Live data from Hacker News

The Hostile Email Landscape

liminality.xyz

111–120 of 251 posts

Re: The Hostile Email Landscape

#111

Earlier quoted context omitted.

> Here they were, a third party with whom we had no agreement, yet they were interfering with our ability to do business (and profiting from it). Well... that's an oversimplification. You don't have an agreement, sure, but your recipient has an agreement with them --- your recipient has decided that it's with paying the spam filtering supplier to filter their mail for them. I realise that this doesn't help you, and f…

No. Our recipients had no knowledge of the third party. Instead, their email providers contracted with the third party for filtering services. EDIT: Not sure why it would preclude their liability in any case though. Their customers would be paying to have spam blocked, not emails from legitimate companies with whom they've agreed to do business. If they were blocking these demonstrably legit businesses in error and r…

Right... their email providers, which they are paying to provide email from them. The money chain is still at your recipient's end.

Note that I'm not suggesting you did the wrong thing here --- I don't see anything else you could have done. I'm just saying that pinning the entirety of the blame on the third party provider is wrong.

...

Having read the rest of the thread: I'm sorry to say but the reason why you're having so much difficulty, and the reason why you're getting hostile replies here, is that as an email advertiser people are going to automatically assume you're in the wrong. You are on the edge of an astonishingly dirty industry, and anyone who works in email has been so burnt by the Neptune-sized tidal wave of diarrhoea that is spam is likely to spit in your face before you have the chance to explain that you are not, in fact, a spammer. And chances are that they won't actually care. To a most people, email + advertising = spam.

I really don't have anything to suggest. I have written antispam software, and I've read some of the forums of both sides, and frankly I don't know who's scarier.

Re: The Hostile Email Landscape

#112
post #15
post #8

Earlier quoted context omitted.

Certificates for SMTP servers are meaningless without DNSSEC because crossdomain email servers are a thing.

Crossdomain web hosts are also a thing, and HTTPS works fine. (Sometimes with particularly hilarious definitions of "fine", like CloudFlare's former practice of putting dozens of customers' websites in the same certificate, via subject alternative names.) If you're worried about the fact that your mail host and web host can now impersonate each other, we can just define a new X.509 extension for "I can only be used f…

If someone spoofs a CNAME to evil.com in response to DNS query for google.com, your browser will not accept a certificate from evil.com as valid for google.com, whereas if you send mail to gmail.com and someone spoofs an MX record for mx.evil.com, a vaild mx.evil.com certificate will be accepted.

Re: The Hostile Email Landscape

#113
Everyone seems to agree that email is broken (and yet incredibly useful and almost universal in reach).

So moving on from there, how do we fix it? Who is currently working on fixing it? What would a new protocol look like?

Re: The Hostile Email Landscape

#114
post #62

Surprised he didn't mention third party reputation providers such at Return Path.

I'm surprised as well, since these services reinforce his point even more. In other words, good reputation = $$$. Also, I currently use mailgun (and dabbling with mandrill on some new projects) but I'm intrigued by postmarkapp.com take on dedicated IP addresses. Apparently they won't sell dedicated IP addresses because of the time needed to warm them up, so you get a shared IP and their TOS is stricter anti-spam than…

Mmm... not really. Dedicated IPs are hard to beat if you have a steady traffic of high quality and low-latency delivery is a priority (think of PagerDuty). Most legit businesses/customers have that. Most likely they're not offering dedicated IPs because they're tough to get, especially if you are a small company in email business.

The reason Mailgun and Mandrill can do this is because they belong to much larger companies with better access to IPv4 stockpiles: Rackspace and Mailchimp.

Source: I worked at Mailgun.

Re: The Hostile Email Landscape

#115
post #10

Earlier quoted context omitted.

Joke answer: the blockchain! Real answer: It comes down to trust (duh). But, how do we manage trust online? How do we manage trust in real life? Real life trust is through association of groups. But, groups online are meaningless. A "gmail user" doesn't belong to a community, they belong to The Nation of Google. How do we break down online identities into manageable, trustable communities? How do we bootstrap new com…

You joke about the blockchain, but HashCash (a similar technique to Bitcoin's Blockchain-difficulty (not the metric itself, but how it's used)) was originally conceived as a means of making email computationally costly to send. The main issue was that spammers would use botnets while normal people would be stuck taking a while sending emails (iirc). Personally, I would like everyone to have their own rsa or ecc key.…

With regards to HashCash, the explanations I've seen didn't persuade me (the counter arguments most often cited have been made by some researchers in some IMHO very weak papers). To me it seems that the real reason why it's not being used is that ISPs would have to allocate resources, which would make them less competitive (who wants to offer free email then pay for a lot of infrastructure, or deal with the mess explaining that users have to pay for better delivery). The CPU cost could be moved to the clients, but somehow no IMAP based mail clients seem to ever have implemented it (chicken and egg problem?), and JavaScript has not been an efficient way to do it.

