments, however, and no anti-spam technique is perfect so in some cases the spam still gets through...

to combat the SEO effect some (possibly most) blog platforms implemented a technique by which links in comments would be marked in such a way that search engines wouldn't count them regardless of whether they were good links or bad links...

that didn't stop comment spam either, of course - people can still follow the links and not all comment spam even has links anymore... as such blog owners still often need to use techniques like those described above to combat comment spam...

back to index

what are splogs?

a splog is a form of web-based spam in the form of a blog...

unlike comment spam, in the case of splogs the entire blog in question is spam, not just a small part of it... because blogs are so easy to setup and publish content on it's become a popular way of spamvertising a site...

to combat this type of abuse of service, blogging service providers typically employ anti-spam techniques like CAPTCHAs to prevent the automated creation of splogs but CAPTCHAs are becoming less effective as techniques for defeating them are developed... on top of that, CAPTCHAs don't prevent real live humans from setting up splogs... because of this, blogging service providers try to prune out splogs manually when they become aware of them...

back to index

Sunday, July 15, 2007

how NOT to fight spam with gmail

there's a rather misguided piece of gmail-related anti-spam advice that crops up from time to time and has been seen most recently here, here, and here... i try to debunk this whenever i see it but gosh darn it the blog comments just don't seem to be getting through to people so . . .

the basic idea is to transform your gmail address (using the well known transformations of adding extraneous dots or the '+keyword' trick) when you give it out to sites so that when (not if) the address gets misused by spammers you can easily make a filter to delete mail sent to that address...

here's an example: the.president@gmail.com

here's another example: thepresident+nopoliticalmessagehere@gmail.com

now, these tricks are well known, they're easy to apply, but most importantly they're easy to reverse because all the information needed to determine what the true gmail address is must remain present for the tricks to work... if you know that google ignores any dots before the @ sign can you guess what address email to the.president@gmail.com gets delivered to? yeah, thepresident@gmail.com... futher, if you know that everything between the + and @ get ignored (+ inclusive) can you guess where email to thepresident+nopoliticalmessagehere@gmail.com gets delivered to? once again, thepresident@gmail.com...

doesn't seem like rocket science, in fact, it's so easy you can write a program to do it for you - and not to put too fine a point on it but it's almost a certainty that someone already has and put the functionality into an email address management program used by email harvesters and spammers...

that means this trick has next to no value in actually combating spam... i've written before about handing out special email addresses to web sites to help stop spam but the key aspect to that, the thing that makes it actually work, is that your true email address remains secret... not only does the gmail id aliasing trick not keep your true gmail address secret, it gives the spammers the opportunity to create arbitrarily many other aliases so that you can never filter by alias - if you filter out mail to the.president and thepresident, mail to t.h.e.p.r.e.s.i.d.e.n.t will still get through as will mail to thepresident+wants.v1agr4...

these tricks can be useful for organizing incoming mail, but if you want to combat spam by handing out special email addresses you have to use addresses that keep your true address secret...

Saturday, March 10, 2007

what is stock spam?

stock spam is a form of spam intended to 'sell' a particular stock that the spammer has already invested in so that the price will go up and allow the spammer to sell his/her shares at a profit...

otherwise known as a pump and dump scheme, stock spam is unusual compared to more conventional forms of spam in the sense that there is no need to show the recipient a URL or clickable link of any kind... there is no specific vendor site which you need to go to in order to buy the stock, the spammed stock is bought where any stock is bought... this makes stock spam a prime candidate for being implemented as image spam since the image spam's lack of a clickable link won't have any negative effect on the stock spam's success...

another difference between stock spam and regular spam is that stock spammers are rarely operating on behalf of the company whose stocks they're pumping... in fact, pumping and dumping can hurt a company's stock so the companies whose stock get spammed by a stock spammer are just as much a victim of the stock spammer (if not more so) than the spam recipients...

back to index

what is image spam?

image spam is a form of spam where the contents of the spammed email are generally little more than an image file containing an advertisement for the product being spammed... often such emails don't even include a clickable link to follow to get to the vendor's website in order to buy the product - instead they contain a url in the picture that the recipient then has to type into his/her browser in order to get to the vendor's site...

a large amount of the spam seen lately is image spam... martin overton has posted about it on a number of occasions on his blog and this post on spam in particular shows multiple types (i think the ransom note format is rather humourous) though a lot of advancement has been made in spam obfuscation since even that short time ago...

