Live data from Hacker News

Spam blacklisting is out of control

blog.roastidio.us

411–420 of 430 posts

Re: Spam blacklisting is out of control

#411

Earlier quoted context omitted.

> The thing is, if you own a good IP in a mixed block with some bad ones, that's no reason for you to be blacklisted. It's pure laziness. It's not laziness; the intention of collateral blocklisting, as with UCEPROTECT L2 and L3, is punitive. It's to incentivize the sending MSP to remove their spammer (or move them to address-space where they can be blocked without causing collateral damage).

It's not laziness; the intention of collateral blocklisting, as with UCEPROTECT L2 and L3, is punitive. Unfortunately the people it punishes are the legitimate users of both systems who only wanted the system to do its job and let them communicate. The bad actors will just move on and abuse another system instead.

> who only wanted the system to do its job and let them communicate

"The system" you are referring to consists of a bunch of private networks. Your opinion about what the job of those networks is may not coincide with the opinions of the operators of those networks.

Email is not a public service, and there is no entitlement to send whatever "vital business communications" you like to anyone you want. It's not even reasonable to require a postmaster to state what their rejection policy is; that would just tell spammers what they have to do to evade your blocks.

If email doesn't work for your business, then switch to another channel, such as huge billboards or whatever. Ranting about blocklists isn't going to help, people have been doing that for two decades.

I take it you've never run a mailserver?

Re: Spam blacklisting is out of control

#412

Earlier quoted context omitted.

> I say you should be legally culpable for any failure to deliver. So you think an MSP's advertised policy should be "We guarantee that anything sent to you will be delivered, including spam"? That no MSP should provide spam-filtering, at risk of legal culpability? If that's not what you mean, then presumably you are requiring all MSPs to block only spam, and to deliver all legitimate email. But that is impossible, b…

The MSP's policy can be whatever they want as long as it IS advertised. If they say "We drop 10% of messages at random, and you knowingly choose to take that, then that is just a stupid arrangement you should never agree to, but they aren't doing something unexpected. I decline to believe you are as stupid as that remark. Good faith best effort is perfectly reasonable. Not knowingly and intentionaly discarding mail i…

> The MSP's policy can be whatever they want as long as it IS advertised.

No.

Suppose the MSP uses bayesian filtering? How would one go about advertising a policy that depends on bayesian filtering? You'd have to publish the contents of your filter table. The only people who could benefit from that would be spammers, who could use the data to customise their spam.

In general, telling the world what your filtering policies are is just going to cause spammers to try to sidestep your policies. The only policy that you maybe ought to publish would be along the lines of "We filter out spam; that sometimes results in false positives. Sorry."

Re: Spam blacklisting is out of control

#413

Earlier quoted context omitted.

You missed my point. I don't want my network to censor traffic. It is email traffic today, it could be web traffic tomorrow. If this trend holds, we would all live in walled gardens, and cede our power to the gate keepers.

Preventing spammers and hackers from using your network isn't censorship though. If you want people to let you into their homes, you have to make sure you don't keep lighting fires and smashing up their furniture. Internet censorship is a real issue, but blocking hackers and spammers are not an example of internet censorship gone wrong. ISPs black spam over email. They block malicious web traffic too. Every network g…

> If you want people to let you into their homes, you have to make sure you don't keep lighting fires and smashing up their furniture.

You analogy is flawed. In the case of IP blacklisting, it is an intermediary preventing legitimate email delivery on shaky ground. My correspondent want the mail; yet she never got to see it. This is censorship.

Re: Spam blacklisting is out of control

#415
UCEPROTECT-2 and 3 aren't blocklists, they're reputation lists. Anyone straight blocking off those lists has most likely misconfigured their filtering and should expect to be missing mails.

NOTE: By using Level 2 blocking, be prepared to lose a few mails too. DO NOT BLAME US, YOU HAVE BEEN FOREWARNED! > https://www.uceprotect.net/en/index.php?m=3&s=4

Use of Level 3 for blocking is recommended only if you are a HARDLINER and you want to cause service providers and carriers that have spammer / abusive clients to be quickly and effectively blocked and it does not matter to you if regular email is also occasionally rejected. > https://www.uceprotect.net/en/index.php?m=3&s=5

This has been the subject of hot debate on one of the popular mailing list operator's lists, and the providers that find themselves in Level 2/3 reliably are working on strategies to deal with that but it becomes complicated to do anything that affects thousands of customers. You'll find the providers that aren't on these lists are the ones that have an equally strict policy for allowing outbound Port 25 from their customers and a severely punitive abuse desk.

IMO, I run a personal mail server and deliver directly and if my mail is rejected or lost then I use another mechanism to contact that person (usually telephone) and inform them of the failure. I also provide usable feedback to senders for why I may have chosen to reject their message. And when it really matters, I also have a relay I can use for troublesome transports.

Re: Spam blacklisting is out of control

#416
post #384

Earlier quoted context omitted.

You have this backward, as well, because that's not how any of this works. The UCEPROTECT list is a literal text file that gets ingested by the mail provider. The provider is under zero obligation to use the entirety of the list and, in fact, is still 100% responsible for maintaining their own list in a way that complies with international laws, ICANN rules, service agreements, etc. UCEPROTECT even offers a very blat…

> The UCEPROTECT list is a literal text file that gets ingested by the mail provider. I don't know whether that is true; but I do know that it is usually used as a DNSBL - a DNS lookup for an IP address, that answers whether that address is or is not in the list. In general, mail providers do not "ingest" entire blocklists. > responsible for maintaining their own list in a way that complies with international laws [e…

> In general, mail providers do not "ingest" entire blocklists.

