Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts

2008-05-03

First there was the campaign for .nyc - a totally pointless call for yet another TLD for the City of New York. We have enough TLD's already - we don't need to pollute the namespace any further with city TLD's. If .nyc or .berlin get their way, who has the right to claim .bristol? The original one in the UK? Or Bristol, TN? Or Bristol, NB? The arrogance of these cities to think that they have the right to pollute the DNS namespace with this nonsense is astounding.

Now there's a story that Spamazon is suing NY State because of a new tax law that allows NY State to force online retailers to collect sales tax at the point of sale for goods shipped to NY residents. Normally, I wouldn't support Amazon (they're on my boycott list, generically, for being email spamtards) but I have to admit that Amazon are in the right here. Only an arrogant State Legislature would pass a law requiring a business in another state to collect taxes on the State's behalf.

It's also disappointing to read that this legislation was originally proposed by former New York Governor Eliot Spitzer. I had a lot of respect for the man - even when he was caught with his trousers down - due to his stance on spammers and telescum like Xentel Inc.

Still, this doesn't score as high in the hubris stakes as Judge Charles Kocoras of the IL courts, who suffers from a superiority complex: he was the one who returned a default judgement against Spamhaus, who don't even have a presence in the US.

2008-03-09

Just reading an article about Nokia's plans to incorporate MicroShaft's SilverShite (my medial caps) onto their mobile platforms. Apparently, SilverShite can be used to develop RIA's, but then so can Flash. However, very little RIA's (of any use) are done in Flash - most of the time it's used to generate those annoying banner ads, like "Punch the Monkey" or some other such nonsense. Yet another reason to surf with FireFox with Adblock and NoScript installed.

Per the article, "Among the new functionality, RIA application developers and designers have the ability to better monetize their sites, and extend these applications to the mobile space". In other words, instead of using Flash to make ads, WebDev's can use SilverShite to push ads onto your cell phone.

It seems that everyday, some marketing droid is out to push their ads on you via cost-shifted advertising (AKA spamming). WAP surfing is expensive enough without the ads: on Primus, every 1KB of traffic costs 5¢ on pay-per-use, or the same cost per KB after you've gone over your quota if you're on a $3/month (256KB) or $7/month (1MB) data plan. It's the same rate on Rogers pay-per-use.

At $3/month (currently what I pay Primus) it won't take long to go over 256KB with sites laden with mobile ads. Perhaps they should be called "madverts".

2007-10-27

I love my VoIP service. In the bad old POTS days, we'd get 3, 4... 5 telejunk calls a day, 7 days a week, some days worse than others.

Now I can block the telespammers, my phone only rings for the occasional low-level telejunker: usually a local duct cleaner, or some 2-bit company trying to hawk windows and doors. All the toll-free numbers go straight to voicemail.

Repeat offenders get auto-forwarded to an out-of-service number. But, just as the email spammers ignore 5.5.x SMTP error messages and keep trying an email address that will never deliver, it seems the tele-spammers' autodialers ignore "number out of service" messages too:

SelectiveCallFwd   112595140000002    Unavailable 2007-10-20
SelectiveCallFwd 112595140000002 Unavailable 2007-10-27

Here are a few more parallels:

Email Spammer
Tele-Spammer
  • Ignores 5.5.x mailer messages.
  • Ignores "out-of-service" messages.
  • Plays numbers game: harasses millions of email users with unsolicited messages for one lousy sale.
  • Plays numbers game: harasses millions of phone users with unsolicited calls and voicemail messages for one lousy sale.
  • Sells "sucker lists" of email addresses.
  • Sells "sucker lists" of phone numbers.
  • Routinely forges "from" addresses.
  • Routinely forges Caller ID.
  • Uses rogue ISP’s to host their "bulletproof" websites.
  • Uses rogue SIP providers to host their VoIP systems.
  • Obfuscates messages to bypass spam filters.
  • Obfuscates Caller ID to bypass Privacy Guard.
  • Uses cost-shifted advertising to spam your mailbox.
  • Uses cost-shifted advertising to spam your cell-phone.


I'm sure there are plenty of other examples, including parallels between tele-junkers and fax spammers.

My personal favourite site for reporting telejunkers: Who Called Us.

2007-04-08

Spammers play the numbers game. They send millions of emails a day, hoping to hit at least a few marks. Any idiot that responds by doing business is pure profit for a spammer. The phrase "There's one born every minute" certainly fits there.

Since no-one wants to let go of their beloved SMTP and come up with a brand new, trust-based email protocol, the only logical step is to make CAPTCHAs an interstitial part of the SMTP handshake for unknown senders. I don't claim this to be my own idea - there's plenty of hits Googling for "CAPTCHA" and "spam". Most of the search results are for discussions on why CAPTCHAs are evil and why they should not be used for website sign-up verifications, because they apparently discriminate against blind users.

Of all the discussions and arguments put forward, there isn't one single FUSSP - only a blended defence (of technological and sociological measures) will make a significant dent in the spam problem. Anyone who tries to think differently from the net-intelligentsia, is labeled an Anti-spam Kook.

So here are the arguments and counter-arguments:

(1) Visual CAPTCHAs discriminate against the blind: yes, they do. But then, logic-test CAPTCHAs discriminate against persons with learning disabilities; natural language-based CAPTCHAs discriminate against persons who don't speak the language used in the CAPTCHA; audio-CAPTCHAs discriminate against the deaf. So, whichever CAPTCHA is used, it will inevitably impact a person with one disability or another. Just as there is no universal solution to the spam problem, there isn't one CAPTCHA that will tell a human from a computer without affecting a minority of people. Trouble is, there are so many vocal tax-payer-subsidised, minority pressure-groups out there, who'd rather tell us to eat our spam than allow one disabled person to be unintentionally excluded. Solution: make alternative contact methods available or have a person assist the user in decoding the CAPTCHA.