the basic premise behind using images in spam instead of normal text or html is that it makes it much harder to analyze in an automated way... essentially, it uses the principles of CAPTCHA in order to foil anti-spam technologies... it used to be that an anti-spam technology would simply look at the contents of an email to tell if it was spam or not, but with image spam it becomes necessary to create software to extract the text from an image (often a distorted image) before those contents can be analyzed and what makes CAPTCHA work is that that's not easy for a program to do...

this isn't the first time such dark implementations of CAPTCHA have been seen... certain email worms have used it in the past in order to foil automated email scanners (the worms sent themselves in a password protected archive along with an image containing the password - and yes, even with all the hoops one would have to jump through in order for such a scheme to be viable, a number of those worms were successful)...

back to index

Wednesday, January 10, 2007

phishing alarmism

there's a new post over on the securiteam blog that seems to be just a little too concerned about a bank of america suggestion to add an email address to customer's address books... the author seems to believe that following the suggestion will make customers more vulnerable to phishing, that the bank is asking them to lower their defenses...

now, it's not like they're telling people to lower the security settings on their browsers in order to view the bank's website (though perhaps they do that too, i don't know), they're just telling their customers to whitelist them so that their emails don't get rejected by spam filters... the author's contention is that phishers will then start using the same address the customers whitelist as the From: address on their own phishy emails and because the address is whitelisted the customers will be exposed to each and every one of those phishing emails...

but here's the thing, even if bank of america didn't advise their customers to whitelist the email address, the phishers would have used it anyways... phishers posing as bank of america will use any address bank of america uses, regardless of what customers do with that address... there's nothing bank of america can do to stop that and there's nothing customers can do to stop that so it makes little difference whether the customers whitelist it or not... whitelisting the address doesn't mean they can start implicitly trusting email apparently sent from that address, it just means that bank of america's legitimate correspondence won't get lost in the junk mail folder...

of course the phishing emails won't get lost there either, perhaps that's the problem? unfortunately, spam filters aren't really any good at stopping phishing emails... the phishers work hard to make their emails look legit (otherwise they wouldn't fool anyone) so they should be equally affected or equally immune to spam filters as the legitimate bank of america emails are... if the legit emails get through then so will the phishing emails, and if the legit emails don't get through then the users will have to look in their junk mail folders for them and then wind up being exposed to the phishing emails anyways...

basically it's a zero-sum situation as far as phishing goes - nothing the legitimate sender or the receiver do with the From: address can increase or decrease the exposure to phishing so the bank of america customers might as well whitelist bank of america's email address - and security folks might as well wake up to the fact that just because something can be used to a phisher's advantage doesn't mean the user is put at greater risk... spam filtering and anti-phishing are not the same, even though we don't want to see either spam or phishing emails in our inboxes, defenses against one are not necessarily appropriate or applicable towards the other... the officially whitelisted email address just means the phishers don't have to work so hard to figure out what email address to forge on their phishing emails - their convenience does not equal lower security for others...

(and if you're wondering why this isn't a comment on the securiteam blog, it's because i can't leave comments there anymore... they've been consistently rejected as spam for months regardless of content, email address used, or the presence of a url - and the blog admin who's supposed to be alerted to the comment in order to correct the issue if it was misclassified never does, nor is there any obvious way to follow the directions which say to contact him/her about it... they sure know how to make a guy feel welcome...)

Thursday, December 28, 2006

how to avoid email spam

typically, the life-cycle of email spam (in the most general sense) goes something like this:
  1. the spammer gets your email address
  2. the spammer sends you spam
  3. you receive and do your best to deal with that spam

most of the anti-spam technology that the average person is aware of works to deal with spam after it's been sent, effectively trying to address stage 3 in the spam life-cycle... you probably know this technology as spam filtering, either a black list where you record all the email addresses (or perhaps domains) from whom you don't want to receive email, a white list where you record all the email addresses from whom you do want to receive email, or some more advanced content-based spam filter such as the bayesian filtering... as most average people are at least vaguely familiar with spam filtering (even if only by way of noticing there's a junk mail folder in their webmail) they also know (or if not, should be made aware) that filtering isn't a perfect solution, that some legitimate mail can get flagged as spam and some spam may fool the filter into thinking it's legitimate mail... nothing is perfect, but as spam volume increases the number of spams that sneak through spam filters also increase, and nobody (except the spammers) want to see the amount of spam in our inboxes increase...

