Live data from Hacker News

Spam blacklisting is out of control

blog.roastidio.us

391–400 of 430 posts

Re: Spam blacklisting is out of control

#391

Earlier quoted context omitted.

> That seems a lot of rationalisation for a situation where a genuine sender on another system sends legitimate mail to a genuine recipient on your system, that mail is not properly delivered, and it's your fault. It's how the internet stays functional. If 0.001% of legitimate mail has to go undelivered in order to prevent overwhelming amounts of spam/attacks from an irresponsible network that's an acceptable loss to…

It's how the internet stays functional. [citation needed] If 0.001% of legitimate mail has to go undelivered in order to prevent overwhelming amounts of spam/attacks from an irresponsible network that's an acceptable loss to most people in our civilized culture. 1. It's way more than 0.001%. Like, several orders of magnitude more. 2. What overwhelming amounts of spam/attacks? Those of us using traditional mail system…

> [citation needed]

Nearly 85% of all emails are spam. source: https://dataprot.net/statistics/spam-statistics/

At times that number has been even higher with over 90% of all messages sent over the internet being spam. If 90% of all the messages in your inbox were spam how long would you continue to use it? Email systems can't bear the costs that spam forces on them. Even with tools like blacklisting which you think shouldn't exist that cost is measured in tens of billions annually. source: https://www.aeaweb.org/articles?id=10.1257/jep.26.3.87

If not for the ability to filter common sources of spam, email would never have survived as a viable means of communication.

> It's way more than 0.001%. Like, several orders of magnitude more.

Whatever the actual number, it's clearly acceptable to us because blocking irresponsible networks is standard practice. We depend on it.

> What overwhelming amounts of spa

Again, 80-90% of all mail is spam, costing billions. If you're able to run a mail system without blacklists that's great for you, but it clearly doesn't work for everyone.

> You don't get to decide what's acceptable to everyone else.

That's the beauty of the internet. I don't have the power to force an abusive network to do their job and prevent spam from leaving their network and that abusive network can't force me to accept mail from them. No one can force anyone to do anything. All we have is a loose set of standards and expectations and it's up to each network to decide what to accept or not based on how well those standards and expectations are followed.

> Any ISP that accepts significant numbers of customers will occasionally have a customer who is either malicious or operating with imperfect security allowing someone else who is malicious to exploit them.

A responsible ISP identifies those users and prevents them continuing to cause problems. If they refuse to do that their reputation suffers and they will get blocked. If they do their job too slowly or too poorly they will be blocked. Is it possible for a responsible ISP to end up on blacklists? Yes, it is, and there are blacklists that don't maintain their lists well. That's fine too because no one is forced to use them. It's still the case that every network has the choice of what blacklists they will or won't use and how they use them. They can whitelist blacklisted IPs they decide to trust and they can use blacklists to greylist instead of block.

> The kind of policy you advocate punishes small ISPs just for being ISPs

Nope. Even small very ISPs can staff their internet abuse departments adequately and implement anti-spam technologies to prevent their IP space from becoming a safe haven for hackers and spammers. If they choose not to do that they will and should be blocked.

> I invite you to apply the same policy fairly and neutrally to larger organisations such as the major mail forwarding services and cloud hosts as well and see how long you survive in this industry.

I'll agree that there are problems when certain services (either cloud providers or mail providers like Gmail) become "too big to blacklist". We've had that problem with AOL and we have it now with Google. Personally, I'd prefer to hold them to the same standards as everyone else, but the problem of the largest players throwing their weight around giving them unfair advantages exists in every industry and until someone comes up with a solution for it, we're all just stuck playing along.

> Block actual spam sources

If your ISP is a safe haven for spammers and hackers their IP space is the spam source.

> provide a reasonable method for removing blocks that are no longer necessary.

So your alternative to blacklists is just more blacklists that are run better? I think everyone who depends on blacklists would like those blacklists to be better at detecting spam sources and better at clearing unnecessary listings. The good news is that badly run blacklists don't tend to get widely adopted because they cause more trouble for ISPs than they are worth.

