Live data from Hacker News

Spammers are better at SPF, DKIM, and DMARC than everyone else

toad.social

221–230 of 261 posts

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#221
post #218

Earlier quoted context omitted.

As a generalist admin, would you say the same about DBA operations or would you say that's just not my specialty? The reasoning you provide doesn't differentiate, and speaks more of frustration which naturally comes with any area you aren't steeped in, or knowledgeable about.

Frustration doesn't come naturally. It comes with shitty software design. "I don't know" is not a problem, you learn and you know, no frustration. The problem is "I spent N hours/days on a thing that everyone does and which is a 99.99% of use cases and boils down to just having a keyfile in a proper(?) location and this knowledge doesn't translate effing nowhere". would you say the same about DBA operations or would…

You are mistaken. Your reasoning is flawed because the heuristics you use are flawed, and the consequences of the heuristics are the reason you are frustrated.

There are critical tools that you clearly have not learned, and likely were never taught. Tools that have been around since the time of the Greeks.

This is evident in your use of poorly defined language running you indirectly in a circular path (trauma/torture loop).

There is irreducible complexity in software. Domain knowledge is needed to use complex software for purpose.

The script you say makes assumptive choices for you. What will you do now that RSA has practically become broken at small key sizes, and instead you need to use a different algorithm?

Do you know how to transition this without starting from scratch, or have you become corrupted by dependency, on someone who provided that for you that did have that knowledge? Are you helpless to do anything but wait.

If you want to correct the underlying reason for your troubles, I'd suggest going over the associated material covered in a Trivium based curricula.

It will require unlearning bad heuristics and re-learning good heuristics. It requires a lot of effort and constant attention until you've got your thought processes fixed and these provide the basics for rational thought.

You should have been taught these things in school.

Logic (Aristotle), Philosophy (metaphysical objectivity, identity and its requirements), Argumentation, Descartes Method, and Kant with regards to A priori knowledge, reasoning, and argumentation.

Small things with an outsized bigger impact.

If you can't understand what is written in the whitepapers, you have no hope of following the conformant requirements.

Software reduces to practice the requirements of business logic, which is described in those whitepapers.

Sometimes its irreducible, and you have to approximate, and they won't hand this ready-made to people that aren't willing to put the time cost and professional skill needed to do so correctly.

You have to offer tribute, in the form of expertise, and time to benefit from these systems. As you have to do for any other specialized career.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#223

Earlier quoted context omitted.

Criminals yes, criminal spammers no. If they could make money with other crime there would be no point in wasting their time with sending spam.

The point to sending the spam is to enable further crime. Do you really think they don't stand to profit from what they promote? Spam is a business like any other, they aren't going to magically disappear just because their advertising costs suddenly become non-zero. Just like how they found ways of shifting the costs of hosting mail servers onto others, they will find ways of shifting the costs of any "email postage…

This is very basic mathematics. If they have to do other crime to get their hands on the cash it would cost for them to spam, then why spam at all instead of only focusing on the other, more profitable crime?

Spam by definition is mass messaging. If the price per message is higher than the expected return per message, it becomes pointless.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#224
post #117
post #71

Earlier quoted context omitted.

The goal of sales isn't to block upto a 1/3 of world wide traffic. Turning off Cloudfare means more traffic and more sales are not blocked. Did you even read the article or did you dismiss it because it came from 'sales'.

Sales: "look, I turned this off and sales went way up" Security: "We had to cancel every single one of those sales because they came from stolen credit cards. It's costing us more to deal with that then we are earning"

Accounting: "We're measuring a pretty big loss because security cancelled legitimate purchases together with fake ones and now clients are leaving."

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#225

Earlier quoted context omitted.

I'm the CTO of a US-based insurance company. Apart from some reinsurers in London and Bermuda, and a couple contractors in Canada, we don't do business outside the US. We've blocked all countries except those, and it has cut down massively on the folks attacking us.

Have you considered the additional cost of making it harder for your customers to do business with you, as well as the limited visibility that you set up for attacks that may become multi-stage in nature later? You never see or collect the information by blocking everything at the outset. In a world where you can proxy past these blocks fairly trivially, that's information you don't have for attribution later. Defens…

As someone who has whitelisted only US IP address space for my employer and blocked everything else I can attest that is DRASTICALLY reduces hostile traffic to us. I have an RDP honeypot that was blocking dozens of IPs every day before the whitelist and now it blocks 1 or 2 a day.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#226

Earlier quoted context omitted.

Ive got a server hosting a number of things, amd monitoring setup for a lot of stats. Got tired of seeing blips because various countries were beating on my server, not a DoS, but enough requests to notice, and sometimes generate an alert. I blocked 7 countries, in full, and the impact was fantastic. No more 2gb of logs generated every day by countries that have no business accessing my server. Unless you own a globa…

> I blocked 7 countries Russia, China, Nigeria, Romania, North Korea, Iran and Belarus [1]? [1] https://www.ox.ac.uk/news/2024-04-10-world-first-cybercrime-...

Romania!? I did a double-take, as it is a member of the European Union. I would think if their cyber-reputation was so terrible, there would be pressure from inside the EU to fix it.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#227

Earlier quoted context omitted.

But there are big problems with mapping from IPs to countries. My IPv6 is detected as Russian, though it is London-located tunnel exit point and I'm in the Netherlands.

Sounds like an issue with an outdated locally hosted IP2 Location database.

Sounds more like IP isn't a reliable factor to determine location. Not that this would be bad though.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#228

Earlier quoted context omitted.

The problems I noticed were, it doesn't matter what the SPF and DKIM look like. If Google or Microsoft refuse to relay your email based on secret internal factors then you're out of business.

Microsoft seems to be the most common culprit.

Agree.

I don’t understand why Microsoft are so bad at this?

They have access to a large percentage of all email traffic to train domain reputation, and spam detection models on yet seem to be notorious for both false positives and false negatives.

Google’s spam filters are far more accurate.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#229

Earlier quoted context omitted.

The problems I noticed were, it doesn't matter what the SPF and DKIM look like. If Google or Microsoft refuse to relay your email based on secret internal factors then you're out of business.

Best, and often practically only, way to avoid this problem is to buy your email services from Google Microsoft duopoly.

It wouldn't shock me if an email services monopoly/duopoly would prefer email spam's only workaround to be signing up for their services, instead of fixing the root of the spam problem.

Re: Spammers are better at SPF, DKIM, and DMARC than everyone else

#230

Earlier quoted context omitted.

> I blocked 7 countries Russia, China, Nigeria, Romania, North Korea, Iran and Belarus [1]? [1] https://www.ox.ac.uk/news/2024-04-10-world-first-cybercrime-...

Romania!? I did a double-take, as it is a member of the European Union. I would think if their cyber-reputation was so terrible, there would be pressure from inside the EU to fix it.

They’re a small economy with lots of hostile traffic, so while in the EU and not sanctioned like the rest of the bunch, I’ve commonly seen them on the chopping block.
Post reply on HN