Language Selection

English French German Italian Portuguese Spanish

Battle Against Spam Shifts to Containment

Filed under

There's a new strategy in the spam battle: Call it containment. Filters for blocking junk e-mail from inboxes have improved to the point that doing much more will needlessly kill legitimate e-mail, said Carl Hutzler, America Online Inc.'s anti-spam coordinator. So e-mail gatekeepers are shifting gears.

Now they're getting more aggressive at keeping spam from leaving their systems in the first place.

EarthLink Inc., for instance, is phasing in a requirement that customers' mail programs submit passwords before it will send out their e-mail.

Like most Internet providers, EarthLink previously made sure only that a computer was associated with a legitimate account. Now that viruses can co-opt computers and use them to send spam, that's no longer secure enough.

So Earthlink sent out new software, made automated tools available for download and walked customers through manually changing their mail settings when they called tech support for other reasons. A year into the initiative, EarthLink has 80 percent of its customers converted.

"Any action can be a little daunting when you're trying to migrate millions of people," said Stephen Currie, EarthLink's director of communications products.

It also costs time and money - not insignificant considering that direct benefits don't necessarily go to EarthLink but to its competitors, whose customers might otherwise receive more spam.

But more than altruism was involved.

"If there's a lot of spam or abusive mail coming from a particular network, in the future you're going to see that e-mail having low rates of deliverability," Currie said.

In other words, other Internet service providers, or ISPs, might start blocking EarthLink e-mail if it doesn't adopt the outbound controls.

The pressure to improve outbound controls comes as viruses infect more and more home computers and convert them into spam-relayng "zombies."

These zombies allow spammers to pose as legitimate customers and get around blocks that Internet providers might have had in place.

Although antispam advocates say Internet providers can do more to stop spammers from signing up for accounts - sometimes fraudulently, but too often because they mean revenues and sales commissions - Hutzler blames zombies for 90 percent of the spam problem.

Traditional spam controls, the inbound filters, don't work as well with zombies because they can block mail from legitimate customers, too. Outbound controls can target specific zombies.

"The best place to stop spam is before it's sent," said John Reid, a volunteer with The Spamhaus Project anti-spam group. "If you can keep it in the bag, bottled up, that's where it's the least expensive."

Outbound controls aren't entirely new.

For years, anti-spam advocates have been pressuring Internet providers to configure mail servers so spammers can't use them to relay junk e-mail. The leading vendor of mail server software, Sendmail Inc., closed such relays by default in 1998, and most ISPs now have the newer software.

EarthLink and AOL also have long implemented a technique that forces customers to route e-mail through the providers' own mail servers, instead of sending messages directly to the Internet.

Other ISPs are starting to adopt it as well, giving them the ability to monitor outgoing mail, trace any problems to specific accounts and even block or place speed limits on e-mail that exceeds some hourly or daily threshold.

ISPs can also run the spam and virus filters on outbound mail.

And when users of Microsoft Corp.'s Hotmail try to send a large number of messages, they are prompted to type in random letters displayed on the screen. Presumably, spammers with automated tools wouldn't be able to do it.

If all ISPs were to implement outbound controls, spam wouldn't be such a headache.

But outbound measures are often difficult to justify because they don't directly pare down the junk in customers' inboxes as inbound filters do, said Anne Mitchell, who runs the Institute for Spam and Internet Public Policy, an antispam consultancy.

Mitchell said ISPs are businesses and "have to look at the bottom line and their profitability."

Besides implementation costs, outbound measures can hurt legitimate customers.

Businesses and some individuals might have a legitimate need to access third-party mail servers, and being forced to go through their providers' systems might cause their e-mail to be mistakenly tagged as spam by the recipient.

Anytime ISPs make changes, they will invariably discover a few customers who use their service in an unanticipated, but legitimate manner, said John Levine, co-author of "Fighting Spam for Dummies."

Martin Deen, manager of messaging engineering at Cox Communications Inc., likens outbound measures to vaccination. They may be good for the overall health of the Internet if all ISPs do it, Deen said, but individual ISPs take a personal risk.
ISPs sometimes grant exceptions for businesses and power users.

AOL has a few thousand customers, out of more than 28 million, who are exempt from caps on multiple mails.

Desert Express Internet Services, a small ISP serving California and Nevada, waived its restrictions for one of its business customers - but only if it agreed in writing to run spam filters on outgoing mail and meet other requirements.

