You'll find great information in this "Read Only" Archive, but remember..... things change.
Be sure to visit the Current Message Board when you're finished here.

We're very friendly, so don't be shy... just jump right in and post your question.
Scams outnumber legitimate biz ops about a bzillion to one, so it's well worth your time.

FIB - Scams 101 - Ye Olde Archives


Posted By: The Roadie <>
Sunday, 5 December 2004, at 7:54 a.m.

In Response To: Re: LOUIS VUITTON REPLICAS SPAMMER (Bill Cornelius)

> I don't get spam. The simple answer to spam is to block all email accept
> from an approved list. As far as I know most all email programs have that
> capability.

That's called "whitelisting", and it would indeed end spam if everybody adopted it as a tactic. Of course, it would put an end to many of the useful features that make email useful for on-line commerce. It would also mean that we are admitting the spammers have won by being able to make us change our behavior.

It would be as if the burglar population exploded over a five year period so that they could teleport into any neighborhood, no matter where they went home to live at night. Everyone might respond by putting bars on the doors, bars on the windows, triple locks on the garage, and nervously peeking from behind the curtains whenever the doorbell rang because they don't know if it's a friend or a burglar.

Spam is like some burglars suddenly gained the ability to teleport not just into our neighborhoods but INSIDE the house. Suddenly bars and locks wouldn't work. Some of them put on masks and appear at first to be your friends. Others leave little turds behind in your house that you have to clean up long after they teleport out.

Another spam-fighting tactic is what's called the "challenge-response" tactic where you buy or use an ISP-provided system that sends a challenge to people who contact you for the first time. If they succeed in responding to the challenge (either by clicking on a link, visiting a web site with an image to decipher, etc.) then their email will get through to you. Spammers presumably would never see the challenge because their "from" addresses are almost always forged.

Problem with C-R systems is two-fold.

1) A lot of spam, that forges the "from" address, would trigger a challenge to go back to that innocent address. Since some spamware takes the "from" address out of their list of addresses to spam, the innocent address might be getting 100-100000 challenges as a result, and their email box would collapse from the load.

2) We have seen spammers using valid "from" addresses, then paying $3-5 a day to teams of people in India and the Philippines, to reply to the challenges! Then the spam gets through to the end-victim, and then ANY future spam that uses the same "from" address also gets through. There is no depth the criminal spammers will not sink to.

Since not everybody is going to go to a whitelisting system, we have to do a few things:

Educate Aunt Tillie (and other newbies) to never ever buy anything from spammers, and to get good filters in case their sales resistance is very low.

Disconnect as many spammers as we can track, herd them into smaller and smaller places on the net that will sell them hosting (easier to filter that way), as is happening now in parts of China and Korea, and get a few good lawsuits against them to serve as a deterrent.

> Of course if you use an advertising signature or post your
> email address in hopes that a prospective buyer will contact you from it
> that sort of defeats the purpose of blocking the spam in the first place.

If you sell on-line, you pretty much need a sales or customer support address. You could also avoid spam by insisting your prospects and customers fill out a web form only, but many users are annoyed at that ploy and avoid sites that insist they fill out a form. By forcing you to not post an email address, the spammers have just cost you some percentage of your customers.

The other reason that email addresses might be useful for "first contact" situations, where you have no other way to contact someone first to get whitelisted, is what we call the "old college roommate" or "high school sweetheart" situation. Do we want the spammers to make it so that we might never hear from someone from our past that we MIGHT want to hear from?

> No, spam is at worst an annoyance.

Spam might be only an annoyance to you. Lucky guy. If you knew your ISP is spending 10% or more of your monthly fee to transmit, store, filter, bounce, and administer spam-related issues, you might be more concerned. If you knew that spam costs the world's economy tens of billions of dollars a year in terms of people's time to "just hit delete", it might begin to affect you. But only if you care about larger, more global issues than your own in-box.

Some people care about things that affect all of us in the global village.

> Spam e-mail can be defeated as I
> described above and spam forum posts can be defeated by simply requiring
> registration.

And like all simple solutions, I reply that one-size does not fit all. Some people need to be contacted by strangers. Others hate to modify their behavior and admit the spammers have won. Some folks object to wasting $30-100/year to pay their ISP to fight spam.

Your mileage may vary.

Roger Ebert's Boulder Pledge

