The Northern Spy: combatting spam
TweetFollow Us on Twitter

The Northern Spy: combatting spam

By Rick Sutcliffe

Spam is used either as a noun to refer to unsolicited bulk email, or as a verb to refer to the act of sending same. There are two categories of spam -- the difference depending on whether or not the mail has a commercial or monetary aspect;that is, the sender is attempting to obtain money from the recipients for a service, product, or cause.

There may or may not also be a fraudulent aspect to the spam -- generally one should expect that those who engage in one unethical activity would challenged where the truth is concerned as well. For instance, non-commercial spam is frequently sent to argue for or against some cause, and may be abusive of the recipient, or of some identifiable group or organization to which the recipient may be supposed to belong. Sometimes it's even a one-time friend or former fellow member of some organization who is now prosecuting a vendetta in semi-public fashion.

But no matter what the motivation for sending spam, or how the sender justifies his/her actions, the practice is universally condemned by recipients, legitimate internet service providers, and the laws of most jurisdictions. Whether the spammer is sending thirty or thirty million messages at a time, you don't want to get them, the ISPs don't want to transmit them, and law enforcement agencies want to catch them and put them out of business for good.

Just as the typical new server will be attacked by hackers within seconds of joining the Internet for the first time, the typical email inbox begins to fill up with unsolicited messages soon after being opened. One of the most frequently asked questions by newcomers to the web (there still are some) is what to do about all the junk mail. Under another hat, the Spy offers web services, and noted that as much as 90% of all email presented to his servers is marked as spam. Well, the Spy obtained his first email address on Bitnet around 1972 (yes, the reader sees that date correctly) and herewith tenders a few modest suggestions.

What to do:

First, never answer an email message without checking to ensure it is from a known source. Spammers sometimes send email to many names on a domain (joe@thedomain, sally@thedomain, fred@the domain, etc.), hoping to hit a real account with one of several hundred thousand attempts. Replying will merely confirm to the sender that yours is a valid email address, and (s)he will promptly add it to many lists and sell it to other spammers.

Second, never display an email address in clear text on your web site, where it can be harvested by spammers and sold. Instead, obfuscate it. The simplest is to render it as me--AT--thisAddress.com rather than using the "@" sign. There are other ways to do this in text so it does not look like an address to a harvester (see a link at the bottom), or the address can be placed in a graphic so it can only be read by human eyes. Likewise, the Spy has now reluctantly concluded, do not allow your debating club, philatelic society, condo owners association, authors' group, or knitting circle to publish your email address. Such lists are frequently stolen.

Third, never do anything that the unsolicited email requests. Any attached file you open almost certainly contains a malware program that can take over your computer, either for the purpose of sending more spam, to find those stored credit card numbers, passwords, and other personal information, or to vandalize your files. The Spy adopts a zero-tolerance policy toward file attachments. Unless the sender has been specifically asked to send it, he deletes all such unread. Sorry, students, but you cannot submit your homework that way. The risks are too great.

Likewise, clicking on a link in the message will surely take you to a malicious web site. These fall into two categories. The first consists of fake sites pretending to be your bank, PayPal, or some other place where you have an account. The goal is to obtain your ID, your credit card or other personal information, and/or your password to an account. The second group of malicious sites are those set up to exploit bugs in browsers that may allow the site access to your computer and files. The common theme here is identity theft.

Note that no legitimate bank, Internet Services Provider, forum, or other online service will ever ask you to go to a site via a link embedded in an email message and provide your username and password or other information to "verify" your account, to deal with a "security issue" or to remove some "limitation" on your account. These are always frauds. If you have a concern about your account after receiving such a message, send an email to your contact person for that account (not using a link, but by typing in the address) or go to the service's web site (again by typing the address, not using the link.

Many email programs will warn you that a malicious link is not what it purports to be, but the absence of such a warning should not lull the reader into a false sense of security.

Fourth, most email programs have spam and abuse filters. Out of the box, these may be able to detect and mark some spam, then move it to the recipients' junk folder/box. These mailboxes should be checked weekly for "false positives", that is, messages that are marked as spam, but really are not. Commands found in the mail program's menu can then "teach" the filters that some messages are or are not spam. Over time, the filters will be better able to identify mail correctly, but the spammers themselves know of these filters and are constantly changing the wording of their messages to bypass them, so the training must be ongoing.