Ultimately, ISPs may require customers with special needs to buy a premium service.

"We don't do that, (but) that would be a possibility certainly," EarthLink's Currie said. "EarthLink and other ISPs are just going to define their services, and certain things will be permitted and certain won't."

By ANICK JESDANUN, AP Internet Writer

More in Tux Machines

Leftovers: KDE


  • 4 Useful Cinnamon Desktop Applets
    The Cinnamon desktop environment is incredibly popular, and for good reason. Out of the box it offers a clean, fast and well configured desktop experience. But that doesn’t mean that you can’t make it a little better with a few nifty extras. And that’s where Cinnamon Applets come in. Like Unity’s Indicator Applets and GNOME Extensions, Cinnamon Applets let you add additional functionality to your desktop quickly and easily.
  • GNOME Core Apps Hackfest
    The hackfest is aimed to raise the standard of the overall core experience in GNOME, this includes the core apps like Documents, Files, Music, Photos and Videos, etc. In particular, we want to identify missing features and sore points that needs to be addressed and the interaction between apps and the desktop. Making the core apps push beyond the limits of the framework and making them excellent will not only be helpful for the GNOME desktop experience, but also for 3rd party apps, where we will implement what they are missing and also serve as an example of what an app could be.
  • This Week in GTK+ – 21
    In this last week, the master branch of GTK+ has seen 335 commits, with 13631 lines added and 37699 lines removed.

Leftovers: OSS and Sharing

  • Puppet Unveils New Docker Build and Phased Deployments
    Puppet released a number of announcements today including the availability of Puppet Docker Image Build and a new version of Puppet Enterprise, which features phased deployments and situational awareness. In April, Puppet began helping people deploy and manage things like Docker, Kubernetes, Mesosphere, and CoreOS. Now the shift is helping people manage the services that are running on top of those environments.
  • 9 reasons not to install Nagios in your company
  • Top 5 Reasons to Love Kubernetes
    At LinuxCon Europe in Berlin I gave a talk about Kubernetes titled "Why I love Kubernetes? Top 10 reasons." The response was great, and several folks asked me to write a blog about it. So here it is, with the first five reasons in this article and the others to follow. As a quick introduction, Kubernetes is "an open-source system for automating deployment, scaling and management of containerized applications" often referred to as a container orchestrator.
  • Website-blocking attack used open-source software
    Mirai gained notoriety after the Krebs attack because of the bandwidth it was able to generate — a record at well over 600 gigabits a second, enough to send the English text of Wikipedia three times in two seconds. Two weeks later, the source code for Mirai was posted online for free.
  • Alibaba’s Blockchain Email Repository Gains Technology from Chinese Open Source Startup
    Onchain, an open-source blockchain based in Shanghai, will provide technology for Alibaba’s first blockchain supported email evidence repository. Onchain allows fast re-constructions for public, permissioned (consortium) or private blockchains and will eventually enable interoperability among these modes. Its consortium chain product, the Law Chain, will provide technology for Ali Cloud, Alibaba’s computing branch. Ali Cloud has integrated Onchain’s Antshares blockchain technology to provide an enterprise-grade email repository. Onchain provides the bottom-layer framework for Ali Cloud, including its open-source blockchain capabilities, to enable any company to customize its own enterprise-level blockchain.
  • Netflix on Firefox for Linux
    If you're a Firefox user and you're a little fed up with going to Google Chrome every time in order to watch Netflix on your Linux machine, the good news is since Firefox 49 landed, HTML5 DRM (through the Google Widevine CDM (Content Decryption Manager) plugin) is now supported. Services that use DRM for HTML5 media should now just work, such as Amazon Prime Video. Unfortunately, the Netflix crew haven't 'flicked a switch' yet behind the scenes for Firefox on Linux, meaning if you run Netflix in the Mozilla browser at the moment, you'll likely just come across the old Silverlight error page. But there is a workaround. For some reason, Netflix still expects Silverlight when it detects the user is running Firefox, despite the fact that the latest Firefox builds for Linux now support the HTML5 DRM plugin.
  • IBM Power Systems solution for EnterpriseDB Postgres Advanced Server
    The primary focus of this article is on the use, configuration, and optimization of PostgreSQL and EnterpriseDB Postgres Advanced Server running on the IBM® Power Systems™ servers featuring the new IBM POWER8® processor technology. Note: The Red Hat Enterprise Linux (RHEL) 7.2 operating system was used. The scope of this article is to provide information on how to build and set up of PostgreSQL database from open source and also install and configure EnterpriseDB Postgres Advanced Server on an IBM Power® server for better use. EnterpriseDB Postgres Advanced Server on IBM Power Systems running Linux® is based on the open source database, PostgreSQL, and is capable of handling a wide variety of high-transaction and heavy-reporting workloads.
  • Valgrind 3.12 Released With More Improvements For Memory Debugging/Checking
  • [Valgrind] Release 3.12.0 (20 October 2016)
  • Chain Launches Open Source Developer Platform [Ed: If it’s openwashing, then no doubt Microsoft is involved]
  • LLVM Still Looking At Migration To GitHub
    For the past number of months the LLVM project has been considering a move from their SVN-based development process to Git with a focus on GitHub. That effort continues moving forward.
  • Lumina Desktop 1.1 Released With File Manager Improvements
    Lumina is a lightweight Qt-based desktop environment for BSD and Linux. We show you what's new in its latest release, and how you can install it on Ubuntu.
  • Study: Administrations unaware of IT vendor lock-in
    Public policy makers in Sweden have limited insight on how IT project can lead to IT vendor lock-in, a study conducted for the Swedish Competition Authority shows. “An overwhelming majority of the IT projects conducted by schools and public sector organisations refer to specific software without considering lock-in and different possible negative consequences”, the authors conclude.
  • How open access content helps fuel growth in Indian-language Wikipedias
    Mobile Internet connectivity is growing rapidly in rural India, and because most Internet users are more comfortable in their native languages, websites producing content in Indian languages are going to drive this growth. In a country like India in which only a handful of journals are available in Indian languages, open access to research and educational resources is hugely important for populating content for the various Indian language Wikipedias.
  • Where to find the world's best programmers
    One source of data about programmers' skills is HackerRank, a company that poses programming challenges to a community of more than a million coders and also offers recruitment services to businesses. Using information about how successful coders from different countries are at solving problems across a wide range of domains (such as "algorithms" or "data structures" or specific languages such as C++ or Java), HackerRank's data suggests that, overall, the best developers come from China, followed closely by Russia. Alarmingly, and perhaps unexpectedly, the United States comes in at 28th place.