Also, I guess the big ISPs have an easy enough time (in their view?) analyzing trust, which is probably a better solution in general if applicable. The problem is that it's easier to judge (newly created) internal users (accounts) than external ones (random IPs).

I would think improving the mail system would be a research topic, but perhaps not interesting enough from the point of view of researchers (would it be best done in social sciences or computer science?, and there are many real-world variables, taking time to collect and verify, and working out simulations to predict possible remedies).

Re: The Hostile Email Landscape

#116

Earlier quoted context omitted.

"3 and 4 would require a sort of token system" Not to get all handwavey, but I think this is why some people are super excited about bitcoin becoming 'part of the internet'. There are definitely some areas where we need a concept of identity & trust, and bitcoin seems like one of the first truly distributed ways of doing it.

I doubt it. No-one wants to pay to send an email. Even if they did, it'd involve waiting 10+ minutes for a payment to go through and limit the global email rate to a maximum of 5 messages per second. Bitcoin is not a good fit.

Not to pay per email, but to pay per email address. If you aren't a spammer, how many email addresses do you need? I don't think asking for a registration fee akin to a domain name is unreasonable.

Re: The Hostile Email Landscape

#117
post #97

I've managed my own mail server since 1993, and my email address has been the same that entire time. Here are some tips for maintaining sanity: Greylisting still works amazingly well. With a long, long whitelist and greylisting plus DNSBL, I don't even bother running a spam filter, since the little bit of spam and emails from new senders ends up in its own directory as it came from a non-whitelisted sender. Comcast f…

> suddenly Gmail was connecting to my mail server over an IPv6 interface, and I had never bothered to put the IPv6 block into the SPF record

Whoa, I think you just solved the problem I've been having with my outbound e-mail for the last two months! Thanks so much!

Re: The Hostile Email Landscape

#118
post #93

Earlier quoted context omitted.

so... your customers were paying a third party to block you, so rather than working with your customers to figure out what the problem was, you threaten to sue the third party.

That's a rather glib and obtuse way to put it. I'm an Amazon customer. If Amazon can't reach my gmail address because Google started using some third party filtering service, what exactly would you expect me to do? Even if I had the ability, I certainly don't have the inclination to spend time resolving this issue. I'll go so far as to mark something "not spam", but that's about it. The cost to me of not hearing from…

> That's a rather glib and obtuse way to put it.

Glib, yes. Obtuse? less so.

>I'm an Amazon customer. If Amazon can't reach my gmail address because Google started using some third party filtering service, what exactly would you expect me to do?

If your free email address doesn't receive mail you want, I expect you might move to a different mail service. I think that if you want anything but automated support out of a free service, you are expecting far too much. Because you still seem to think sticking with your free email provider is the only reasonable course of action, I can only assume that said free provider is meeting your needs; that the automated support is good enough and that you don't mind the odd false positive.

Sure, if you want service, you are going to have to pay a few dollars, but there are plenty of spamfiltering services that are fairly cheap that do have a real person who will fix it if you tell them you aren't getting legitimate mail.

In reality, users consider "legitimate" newsletters to be spam... spending a bunch of time digging through the "legitimate sender" settings to get the mail you want and not the "legitimate newsletters" is often so much work that users just mark the newsletters as spam, and hope their provider will figure it out. Of course, this works really badly when it comes to reputation systems, as the billing stuff and the "newsletters" often come from the same server.

(really, if you must send "newsletters" in addition to your billing, you should do them from a different mailserver and different email address.)

Re: The Hostile Email Landscape

#119
post #85
post #59

Earlier quoted context omitted.

http://cr.yp.to/im2000.html Internet Mail 2000 IM2000 is a project to design a new Internet mail infrastructure around the following concept: Mail storage is the sender's responsibility.

Bernstein is an incredibly smart guy. But he's also an example of how the social stuff matters. His software would run the internet if he put a little more effort into the social/political side of things. The big problem with IM2000 is that it doesn't solve the real problems. It's focused on the economics of storage of mail, which, yeah, are a thing for a few mail administrators, but generally is considered less impo…

> ... because it would mean that spammers would need to control the servers they use to send for longer than they do now.

This is the reason IM2000 is exciting. Spammers only survive using hit and run tactics. We might see a 99% reduction in total generated spam.

Re: The Hostile Email Landscape

#120
post #97

I've managed my own mail server since 1993, and my email address has been the same that entire time. Here are some tips for maintaining sanity: Greylisting still works amazingly well. With a long, long whitelist and greylisting plus DNSBL, I don't even bother running a spam filter, since the little bit of spam and emails from new senders ends up in its own directory as it came from a non-whitelisted sender. Comcast f…

> Greylisting still works amazingly well. With a long, long whitelist and greylisting plus DNSBL, I don't even bother running a spam filter, since the little bit of spam and emails from new senders ends up in its own directory as it came from a non-whitelisted sender. Any good tips on this section in particular? If I'm running my own mail server, how would I get started making sure this is in order?

old but valid HOWTO blog post. http://blog.philippheckel.com/2010/01/28/how-to-postfix-as-m...
Post reply on HN