Fifth, if your email is part of a hosting package and you have a control panel for that hosting package (such as cPanel) you may have additional options for stopping spam at the server. These include:

(i) The server's own mail filtering programs, such as the very common Mailscanner, attach a number to all mail scanned, indicating the likelihood of its being spam or abusive. You can set the mail software at the server level to regard anything over a particular score as "high spam, then refuse delivery of high spam. You may fail to get a few false positives, but your mailbox will slim down considerably.

(ii) The server's control panel may also offer user-defined filters that you can set to discard or reject any mail with a particular phrase in its headers, including a specific "From:" (a blacklist). Again, the action is taken at the server level, and the message will not reach you.

(ii)Along the same lines, when you control your own domain, you can create as many email addresses or forwarders as you want. Give these out when you order on line, and as long as the company you dealt with doesn't sell it to a spammer, continue to use it when corresponding with them. When it does show up sold to a spammer, delete it.

(iii) If you are uncomfortable with changing these settings yourself, you can complain to your own web host or email service provider, who should be more than happy to set server wide or account level blacklisting on a troublesome spammer, preventing acceptance of the message by the server. The system operator also has access to a suite of server-wide filters, blacklists, and spam markings that can be taught to the mail scanner.

(iv) Server level spam filters rely on spammer lists maintained by third parties such as Spamhaus. You may be able to report spam directly to such an organization and have the offender blacklisted worldwide. However, despite defining spam as "unsolicited bulk email" Spamhaus has a more restrictive operational definition than envisioned here, and will only take action on commercial spam, not on other bulk unsolicited email, and not on abusive mail.

(v) Yet another spam prevention service worth cooperating with if you have your own site is Project Honeypot. This involves putting code and an "email address" on your website that when harvested and used in a spam email list immediately identifies the mail as spam, for only an illegitimate automatic harvester would detect the alleged address.

Sixth, ISPs (Internet Service Providers), even if only offering mail services, all have explicit clauses in their terms of reference that ban hate mail, abusive mail, and spam of all kinds. Here is an excerpt from a gmail TOS document:

In addition to (and/or as some examples of) the violations described in the terms of service, users may not:

Generate or facilitate unsolicited commercial email ("spam"). Such activity includes, but is not limited to

o sending email in violation of the CAN-SPAM Act or any other applicable anti-spam law;

° imitating or impersonating another person or his, her or its email address, or creating false accounts for the purpose of sending spam;

° data mining any web property (including Google) to find email addresses;

° sending unauthorized mail via open, third-party servers;

° sending emails to users who have requested to be removed from a mailing list;

° selling, exchanging or distributing to a third party the email addresses of any person without such person's knowing and continued consent to such disclosure;

° sending unsolicited emails to significant numbers of email addresses belonging to individuals and/or entities with whom you have no preexisting relationship.

Here is another from Hotmail:

Terms of Service. The Hotmail Terms of Service (TOS) strictly forbids sending unsolicited e-mail -- and the TOS is enforced with zero-tolerance zeal. All reported accounts in violation of the TOS are terminated immediately and permanently. Hotmail publicly posts its closures of those accounts from which unsolicited commercial e-mail has been sent to anti-spam Usenet newsgroups on a regular basis.

In addition, Hotmail recently instituted a "liquidated damages" clause in the TOS. This clause requires members who misuse Hotmail in connection with spam to pay $5 per spam message to Hotmail. This clause serves as a deterrent to keep Hotmail spam-free and will make it easier to pursue spammers.

Nearly all other such email providers, whether large or small, have similar clauses in their TOS, and enforce them. If you receive spam from a domain whose provider you can recognize, you can complain to the "abuse" department of that provider about the mail, and may be able to get the account cancelled, if the provider is reputable. Of course, the spammer is likely to start up again elsewhere, but you do get a temporary respite. If the amount of spam is large enough or the spammer is using a stolen address list, the provider may be willing to take legal action for the fines, or to put the offender in prison. One can always hope.

Seventh (modification of the very first point above for the brave) If you already know the spammer, or know that (s)he has your real address list anyway, you could consider sending a message to the person requiring that your name be removed from the mailing list being used. Keep this message and any reply. If the person refuses, even if implicitly by continuing to send the spam, complain to their services provider as in the previous section. It is a violation of nearly every provider's TOS to refuse to remove an address from a mailing list on request, so if the service they use is a legitimate one (such as gmail or hotmail) this complaint should result in cancellation of their account there. However, it is the Spy's experience that many companies are not as diligent about this as they ought to be.

