Get me off Your Fucking Mailing List (2014) [pdf]
scs.stanford.edu
scs.stanford.edu
https://www.vox.com/2014/11/21/7259207/scientific-paper-scam
> The journal, despite its distinguished name, is a predatory open-access journal, as noted by io9. These sorts of low-quality journals spam thousands of scientists, offering to publish their work for a fee.
> In 2005, computer scientists David Mazières and Eddie Kohler created this highly profane ten-page paper as a joke, to send in replying to unwanted conference invitations. It literally just contains that seven-word phrase over and over, along with a nice flow chart and scatter-plot graph
> According to the blog Scholarly Open Access, this PDF made the rounds, and an Australian computer scientist named Peter Vamplew sent it to the International Journal of Advanced Computer Technology in response to spam from the journal. Apparently, he thought the editors might simply open and read it.
> Instead, they automatically accepted the paper — with an anonymous reviewer rating it as "excellent" — and requested a fee of $150.
Did they pay? They really should have to get it published
"Correction: This article previously said the article was published by the journal. It was only accepted, because the author didn't want to pay $150."
If you ask me this, should just be standard.
Did you use Oauth that time? Which Oauth service?
Did you use an email? Were you on your phone and actually used the Apple Id “Oauth” looking button and gave a relay email?
Were you lazy and used your phone browser’s autofill and password manager?
Were you NOT lazy and an unhidden email and separate third party password manager?
This was all before Apple's feature came to be. I just hope this kind of email 'protection' becomes more mainstream.
(Which is a shameless plug, since I work on that, but I know there are quite a few people here who trust Mozilla and for whom it's relevant.)
And if you use it to generate email masks in your browser, it can remember what website you created on without exposing that to the sender, and without a trail linking the email address to your other addresses.
I also added a rule to make every sub-email into its own subdirectory so it is super easy to manage
Postfix itself is, uh, well I knew it well coz we also use it at work, but it was a bit of work, as my setup was a bit specific. The config itself was simple (mostly off their docs again), but I did a bit of customization.
I did extremely simple auth with just a text file with list of all the accounts + a bunch of aliases. Auth was provided by dovecot
...
passdb {
driver = passwd-file
args = /etc/dovecot/passwd
}
userdb {
driver = static
args = uid=vmail gid=vmail home=/home/vmail/%u
}
...
# auth for postfix submission
service auth {
unix_listener /var/spool/postfix/private/auth {
group = postfix
mode = 0660
user = postfix
}
}
that just allowed to give smtpd auth this as extra parameters: + -o smtpd_sasl_type=dovecot
+ -o smtpd_sasl_path=private/auth
In the "other direction" (postfix sending mails to dovecot for delivery) I set up this in master.cf dovecot unix - n n - - pipe
flags=DRhu user=vmail:vmail argv=/usr/lib/dovecot/dovecot-lda -f ${sender} -d ${user}@${nexthop} -m tag.${extension}
that is entirely standard except one thing, -m tag.${extension} is a bit of a "trick"; it will create any +address as a directory under tag/ (if you have "lda_mailbox_autocreate" set to "yes" in "protocol lda"So, for example email to "me@domain.com" would land in INBOX but "me+badsite@example.com" would land in tag/badsite directory.
that just needs something like
dovecot_destination_recipient_limit = 1
virtual_mailbox_domains = example1.com, example2.com
virtual_transport = dovecot
virtual_alias_maps = hash:/etc/postfix/virtual
to set upA pain, but he was serious about hating email spam.
https://kevincox.ca/2022/07/07/signed-email-addresses/
Basically signed addresses are exempt from regular spam filtering. If they are abused they are blocked.
Also gmail spam filter isnt what it once was, or perhaps it is just the 1% failure rate shows up more when you get 100's of spam messages a day.
At some point in the last few (3-5 years?) I just gave up. My communication with important people hasn't really changed. I star important people by default and just glance over at them.
I've also trained those same important people that I always pick up my phone, so they feel like they can call me if it's urgent or important.
My output is higher now and I just don't think about email. Sometimes I miss things that people ask of me. They either come back around, because they are actually important, or they die on the vine.
I'm also very specific about what/who an important person is, so there just aren't that many important emails.
It was the one feature I never got full buy in when working there, but if anyone has half a mil to spare, you can run some very fun experiments with mail.
American companies are great of subscribing you to their spam mails without opt-in.
spammer.douch.nozzle/collect_request/JoeShmo_1x1-transparent-UUID_0se9a009fjwljwlfl2f.gif
but all the info the douch needs is in the "UUID", the rest is easily obfuscated.
If your email client renders renders images willy nilly, the image is enough to confirm a valid target (clicking "unsubscribe" isn't necessary to become victim but is a hard lock-in mechanism (A human is on the hook...)).
No. I’m talking about abuse-mails, I’ll reply to the top-level comment
I reckon they might be using this: https://www.rfc-editor.org/rfc/rfc8058
This is pure speculation since I have no visibility into their inner workings, but it might just be possible that they would send a POST request on your behalf, at least to domains on some sort of a pre-approved list.
But looking at the list of addresses we blacklisted because of them, I now realize that those are actually all web.de and gmx.de (crappy German freemailers), so it seems the leaks only happen with them.