If some network won't accept your mail and you're convinced that your ISP is acting responsibility and that it's the blacklist that's wrong, you can have the person you're trying to reach contact their ISP to get your mail server whitelisted. If an ISP sees that a blacklist they use is catching too many messages that it shouldn't they'll adjust their thresholds or stop using that list.

It's not a perfect system, but it's the best one we have.

Re: Spam blacklisting is out of control

#392

Earlier quoted context omitted.

When your act is choosing and giving money to a host that supports and enables spammers and attackers yes, your are responsible for that. Blacklists can be outsourced, but many ISPs maintain their own internal blacklists as well. ISPs can also subscribe to a 3rd party blacklist, but still whitelist specific blacklisted IPs they know aren't going to cause them problems. There are plenty of blacklists that ISPs choose…

You missed my point. I don't want my network to censor traffic. It is email traffic today, it could be web traffic tomorrow. If this trend holds, we would all live in walled gardens, and cede our power to the gate keepers.

Preventing spammers and hackers from using your network isn't censorship though. If you want people to let you into their homes, you have to make sure you don't keep lighting fires and smashing up their furniture.

Internet censorship is a real issue, but blocking hackers and spammers are not an example of internet censorship gone wrong. ISPs black spam over email. They block malicious web traffic too. Every network gets to decide what to accept or reject. It's about as fair a system as you could ask for.

Re: Spam blacklisting is out of control

#393

Earlier quoted context omitted.

You don't even need to threaten. Just a letter of representation from a lawyer is magically effective for things like this. ETA: We refer to it as "6mins and a stamp".

Hmm. If lawyer isn't a protected title in my home country, I wonder if it's possible for anyone to take a template and refer to themselves as a lawyer with an email to legal. I suspect they'd see through it, but it might convince someone in some cases?

That's not smart for a number of reasons. But why not just give the template to legal and let them do their job?

Or just write and snail-mail a letter from yourself. People respond surprisingly well to requests and offers in a personal/non-bulk letters.

Re: Spam blacklisting is out of control

#394

Earlier quoted context omitted.

It's how the internet stays functional. [citation needed] If 0.001% of legitimate mail has to go undelivered in order to prevent overwhelming amounts of spam/attacks from an irresponsible network that's an acceptable loss to most people in our civilized culture. 1. It's way more than 0.001%. Like, several orders of magnitude more. 2. What overwhelming amounts of spam/attacks? Those of us using traditional mail system…

> [citation needed] Nearly 85% of all emails are spam. source: https://dataprot.net/statistics/spam-statistics/ At times that number has been even higher with over 90% of all messages sent over the internet being spam. If 90% of all the messages in your inbox were spam how long would you continue to use it? Email systems can't bear the costs that spam forces on them. Even with tools like blacklisting which you think…

https://dataprot.net/statistics/spam-statistics/

Did you actually read that, and the sources it cites, before posting it? If you had you might have noticed that it's full of the worst kind of junk stats. Several of the sources cited, the ones that supposedly support your arguments here, don't even say what the piece you linked claims. They literally have completely different numbers. Not that it matters since there is no indication of methodology used and the exact figures are clearly impossible for anyone to measure accurately. Some of the other "sources" are just links to organisation home pages without identifying any specific research or analysis at all.

If 90% of all the messages in your inbox were spam how long would you continue to use it?

As someone old enough to remember the time when that was actually the case, obviously we managed. But this is distorting the argument again because you are implying a false dichotomy where the alternative to overly aggressive blacklisting policies such as you advocate is all of the spam reaching our inboxes. Clearly that is not realistic as less aggressive defences are still highly effective and have consistently been so for a long time.

No one can force anyone to do anything.

Really? Then where can I sign up for a mail service that will reliably deliver both my incoming and outgoing legitimate messages without undue monitoring or interference with my own business? I contend that possibly no such service currently exists.