addressing stage 2, trying to stop the spam from getting sent or at least making it more difficult or costly, is something most average folks aren't aware of (or at least don't often think about) because it's not something they've been a part of for the most part... early on there was account termination for those caught spamming, then there were CAPTCHA tests to stop the spammers from creating very large numbers of accounts (which would otherwise make account termination a non-issue) from which to spam from... after that there was a crack down on open mail relays and ISPs started trying to block their subscribers from connecting to outside SMTP servers... now spammers use botnets designed for sending spam, effectively moving the burden of stopping spam out of the hands of centralized organizations like ISPs and into the hands of end users whose machines have been compromised and who are least likely to be able to deal with the problem or even be aware of it's existence... if you've never heard of this before, now you've got a brand new reason to prevent malware from compromising your computer - to help keep the spam problem in check...

avoiding spam
neither of these qualify as avoiding spam, however... in order to do that one must address spam at the earliest stage in it's life-cycle, one must stop the spammer from getting one's email address in the first place... think of your email address as being like your home phone number - it's confidential information that you don't hand out to every tom, dick, and harry you happen across...

keeping your real email address secret is probably not the most intuitive thing in the world, especially since so many things require you to give them an email address, but there are services and techniques that can help make it easier... there are also limits to how well the secret can be kept, but as an example i've managed to keep a webmail address i use daily completely spam free (there isn't even anything in the spam folder) for over 2 years simply by being careful and not giving out the address except to those i trust... one other caveat is that you can't make an email address secret if it wasn't a secret before... if your current address is receiving spam then the spammers already have your email address, the address has been compromised and there's nothing you can really do about that - you can't put the genie back in the bottle...

what you can do, with a fresh email address, is use disposable email addresses that forward to that real email address... a number of people are already familiar with the idea of a throw-away email address and often use hotmail or some other free webmail provider to make one but unfortunately that leaves you with no way to know who leaked your address to the spammers so when you need to change addresses (because the current throw-away address has gotten too spammy) you'll have no way to know which organizations to not give the new address to (never mind the fact that you'll have to give a new address to a bunch of organizations)... this is where true disposable email addresses come in - you need to use a different address for each site you give an address to (whether it's ebay, amazon, or your bank) so you can identify which one leaked the email address simply by looking at which email address got leaked and so that you only have to turn off that one address when it starts getting spammed rather than changing addresses and updating a potentially long list of sites with your new address... dedicated disposable email address services make creating multiple addresses easier (certainly easier than creating multiple throw-away email addresses where you have to answer a CAPTCHA test for each one) and managing multiple addresses (ie. turning off the ones that get spammy) easier as well...

different services provide addresses with different properties; some will forward the email sent to the disposable address on to your real address while others might maximize the ease and convenience of creating a new address by allowing you to create one without contacting the disposable email address provider first... beware the combination of these two properties (something spamgourmet.com does), however, because you invariably wind up giving out the information necessary for others to create new addresses that will forward to your real address and you don't want any tom, dick, or harry to be able to do that anymore than you want them to be able to email you directly... instead, use the created-on-the-fly addresses in cases where no sensitive information is going to be sent and/or in cases where you're likely only going to need to check for mail once (because most on-the-fly disposable email address services also don't require a login to check the email - mailinator.com and dodgeit.com work this way), and use forwarding addresses (such as those from sneakemail.com or mailnull.com) for everything else so that you get the benefit of picking up the mail in one place that only you (and your real email provider) have access to...

website feedback
now that takes care of sites that ask you for your email address, what about if you have a website or even a blog like this one? you want to be able to receive feedback from people without being deluged by spam but if you put an email address on the page then software that searches for email addresses on the web will find that address pretty quickly and it will soon be filled with spam... using disposable email addresses on their own doesn't solve this problem...

one thing people like to try is email address obfuscation - where the email address is manipulated in such a way that software that searches for email addresses can't easily recognize it as one... unfortunately this runs into competing requirements - in order to truly prevent software from collecting your email address for the spammer the email address has to not be machine readable, however people expect to be able to click on something and start typing their feedback and that functionality requires that the email address is machine readable... no email address obfuscation method can achieve both requirements so you generally either have to break expected functionality or accept that the email address isn't truly hidden...

a better solution is to use a contact form, specifically one that doesn't contain your email address in it's code... mailnull.com happens to offer this facility, it's what i'm currently using for this site at the time of writing, you can see what it looks like by clicking here... the only major drawback to using a web-based contact form is that people can't send you attachments but considering how troublesome attachments can be from a security standpoint, not providing a way for first time contacts to send them to you doesn't seem like all that big a deal... if you do encounter a scenario where it is a problem, the first time contact could use a file storage solution like dropload.com with their own disposable email address in the To: field and then paste the resulting URL into the web contact form...