If your service happens to be the same as the spammer's (say, gmail) you may be able to complain simply by clicking a box next to the email to tell the system operator that the mail is spam or abusive as far as you are concerned.

Eighth, even where no commercial or fraudulent aspect is present, and the mail contains no abuse, the sending of bulk unsolicited email is illegal in many jurisdictions, and may attract heavy fines and/or jail sentences. In celebrated recent cases spam kings Sanford Wallace and Adam Guerbuez, both of whom spammed Facebook accounts with commercial ads were fined $711M and $873M respectively. The latter judgement, made in California, has now, with exchange, amounted to nearly $1B CDN, and has been upheld by the Quebec Supreme Court. There have been other cases where the fines reached into the hundreds of millions, so these are not unique.

The gold standard now appears to have become a fine of $100 per address per message, and the larger ISPs and social networking sites seem to believe that at some point it is very much worth spending the legal money to pursue spammers, even if little or nothing can ever be recovered by way of paid fines (the offender declares bankruptcy). The hope seems to be that the publicity will deter others.

The Spy suspects that little short of jail will make much difference, for in most cases criminal prosecution is indeed a viable option. This is especially so in cases involving fraud, such as that of Alan Ralsky, the self-proclaimed "Godfather of Spam," who was sentenced to 51 months in prison for a pump-and-dump fraud run through spam.

It is worth noting that abusive mail, even if not explicitly threatening, is not only implicitly so, but its repetition is generally deemed harassment. Since uttering threats and harassment are criminal offences in almost all Western jurisdictions, this type of email can also result in slammer time. The recipient must decide whether the threats and/or harassment are sufficiently grave to file a police report.

Moreover, as in the last section, refusal to remove a name from an email list is a serious offence in many jurisdictions, and this may also be an avenue that either you, your provider, or the offender's provider can pursue.

Finally, an oddity of law in some countries, including the United States, prescribes particular penalties for sending unsolicited mail to a wireless device, offering a further legal option where applicable.

How much action is worth it?
In the case of commercial advertising, it is probably sufficient to stop the spam from getting to you, especially if this can be done at the mail server level before you download your mail to your own computer. In the case of abusive mail, particularly if a stolen database is involved, recipients may wish to give serious consideration to complaining up the line, first to their own ISP, then to the offenders' (if this is not just a server under his own control) and then to the police.

Now, wouldn't it be nice if a column like this never needed to be written? The Spy would be happy to see all spammers busted with heavy fines, all thieves of databases and senders of abusive email locked up. Perhaps the rest of us could then get on with our lives.

Rick Sutcliffe, (a.k.a. The Northern Spy) is professor and chair of Computing Science and Mathematics as well as Senate Chair at Trinity Western University. He is also on the board of CIRA, operator of .ca. He's written two textbooks and several novels, one named best ePublished SF novel for 2003. His columns have appeared in numerous magazines and newspapers (paper and online), and he's a regular speaker at churches, schools, academic meetings, and conferences. He and his wife Joyce have lived in the Aldergrove/Bradner area of BC since 1972.

Want to discuss this and other Northern Spy columns? Surf on over to ArjayBB.com. Participate and you could win free web hosting from the WebNameHost.net subsidiary of Arjay Web Services. Rick Sutcliffe's fiction can be purchased in various eBook formats from Fictionwise, and in dead tree form from Amazon's Booksurge.

URLs


The Northern Spy Home Page: http://www.TheNorthernSpy.com


The Spy's Laws collected: http://www.thenorthernspy.com/spyslaws.htm


The Spy's Shareware download site: http://downloads.thenorthernspy.com/

 

Community Search:
MacTech Search:

Software Updates via MacUpdate

CleanMyMac 3.9.2 - $39.95
CleanMyMac makes space for the things you love. Sporting a range of ingenious new features, CleanMyMac lets you safely and intelligently scan and clean your entire system, delete large, unused files... Read more
Printopia 3.0.4 - Share Mac printers wit...
Run Printopia on your Mac to share its printers to any capable iPhone, iPad, or iPod Touch. Printopia will also add virtual printers, allowing you to save print-outs to your Mac and send to apps.... Read more
Tinderbox 7.3.1 - Store and organize you...
Tinderbox is a personal content management assistant. It stores your notes, ideas, and plans. It can help you organize and understand them. And Tinderbox helps you share ideas through Web journals... Read more
ExpanDrive 6.1.6 - Access cloud storage...
ExpanDrive builds cloud storage in every application, acts just like a USB drive plugged into your Mac. With ExpanDrive, you can securely access any remote file server directly from the Finder or... Read more
Printopia 3.0.4 - Share Mac printers wit...
Run Printopia on your Mac to share its printers to any capable iPhone, iPad, or iPod Touch. Printopia will also add virtual printers, allowing you to save print-outs to your Mac and send to apps.... Read more
Tinderbox 7.3.1 - Store and organize you...
Tinderbox is a personal content management assistant. It stores your notes, ideas, and plans. It can help you organize and understand them. And Tinderbox helps you share ideas through Web journals... Read more
ExpanDrive 6.1.6 - Access cloud storage...
ExpanDrive builds cloud storage in every application, acts just like a USB drive plugged into your Mac. With ExpanDrive, you can securely access any remote file server directly from the Finder or... Read more
VOX 3.0.1 - Music player that supports m...
VOX just sounds better! The beauty is in its simplicity, yet behind the minimal exterior lies a powerful music player with a ton of features and support for all audio formats you should ever need.... Read more
Merlin Project 4.3.3 - $289.00
Merlin Project is the leading professional project management software for OS X. If you plan complex projects on your Mac, you won’t get far with a simple list of tasks. Good planning raises... Read more
Mac DVDRipper Pro 7.1 - Copy, backup, an...
Mac DVDRipper Pro is the DVD backup solution that lets you protect your DVDs from scratches, save your batteries by reading your movies from your hard disk, manage your collection with just a few... Read more

Latest Forum Discussions

See All

Animal Crossing: Pocket Camp mid-game gu...
By this point, you've probably hit or surpassed mid-way inAnimal Crossing: Pocket Camp.The game changes quite a bit as your focus slowly shifts from endlessly fulfilling requests for campsite buddies to improving your amenities. Here are a few tips... | Read more »
Mille Bornes (Games)
Mille Bornes 1.0 Device: iOS Universal Category: Games Price: $1.99, Version: 1.0 (iTunes) Description: | Read more »
Blob gets a new look in Give It Up! 3
Blob makes his triumphant return, as Yoozoo Games and Invictus Gaming have joined forces to create Give It Up! 3, the third in a series of delightful action-adventure games featuring our wobbly friend Blob. In this newest adventure, you’ll get to... | Read more »
148Apps' Ultimate Guide to Black Fr...
Black Friday is here, and there are a whole lot of discounts running right now for folks on the lookout for new mobile devices, accessories, and yes, even games. Here's a helpful rundown of what you'll find both in stores and online. Happy... | Read more »
The best Black Friday mobile game deals
Black Friday's upon us, and if you've happened to nab a fancy new phone during the week's big savings, you might be searching for some new games to fill up space on your new gadget. There are a lot of great games on sale right now for Black Friday... | Read more »
The best mobile games to play while your...
Thanksgiving is a time to reconnect with loved ones, eat lots of food, and all of that jazz, but once the festivities start to wind down, folks tend to head to the couch to watch whatever football is happening for Turkey Day. | Read more »
The best Black Friday deals for Apple ga...
Black Friday is hours away at this point, but many popular retailers are getting a jump on things with plenty of pre-Black Friday sales already available. Many of those early bird sales including some sharp discounts on the latest Apple phones... | Read more »
The Inner World 2 (Games)
The Inner World 2 1.0 Device: iOS Universal Category: Games Price: $4.99, Version: 1.0 (iTunes) Description: Solve mind-bending puzzles in a world full of mystery and save the family of the flute-noses! Their dynasty has been... | Read more »
warbot.io wants you for the robot wars
Fans of epic gundam-style battles will find a lot to love in warbot.io, the first game for up and coming developer Wondersquad. The game saw a lot of success when it first launched for browsers and Facebook, and now even more people are getting the... | Read more »
Uncover alien mysteries in cross-genre s...
If the Alien franchise taught us anything, it’s that landing on a strange planet at the behest of a faceless corporation is probably asking for trouble. And Eldritch Game’s Deliria doesn’t prove otherwise. In 2107, Dimension LG7 is rich with... | Read more »