Personally, I'd prefer to hold them to the same standards as everyone else, but the problem of the largest players throwing their weight around giving them unfair advantages exists in every industry and until someone comes up with a solution for it, we're all just stuck playing along.

Which is exactly why some of us are in favour of statutory regulation to compel anyone participating in such an important technological ecosystem to be a good citizen.

So your alternative to blacklists is just more blacklists that are run better?

I don't believe I have ever suggested anywhere in this discussion that using blacklists to block traffic from proven spam sources was unfair or inappropriate. My objection, which seems to be in line with the submitted article, is to big mail services that think spraying fire into a crowd of 250 indefinitely because there was once one bad person there is a reasonable response to the problem. There is huge collateral damage being caused and the defenders of this policy are trying to sweep it under the carpet and use highly debatable arguments of necessity to justify their damaging policies.

This is not the best system we have. That's the point being made here.

Re: Spam blacklisting is out of control

#395
post #164

Earlier quoted context omitted.

Transactional email from a backup service you deliberately signed up to isn’t spam, so congratulations you’ve got what you’re after. Now someone will likely reply shifting the definition of what “spam” is to include Rsync’s critical service emails, and now the term spam is so wide as to be meaningless. At that point it’s on you to manage your own spam filter if you truly feel “your critical backup service is down” is…

I did not solicit emails from that service. I solicited them to store my data. Did you solicit every nag and advert Amazon sends you? That you bought something from someone does not mean your email inbox is now free game.

Fine then. Filter them client side. That’s your choice, don’t make the choice for others.

Re: Spam blacklisting is out of control

#396
post #372
post #227

Earlier quoted context omitted.

This actually does cause problems with blocked password resets and things

If I request a password reset, that constitutes an approval to send me that email.

Some systems might just block all outgoing emails to anyone who has clicked unsubscribe which would block password resets as well

Re: Spam blacklisting is out of control

#397
post #289

Earlier quoted context omitted.

Great response, and I was just wondering what went into sending email. One question though, what do you mean by 'traps'? I feel like I'm missing some interesting context

Traps = Spam Traps. One of the ways most blocklists work is by employing spam traps which can either be individual email addresses or entire domains. It's quite a large topic, but I'll try and summarise for you. You can't just take a spam trap and use it to block anything that hits it - that would be incredibly unfair as you might not know the history of the email address or domain and you'd generate considerable fal…

That was phenomenal, thank you!

Re: Spam blacklisting is out of control

#398
post #146

Earlier quoted context omitted.

>Get your legal department involved. We have repeatedly been taken off various public and private blacklists by having lawyers do their job. What's the particular law that makes those curators of blacklists pay attention to your company's lawyers? Do you have example text of those legal requests?

It's not a law, it's who handles the request. There's two types of employees in any company with very different KPIs. The first has their performance measured in number of tickets closed. The second has their performance measured in number of incidents allowed. Support tickets get handled by the first type of employee, anything that's plausibly a legal threat gets handled by the second. The easiest way to close a tic…

This is brilliant logic. It considers all parties involved and what they want.

Re: Spam blacklisting is out of control

#399

Earlier quoted context omitted.

> [citation needed] Nearly 85% of all emails are spam. source: https://dataprot.net/statistics/spam-statistics/ At times that number has been even higher with over 90% of all messages sent over the internet being spam. If 90% of all the messages in your inbox were spam how long would you continue to use it? Email systems can't bear the costs that spam forces on them. Even with tools like blacklisting which you think…

https://dataprot.net/statistics/spam-statistics/ Did you actually read that, and the sources it cites, before posting it? If you had you might have noticed that it's full of the worst kind of junk stats. Several of the sources cited, the ones that supposedly support your arguments here, don't even say what the piece you linked claims. They literally have completely different numbers. Not that it matters since there i…

> As someone old enough to remember the time when that was actually the case, obviously we managed.

