Verizon Routing Millions of IP Addresses for Cybercrime Gangs
spamhaus.org
spamhaus.org
Wow. The 90s called, they want their SMTP gateways back.
What I don't understand is that pretty much everyone has an incentive to eliminate spam. ISPs to reduce traffic, emails providers to produce a better service and spend less time dealing with spam. Users for obvious reasons. Only the NSA enjoys the current unencrypted status quo. Why doesn't it happen? Why are we stuck with a 30y protocol?
[edit] also a system of extended validation for signatures like for ssl certificates would be useful. I would end up expecting a nice green logo in my mail client for emails from citibank.com, something cit1bank.com could not achieve.
[edit2] also a modern design would require emails to be instantaneous. All these messenger apps would become redundant and we would revert to a common standard.
http://craphound.com/spamsolutions.txt
Good checklist of things a potential "reformed SMTP" needs to do.
If the Wright Brothers wanted to eliminate auto accidents by flying, anyone at the time could have told them they were doomed to failure, and history would have proven them right, even though air travel is safer than road travel. That's because getting people to stop using cars isn't simply a matter of inventing an airplane.
Someone should write up such a list along with a bot that replies to any post that cites the craphound link linked above. I think it's a valid counterpoint.
Nevertheless, whenever someone offers up a cure-all for SMTP, that craphound list is the first thing that comes to mind.
Almost every business relies on OpenSSL or some equivalent, but how many actually learn enough about SSL to contribute back to the codebase? Not many, because despite the need there's little acclaim or funding to be had pursuing things that won't make direct revenues, regardless of their importance.
Protocols like this generally don't get updated until it becomes a matter of necessity -- either by public awareness (we're far from that point) or someone designing the "next big thing" needs an un-implemented feature and contributes.
Fixing smtp should be as important if not more than upgrading http 1.1.
My point though, is that it's always a "secondary" or "tertiary" business concern... a point emboldened by the number and frequency of data breaches -- always followed of course, by the email newsletter follow-up & mea culpa. "We care about the security of your data, we swear. We regret to inform you that ..."
Sadly things are not always as they should be, friend...
And unless you permit sending a single message to both SMTP and better-than-SMTP recipients without any UI awareness, you've built a product that's strictly worse than SMTP for end users.
You could add features to email to make a more compelling product, and then kill seamless integration with other SMTP users and still have a better product. (See e.g. Slack. Or Facebook, for personal email.) And then maybe in many many years nobody will want email any more. But that won't be quick.
If Gmail, Yahoo, Microsoft, and Comcast announced that they are making it more likely that outside email (from online stores, from individual Exchange installations, etc.) will be marked as spam when it's not actually spam, people will find new email hosts. Somehow.
If they just want to mark traffic as spam when it is, they're already doing that.
I got nowhere. Their forms to be unblocked just reply "Yes you are a spammer, Bye". Contacting a human has been futile.
And this is the same place that is ranked as the top host for spammers?
This might be a long shot, but when I'm trying to solve difficult problems like these, I just call Sales. And Sales might have these phone numbers!
Sure, they're probably not even in the same state (:P) as the department you really need to speak with, but they're constantly trained to be driven and achieve customer satisfaction - and they all have that after-conversation rating thing they're working for (btw, max everything out on that, most of them are graded exponentially toward maximum, something insane like: 0..n-2 usually means 10-20%, n-1 is 50% and n is 100%).
After enough convincing (the magic, arbitrary protocol is always different) they'll try and figure Something(TM) out. Especially if you repeatedly, patiently call them.
In all seriousness, it's not V who decides who is good or bad on the Internet - it's a shared consensus that things like this are Bad(tm).
Verizon shouldn't be helping people steal IP addresses from other organizations.
Bogons are unacceptable regardless of what they're being used for, because the announcer is essentially hijacking those IP addresses. In this case the addresses being hijacked aren't being used, but they still don't belong to the group using them.
Any ISP that propagates BGP announcements from their customers should have filters in place to prevent this from happening. Verizon isn't doing their due diligence.
They make coin from the spammers, right? Might have a little something to do with their negligent complicity.
What's most troubling is that Verizon ignores the anti-spam efforts. Did someone fall in deep sleep while reading the mails?!
If the people stole those IP addresses, then something should be done.
"In addition, spamming from these stolen IP addresses is a felony under the US CAN-SPAM Act." said another way.... "In addition, sending information in a unauthorized fashion is a felony under the US CAN-SPAM Act."
Should we really be cheerleading more rules and tighter restrictions on comms? Uh. Lets require biometrics to xmit!
BGP is a trusting protocol, with expectations enforced by social contract rather than cryptography. Part of the social contract among ISPs is that only competent, legitimate entities get to participate in BGP, and Verizon is violating that.
It's too easy to restrict people by 'fixing' a non-problem (junk mail from 'gangs' in this case).