Really, if your computer is spamming someone, even if you aren't aware of it, you are harming them, and ignorance shouldn't be protection. Maybe fines and jail are a bit too severe, but rate limiting and possible disconnection are more then fair.
Really, if your computer is spamming someone, even if you aren't aware of it, you are harming them, and ignorance shouldn't be protection. Maybe fines and jail are a bit too severe, but rate limiting and possible disconnection are more then fair.
It's a pretty solution to the problem in theory, but when you actually apply it, it doesn't quite work out as well.
They can literally compromise new machines faster than you can identify existing compromised machines. It doesn't do anything to impose anything on the machine owner -- as soon as you identify the machine you can blacklist it, and as soon as you blacklist it they stop using that one.
The problem is in the time it takes you to identify a compromised machine, they can compromise many more additional machines.
(2) Same with spam blacklists, you get de-listed either automatically, if few weeks pass without incident, or faster by manual request.
(3) It should not matter why bad traffic was sent. A much more realistic situation is: "So you work from home and your computer gets trojan which starts to send phishing emails, so now the ISP cuts you off from the Internet. Now what?"
In either case the answer is: prove to humans @ ISP that you are no longer danger to the internet and ask them nicely to unblock you. If you work from home is that critical, have a separate internet source (say 3G modem which you activate with a phone call)