Price Scanner via MacPrices.net

Apple 9″ 32GB iPad for $80 off on Walmart onl...
Snag a 9.7″ 32GB WiFi iPad for $249 on Walmart’s online store as part of their Black Friday sale. That’s $80 off MSRP, and it’s the lowest price available for an iPad so far this season. Sale price... Read more
Apple Black Friday sale for 2017: $150 Apple...
BLACK FRIDAY Apple has posted their Black Friday deals for 2017. Receive a $150 Apple gift card with the purchase of select Macs and up to $100 with various iPads, iPhones, and Apple Watches. The... Read more
Black Friday 2017: Where to find the best dea...
B&H Photo has 15″ and 13″ MacBook Pros on sale for up to $200 off MSRP as part of the Black Friday and Holiday sale. Shipping is free, and B&H charges sales tax for NY & NJ residents only... Read more
Black Friday 2017: Where to find the best dea...
B&H Photo has 12″ MacBooks on sale for $150 off MSRP as part of the Black Friday and Holiday sale. Shipping is free, and B&H charges sales tax for NY & NJ residents only: – 12″ 1.2GHz... Read more
Black Friday 2017: Where to find the best dea...
B&H Photo has 10.5″ iPad Pros in stock today and on sale for up to $130 off MSRP. Each iPad includes free shipping, and B&H charges sales tax in NY & NJ only: – 10.5″ 64GB WiFi iPad Pro... Read more
Black Friday 2017: Where to find the best dea...
B&H Photo has 13″ MacBook Airs on sale for up to $150 off MSRP as part of the Black Friday and Holiday sale. Shipping is free, and B&H charges sales tax for NY & NJ residents only: – 13″... Read more
Black Friday 2017: Where to find the best dea...
B&H Photo has 27″ and 21″ iMacs on sale for up to $200 off MSRP as part of the Black Friday and Holiday sale. Shipping is free, and B&H charges sales tax for NY & NJ residents only: – 27... Read more
Black Friday 2017: Where to find the best dea...
B&H Photo has Mac minis on sale for $100 off MSRP as part of their Black Friday sale, each including free shipping plus NY & NJ sales tax only: – 1.4GHz Mac mini: $399 $100 off MSRP – 2.6GHz... Read more
Black Friday 2017: Find the best deals and lo...
Scan our exclusive price trackers for the latest Black Friday 2017 sales & deals and the lowest prices available on Apple Macs, iPads, and gear from Apple’s authorized resellers. We update the... Read more
Black Friday: 27″ 3.4GHz iMac for $1599, save...
Amazon has the 27″ 3.4GHz Apple iMac on sale for $1599.99 as part of their Black Friday sale. That’s $200 off MSRP, and shipping is free. Their price is currently the lowest price available for this... Read more

Jobs Board

Information Systems Engineer, *Apple* Retai...
# Information Systems Engineer, Apple Retail Engineering Job Number: 112895982 Santa Clara Valley, California, United States Posted: 02-Oct-2017 Weekly Hours: 40.00 Read more
Commerce Engineer, *Apple* Media Products (...
# Commerce Engineer, Apple Media Products (New York City) Job Number: 113028813 New York City, New York, United States Posted: 20-Sep-2017 Weekly Hours: 40.00 **Job Read more
Business Development Manager, *Apple* Pay -...
# Business Development Manager, Apple Pay Job Number: 112919084 Santa Clara Valley, California, United States Posted: 18-Aug-2017 Weekly Hours: 40.00 **Job Summary** Read more
Digital Marketing Media Planner, *Apple* Se...
# Digital Marketing Media Planner, Apple Services Job Number: 113080212 Culver City, California, United States Posted: 03-Oct-2017 Weekly Hours: **Job Summary** Read more
*Apple* Retail - Multiple Positions - Apple,...
Job Description: Sales Specialist - Retail Customer Service and Sales Transform Apple Store visitors into loyal Apple customers. When customers enter the store, Read more
All contents are Copyright 1984-2011 by Xplain Corporation. All rights reserved. Theme designed by Icreon.