(2) Spammers will just hire people to decode CAPTCHAs: perhaps. But remember, spammers play the numbers game. Use this against them. When it becomes prohibitively expensive for even the biggest of spammers to hire manual decoders, the spam will stop. To send 1 million emails and hire X number of flunkies to decode even half of the CAPTCHA challenge-responses in order to reach a handful of marks would just not make it worth the cost or effort.

(3) Spammers will redirect CAPTCHA images/logic-puzzles to their own sites and have people decode the CAPTCHA in exchange for access to pr0n: perhaps. But again, it's all about the numbers. How many visitors (dynamic) could decode a CAPTCHA before it expires? Hot-linking of images is easy to disable anyway.

(4) SMTP challenge-response systems are evil and just add to the spam volume: sometimes. I believe a dynamically-generated 5xx SMTP error message with a CAPTCHA URL is an acceptable method of challenge-response. To accept a message and then reply to it with a CAPTCHA URL is not acceptable. Also, until the original unknown sender is CAPTCHA authenticated, no more 5xx messages should be sent.

It's unfortunate that it's come down to this. But let's not forget that people have been obfuscating (munging) information for a long time - even before spammers started harvesting email addresses from usenet, people used images of email addresses on their websites. Did anyone complain when a blind person couldn't privately email a usenet poster because they had munged their email address? I'm sure I would have noticed the noise from the pressure groups if that happened.

Talking of usenet, here's an extremely inciteful post* made in 2003 by a NANAE regular. I am not going to repost the contents here, as it's archived on numerous sites - just Google for "thank the spammers". Even in 2003, CAPTCHAs were being used to prevent access to WHOIS data miners.

In our zeal to bend-over-backwards to help people who are less abled than ourselves to get onto the 'net, the spammers have been exploiting that good will to pump out their spam. I'm sorry, but I'm not going to be told to eat my spam in deference to the "politically correct" pressure groups.

And anyway, spammers themselves discriminate against the blind since there's a trend to circumvent text-based spam filters by using image text in their spams. Would the pressure groups complain about that? Didn't think so.

2007-04-04

One thing that never ceases to annoy me are the flyers that street-spammers stuff into my mailbox. Unlike the email spammers (typically penis enlargement pills and other fake pharmaceuticals) and telejunkers (usually for quasi-charities, duct cleaning and windows) it seems that mailbox spam is not limited to hawking one particular thing.

Tonight, I get home from work to find a religious flyer in my mailbox. I won't mention the faith in question, because (a) it's largely irrelevant and (b) I don't wish to incite hatred by labeling one particular faith as more spammy than another.

The contents of the flyer itself are not worth commenting on - I didn't even waste any time reading it, but what is laughable is the one-liner at the top of the flyer that caught my eye: "Note: This publication uses the Holy Scriptures; discard it with the proper care". Of course I'll discard it with the proper care - it's on plain paper, so it went quite nicely straight into the recycling bin. What did they want me to do with it? Bury it? Cremate it? Mail it back?

2007-02-04

One thing that never ceases to annoy me are the flyers that spammers stuff into my mailbox. Unlike the email spammers (typically penis enlargement pills and other fake pharmaceuticals) and telejunkers (usually duct cleaning and windows) it seems that mailbox spam is not limited to hawking one particular thing.

Tonight, I get home from work to find a religious flyer in my mailbox. I won't mention the faith in question, because (a) it's largely irrelevant and (b) I don't wish to incite hatred by labeling one particular faith as more spammy than another.

The contents of the flyer itself are not worth commenting on - I didn't even waste any time reading it, but what is laughable is the one-liner at the top of the flyer that caught my eye: "Note: This publication uses the Holy Scriptures; discard it with the proper care". Of course I'll discard it with the proper care - it's on plain paper, so it went quite nicely straight into the recycling bin. What did they want me to do with it? Bury it? Cremate it? Mail it back?

2007-01-14

Warning: the external links referenced in this article will most likely generate popups - do not click on them unless you are one of these fabled people who actually like popups, or if you have a popup blocker in your browser.

Whilst Googling around today, I chanced upon an (old) news article on The Times of India.

Luckily, I am running Mozilla Firefox, which has a built-in popup blocker.

According to my browser, "Firefox prevented this site from opening 7 popup windows". That's right, SEVEN popups. Clicking on "Options" shows 7 URL's off of 4 unique domains.

This is the sort of bullshit that makes the 'Net suck. Obviously, enough people made enough noise for Microsoft to finally integrate a popup blocker in version 7 of Internet Exploiter, long after Opera and Mozilla implemented it in their browsers.

I understand that most sites (especially those that have no corresponding offline presence) need to make revenue and I have no problem with small file-size banner ads in principle. If I am interested in a banner, I'll click on it, rest assured. I will never *EVER* buy or subscribe to anything displayed in a popup.

The same idiocy is practiced by the tuckfards at experts-exchange.com. They evade popup blockers by deliberately obfuscating the JScript to launch a popup, even fooling Firefox:


<script language=javascript><!--
document.write('<scr'+'ipt language=javascript src="http://a.tribalfusion.com/j.ad?site=*removed*
&adSpace=*removed*&size=468x60&type=horiz&noAd=1&requestID=*removed*">
</scr'+'ipt>');
//-->
</script>

[note the obligatory misnomer domain name, indicative of most dotcom-only junk-monger companies these days]

Particularly ironic - given that experts-exchange is a tech resource site, they should already be enclued into how annoying popups really are.

So, webmasters, get a clue: no-one likes popups, so lose them already!