OSS in the Back End

  • AtScale Delivers Findings on BI-Plus-Hadoop
    Business intelligence is the dominant use-case for IT organizations implementing Hadoop, according to a report from the folks at AtScale. The benchmark study also shows which tools in the Haddop ecosystem are best for particular types of BI queries. As we've reported before, tools that demystify and function as useful front-ends and connectors for the open source Hadoop project are much in demand. AtScale, billed as “the first company to allow business users to do business intelligence on Hadoop,” focused its study on the strengths and weaknesses of the industry’s most popular analytical engines for Hadoop – Impala, SparkSQL, Hive and Presto.
  • Study Says OpenStack at Scale Can Produce Surprising Savings
    Revenues from OpenStack-based businesses are poised to grow by 35 percent a year to more than $5 billion by 2020, according to analysts at 451 Research. In its latest Cloud Price Index, 451 Research analyzes the costs associated with using various cloud options to determine when it becomes better value to use a self-managed private cloud instead of public or managed cloud services. The idea is to createa complex pricing model that takes into consideration the major factors impacting total cost of ownership (TCO), including salaries and workload requirements.The 451 study found that because of the prevalence of suitably qualified administrators, commercial private cloud offerings such as VMware and Microsoft currently offer a lower TCO when labor efficiency is below 400 virtual machines managed per engineer. But where labor efficiency is greater than this, OpenStack becomes more financially attractive. In fact, past this tipping point, all private cloud options are cheaper than both public cloud and managed private cloud options.
  • How OpenStack mentoring breaks down cultural barriers
    Victoria Martinez de la Cruz is no stranger to OpenStack's mentorship opportunities. It's how she got her own start in OpenStack, and now a few years later is helping to coordinate many of these opportunities herself. She is speaking on a panel on mentoring and internships later this week at OpenStack Summit in Barcelona, Spain. In this interview, we catch up with Victoria to learn more about the details of what it's like to be a part of an open source internship, as well as some helpful advice for people on both sides of the mentoring process.