additionally, if you not only have your own website but your own domain, you may want to turn off the default/catch all email functionality (where email sent to any non-existent address on that domain is 'caught' and collected for review and possible redirection to relevant parties)... so long as you are providing people with a clear way to directly contact the right individuals within your domain there should be no reason for anyone to send email to non-existent addresses on your domain or firing emails blindly at arbitrary addresses on your domain...

friends and family
as i mentioned before, there are limits to the extent to which you can keep your email address secret and a potentially very big hole in the strategy involves your trusted contacts (be they friends, family, or business contacts)... these are people you can't reasonably be expected to keep your email address a secret from and so may wind up being a source of email address leakage... what can you do?

pretty much what you can do boils down to treating their email addresses with the same care you would treat your own and teaching them to do the same for you (maybe even pointing them here)... that means that you shouldn't give their addresses to websites no matter how cool those websites might happen to be or how interesting you think your friends/family/contacts will find the site (even those greeting card websites that are so popular around the holidays) - instead you should give those sites one of your own disposable email addresses and then forward the resulting email to the person you wanted to share the site with, thus giving them exactly the same information you would have given them if you'd exposed their email address to the website but without actually exposing their email address to the website...

additionally, don't share people's email addresses with other people they don't know... if you're emailing people that don't know each other, put your own email address in the To: field and put the other email addresses in the Bcc: field so that they can't see each other's addresses... if you're forwarding something to people, make sure not to include any of the email addresses that it was previously sent to or from as forwarded emails otherwise tend to build up large numbers of email addresses on a large number of strangers machines - any one of which might get compromised by a piece of malware that harvests email addresses for spammers and other email miscreants and that's something you want to minimize where possible...

anti-spam safe hex
all these things effectively form a set of spam-related safe hex rules... summarized, they are:
  1. treat your email address like a secret
  2. use a different disposable email address for each website you give an address to (so that if you do get spam you can tell who to blame)
  3. use contact forms instead of email addresses on your website
  4. turn off the catch-all email functionality for any domain you might have
  5. don't give your friend's/family's/contact's email address to websites
  6. don't give your friend's/family's/contact's email to people they don't know
  7. try to teach your friends/family/contacts to show your email address the same care that you show theirs

Thursday, November 23, 2006

what is spam?

spam is a form of network abuse whereby one tries to force feed a (usually commercial) message to as many people as possible...

by force feed i mean that the spammer puts the message where people don't want it and can't easily ignore it - often they have to do something about it to get rid of it...

reaching as many people as possible is achieved either by sending the message many times to many people (such as with email spam) or broadcasting it in such a way that a single instance of the message will be seen by many people (such as with usenet spam) or both...

it may seem like this description isn't doing spam justice, that spam's impact is larger than what is implied here, that a message you don't want to see is a minor annoyance (like commercials on tv) in comparison to spam... well multiply that minor annoyance by 100 (or more)... a single spammed message really doesn't have a lot of impact and if we only got a single spam every now and then we wouldn't really be all that concerned about it... the problem with spam doesn't come from the nature of spam but rather from the sheer unrelenting volume of spammed messages... one popular statistic (at the time of writing) states that spam accounts for 85% of all email traffic - that's a lot of garbage to wade through to get useful content out of your email...

spamming can be done over any network that humans communicate (in some fashion) over such as email (conventional spam), usenet (usenet spam), instant messaging (spim), blogs (splogs), blog comments (comment spam), or even p2p networks...

[see this article on spam etymology for details on the origin of the term]

back to index

Sunday, May 28, 2006

the merits of the blue security anti-spam approach

if you hire someone to send a million messages on your behalf, you better be prepared for a million responses...

that was the gist of blue security's blue frog anti-spam technology, and it's the approach that okopipi hopes to build upon... i posted about blue security going down for the count previously and i predicted that a group like okopipi would try and fill blue security's shoes (not through any sort of precience, mind you, but rather just because it would have fit an established pattern of human behaviour), but it seems okopipi have stirred up a hornet's nest of controversy in the process...

let's look at the criticisms... the one with the most technical merit concerns the anti-spam registry that the blue security approach had... essentially it was a list of hashes of email addresses that the spammers could use to remove blue frog users from their spam lists... the fact that email addresses were hashed (a non-reversible transformation) prevented spammers from finding any new addresses directly from the registry, however it did allow them to identify which addresses in their own spam lists were blue frog users and that allowed them to retaliate against those users... however there is no way to tell spammers which email addresses to remove without identifying those email addresses - the only alternative is to not offer the spammers any kind of remediation process at all and say "sucks to be you", which clearly would have had much worse chances of a productive outcome... a zero tolerance approach may be safer for the users, but it can't get their names removed from the spammers' lists - it's predicated on getting the spammers to give up their business entirely instead of simply adjusting their approach and i suspect that nobody is that persuasive...

another criticism is that the blue security approach could be used against innocent merchants... the idea was that if one sent out spam advertising a competitor, that competitor would then have to deal with a deluge of complaints they could do nothing about.... this rose out of the more general concern about whether it's possible for blue frog to target the wrong site and what happens then... the thing is, blue frog could only send complaints to sites that blue security enabled it to and blue security took pains to confirm that those sites were appropriate places to lodge complaints... the process they followed can be reviewed here...