Completely false. They ingest lists[1] into their own local daemon. There is not a major mail provider on the planet who is querying a third party DNSBL every time an email comes in. It's also more than a little ridiculous that you admitted to not knowing if something were true, but then decided to confidently (and incorrectly) explain it anyway, rather than taking ten seconds to look it up.

> Actually, anyone can publish a list of anything; unless that publication amounts to a contract (statement of purpose, assertion of fitness for purpose), then I'm not aware of any international "law" that says you can't put anything you like in a publicly-acccessible list.

Both wrong and irrelevant. I explained how Comcast is responsible for maintaining their own blacklist, which is NOT public, and as an ISP they are absolutely under all sorts of legal regulations, in addition to having service agreements with end users and other network providers. Yet, you responded with a "point" about how UCEPROTECT (a completely different company) is allowed to post whatever they want in a text file. Do you seriously not see the disconnect between what people are actually saying and how you interpret them? Because it's beyond frustrating.

> Have you ever read a FOSS licence? UCEPROTECT are simply stating that as a free user, you can't hold them responsible for the accuracy of their lists

Entirely irrelevant. The UCEPROTECT disclaimer is not for the end user -- it's for the ISPs. If someone sues Comcast, they're not trying to hold UCEPROTECT responsible for creating a text file, they're trying to hold Comcast responsible for acting in bad faith by not allowing reasonable recourse for removal from Comcast's copy of the text file. So, the end user in this situation is not a "free user of UCEPROTECT," but instead a paid user of a network provider with a service agreement in place.

[1] http://www.uceprotect.net/en/index.php?m=6&s=10

Re: Spam blacklisting is out of control

#417

Earlier quoted context omitted.

You must be living in a different world than me. I regularly get spam even from large corporations, that I know I never signed up for anything for. I know it is actually them, because it's DKIM signed with their domain certificates. Walmart (which doesn't exist in my country), Unilever and tons or their brands. Even a national division of Microsoft got hands on my email and decided to sign me up for invites to develo…

Apparently we do live in different worlds. May I ask what sort of email infrastructure you use? I don't think anything I use, either personally or professionally, is particularly complicated or unusual but apparently our recent experiences have been very different. Probably 95% of the spam I receive is automatically filtered to a spam folder, with a negligible false positive rate. Every now and then some new pattern…

I have a gmail account and a RoundCube thing at my own domain (managed by the domain name provider).

Gmail's spam filtering is very generous to DKIM-signed mail - it has a tendency to let it trough even if I've flagged exactly that sender before (as I did with walmart). The one on my own domain has received too little spam to tell how good the filter is.

Re: Spam blacklisting is out of control

#418

Earlier quoted context omitted.

Preventing spammers and hackers from using your network isn't censorship though. If you want people to let you into their homes, you have to make sure you don't keep lighting fires and smashing up their furniture. Internet censorship is a real issue, but blocking hackers and spammers are not an example of internet censorship gone wrong. ISPs black spam over email. They block malicious web traffic too. Every network g…

> If you want people to let you into their homes, you have to make sure you don't keep lighting fires and smashing up their furniture. You analogy is flawed. In the case of IP blacklisting, it is an intermediary preventing legitimate email delivery on shaky ground. My correspondent want the mail; yet she never got to see it. This is censorship.

> it is an intermediary preventing legitimate email delivery on shaky ground.

The 3rd party hosting the blacklist is an intermediary, but the network operator on the receiving end isn't. They still have total control over what lists to subscribe to, how they'll be used, and what to block or allow. That's not censorship. As a network operator it is there right to block or accept whatever traffic they want. If you, as a customer/end user don't like how they run their network you're free to operate your own or choose to give your money to someone else.

Re: Spam blacklisting is out of control

#419

Earlier quoted context omitted.

Can you imagine what would happen if we applied your argument to other important communications channels like postal mail or telephone calls? Sorry, someone in your old friend's city was using a robodialler so now none of the local phone service providers available to you will accept calls from anyone in that area code. We absolutely can regulate the Internet on this kind of issue. We don't have to regulate everywher…

> Can you imagine what would happen if we applied your argument to other important communications channels like postal mail or telephone calls? The only reason we don't is because unlike email, it's the sender who pays not the receiver. Telecoms do monitor and block outbound international calls if the connection times are excessive, if they occur at unusual hours, or if they going to certain "blacklisted" countries w…

Other guy sounds like a giant dick-wad - we should not be wholesale blocking IP ranges without recourse to "unblock".

Whatever the other guy thinks about it being "necessary" or whatever, there is not commonly a way for a user to whitelist a service. And services providing email dont normally take that sort of signal into account, either.

Once you are operating a large system that is used by many people, you become a public utility - furthermore, at that scale we can generally find where you live and come lock you up. This kind of thing is 100% regulatable.

Either let users choose what mail they receive, or implement regulation forcing compliance. If that doesnt happen, and you snub my lawyer like the irresponsible mega corp you probably are, guess thats one more reason for me to polish off my shotgun and takeout the dickwads running the megadoom corp.

Re: Spam blacklisting is out of control

#420

Earlier quoted context omitted.

That seems a lot of rationalisation for a situation where a genuine sender on another system sends legitimate mail to a genuine recipient on your system, that mail is not properly delivered, and it's your fault. There is a reason that collective punishment is considered immoral by civilised cultures. It hurts the innocent and often fails to achieve its original goal anyway.

> and it's your fault Or maybe your policy? > There is a reason that collective punishment is considered immoral by civilised cultures Rejecting email submissions isn't punishment, collective or otherwise. It's something you have to do if you run a mailserver. In the same way, I'm not punishing trespassers if I secure my front-door with a deadlock.

No, but if you secure a cellar with a padlock on hundreds of people, thats called kidnapping and possibly murder.
Post reply on HN