I'm also old enough to remember that and we managed by blocking huge amounts of IP space. Even massively popular services like AOL have blocked the IP space of entire ISPs or entire countries from being able to send them email. Eventually spam filtering improved, things like SMTP auth, DKIM etc caught on and wide range blocking could be scaled back somewhat, but I doubt it will ever go away entirely.

> Really? Then where can I sign up for a mail service that will reliably deliver both my incoming and outgoing legitimate messages without undue monitoring or interference with my own business?

Use your own servers and you can do whatever you want. Again, you can't force others to accept email from your mail servers, but you can choose to accept or reject whatever you want from others. No one can stop you from sending mail from one mail server you own to another mail server you own.

> Which is exactly why some of us are in favour of statutory regulation to compel anyone participating in such an important technological ecosystem to be a good citizen.

You can't really regulate the internet. If you could enforce regulations on a global network made up of discrete but interconnected networks we could just make spam, phishing, and hacking illegal on the internet, enforce that law/regulation and there would be zero need for blacklists. Because laws and regulations don't work on the internet we instead have to come up with blacklists, filtering technology, and other tricks to keep the internet even semi-functional.

> My objection, which seems to be in line with the submitted article, is to big mail services that think spraying fire into a crowd of 250 indefinitely because there was once one bad person there is a reasonable response to the problem

It's the only one that works. I've seen with my own eyes ISPs who didn't care enough to invest at all in abuse handling, but were forced to because of being blacklisted and in order to keep their customers they had to clean up their network, pay attention to abuse notices, participate in feedback loops, and slowly rebuild and maintain their reputation as responsible network operators.

If you limit blocks to individual IP addresses than spammers just cycle IP addresses. ISPs that ignore anything sent to their abuse@ address (if they even have one) never have any pressure to invest in preventing spam and can just keep accepting money from spammers and hackers and give them new IPs whenever they need to.

IPv6 makes the problem much much worse since a single spammer would get a huge amount of IPs to burn through before they have to bother their ISP about it. Blacklists themselves could become so massive and cumbersome that restricting larger and larger ranges may be the only option.

Re: Spam blacklisting is out of control

#400

Earlier quoted context omitted.

The rationale for involving legal is to place some accountability and consequences where they belong. Currently, countless people essentially commit countless abuses for free because the actor is hidden behind a machine or a process. But somewhere it's a humans decision to institute an abusive protocol, and it seems pretty fair fo me to make that human accountable for their action. Not just email but all kinds of thi…

> I say you should be legally culpable for any failure to deliver. So you think an MSP's advertised policy should be "We guarantee that anything sent to you will be delivered, including spam"? That no MSP should provide spam-filtering, at risk of legal culpability? If that's not what you mean, then presumably you are requiring all MSPs to block only spam, and to deliver all legitimate email. But that is impossible, b…

The MSP's policy can be whatever they want as long as it IS advertised.

If they say "We drop 10% of messages at random, and you knowingly choose to take that, then that is just a stupid arrangement you should never agree to, but they aren't doing something unexpected.

I decline to believe you are as stupid as that remark.

Good faith best effort is perfectly reasonable. Not knowingly and intentionaly discarding mail is all that's required.

If you're the mailman, you do not have to garantee that you will never lose a single letter in a car accident.

But you can certainly garantee, absolutely, that you never go through the bag and throw away all the spam and sometimes mistake a legit letter from a lawyer for lawyer spam.

You can ceetainly garantee, absolutely, that you never apply utterly thoughtless rules like "we got these scam letters from Nigeria so now we just throw away anything from Nigeria."

You should absolutely be responsible for other peoples stuff that is in your hands while it is in your hands. It's not yours to dispose of, even when part of your explicit job is to filter. If that sounds onerous, that's why you get paid money for the responsibility. If it's too hard to bear this responsibility properly, then you have no business doing that job. Do the job right or don't do the job. There is nothing unreasonable about those two choices. It is not at all required to do the job, but poorly or carelessly.

Post reply on HN