[edited to add this paragraph] still another criticism is that sites are hosted on hacked machines and just move around from one hacked machine to another... that kind of thing can be detected, however, since blue security contacted the isp as well as the merchant site... also, a fly-by-night operation wouldn't have gone unnoticed with an examination period exceeding 10 days... if the site was one that didn't stick around for at least a couple days blue security would have had no reason to develop a script to send complaints to it...

there's also a criticism that sending opt-out requests to the merchant sites constituted a DDoS... this is a rather ridiculous thing to say - each person who receives a spam has a right to complain about it, and since the spammer was merely acting as an agent of the merchant when s/he sent out the spam (and since the spammers go to great lengths to not be reachable themselves) the merchant is the appropriate entity to address one's complaints to... at most one opt-out would be sent per spam the blue frog user received and each opt-out was a response to an incomming spam message... while that may result in service disruptions for the merchant, it's no different than if each spam recipient manually went to the merchant's site and complained (and lets face it, the spam invites each recipient to visit the merchant's site)... the blue frog cleint automated the process of filing a complaint initiated by the user, nothing more...

an even more outlandish claim is that the blue frog clients installed on user machines constituted a botnet... a botnet is ultimately controlled by a central controller, a bot master... the blue frog clients were operated by the blue frog users themselves, not blue security - blue security just sent out updates to those clients (which included instructions on how to send the complaints but not instructions to actually send them)... these kinds of claims by so-called security experts are pure FUD... those spreading the FUD appear to be parroting the opinions of others and simply claim there is universal agreement rather than actually backing up their claims - that kind of argumentation is fallacious and hopefully more people will be able to see that now...

blue security's approach was designed in such a way that the easiest way to resolve the problem was to remove the specified addresses from their spam lists (and they had safeguards in place to prevent their system from being abused to hurt legitimate merchants) - unfortunately while we as humans often take the easiest way out sometimes we don't and that manifested itself in this case in a significant DDoS attack against blue security (bringing down their website and service) and it's users (sending them orders of magnitude more junk mail than usual)... some spammers didn't like being told what to do and and had the means to retaliate and now blue security is no more... okopipi hopes to develop a similar system but one that is less prone to attack (though nothing is invulnerable)... i hope they employ equivalent safeguards against abuse and if so, more power to them...

Wednesday, May 17, 2006

the future of blue security

i know it sounds like a strange subject to blog about, now that blue security has given up... the thing is, this is the internet - and i've been on the internet long enough to know that neither good ideas nor bad ideas ever happen just once... everything gets repeated - over and over and over and over and over again...

so the spammers knocked the company off the face of the web with a DDoS (distributed denial of service) attack... the very fact that they mounted such a counter attack is an indication that the technique blue security was using was working... lashing out the way they did is a sign of weakness, not strength...

unfortunately (for the spammers) the spammers are apparently unfamiliar with the streisand effect... their actions have served to advertise their vulnerability and all the people who thought blue security's idea was a good one and a bunch of new people who hadn't even heard of it before are now going to recognize that vulnerability for what it is and put that information to use...

you see, you might be able to kill a commercial venture like blue security through force and intimidation, but you can't kill an idea quite so easily... you remember what happened when the original napster went down? hundreds of knock-offs popped up in it's place and peer-to-peer filesharing has been an unstoppable hydra ever since...

it's likely that something similar will happen here with the same analysis of past efforts, identification of points of weakness, and innovation to overcome those weaknesses that continues to take place on the p2p front to this very day...

and what about that one russian spammer threatening to take down the entire internet if he can't send his spam? well let's just say that there are all kinds on the internet, and i'm not naive enough to think that there aren't some people out there that are so fed up with spam as to be willing to endure the internet version of a scorched earth in order to affect a final solution to the spam problem...

blue security may be gone, but i don't think the story is over... not by a long shot... the spammers clearly won this battle, but they may have just lost the war...