My crazy idea to piss off spammers
indiegogo.com
indiegogo.com
( ) technical ( ) legislative ( ) market-based (x) vigilante
approach to fighting spam. Your idea will not work. Here is why it won't work. (One or more of the following may apply to your particular idea, and it may have other flaws which used to vary from state to state before a bad federal law was passed.)
( ) Spammers can easily use it to harvest email addresses
( ) Mailing lists and other legitimate email uses would be affected
( ) No one will be able to find the guy or collect the money
( ) It is defenseless against brute force attacks
(x) It will stop spam for two weeks and then we'll be stuck with it
( ) Users of email will not put up with it
( ) Microsoft will not put up with it
( ) The police will not put up with it
( ) Requires too much cooperation from spammers
( ) Requires immediate total cooperation from everybody at once
( ) Many email users cannot afford to lose business or alienate potential employers
( ) Spammers don't care about invalid addresses in their lists
(x) Anyone could anonymously destroy anyone else's career or business
Specifically, your plan fails to account for
( ) Laws expressly prohibiting it
( ) Lack of centrally controlling authority for email
( ) Open relays in foreign countries
( ) Ease of searching tiny alphanumeric address space of all email addresses
( ) Asshats
( ) Jurisdictional problems
( ) Unpopularity of weird new taxes
( ) Public reluctance to accept weird new forms of money
( ) Huge existing software investment in SMTP
( ) Susceptibility of protocols other than SMTP to attack
( ) Willingness of users to install OS patches received by email
( ) Armies of worm riddled broadband-connected Windows boxes
(x) Eternal arms race involved in all filtering approaches
(x) Extreme profitability of spam
(x) Joe jobs and/or identity theft
( ) Technically illiterate politicians
( ) Extreme stupidity on the part of people who do business with spammers
( ) Dishonesty on the part of spammers themselves
(x) Bandwidth costs that are unaffected by client filtering
( ) Outlook
and the following philosophical objections may also apply:
(x) Ideas similar to yours are easy to come up with, yet none have ever been shown practical
( ) Any scheme based on opt-out is unacceptable
( ) SMTP headers should not be the subject of legislation
( ) Blacklists suck
( ) Whitelists suck
( ) We should be able to talk about Viagra without being censored
(x) Countermeasures should not involve wire fraud or credit card fraud
( ) Countermeasures should not involve sabotage of public networks
( ) Countermeasures must work if phased in gradually
( ) Sending email should be free
( ) Why should we have to trust you and your servers?
( ) Incompatiblity with open source or open source licenses
(x) Feel-good measures do nothing to solve the problem
( ) Temporary/one-time email addresses are cumbersome
( ) I don't want the government reading my email
( ) Killing them that way is not slow and painful enough
Furthermore, this is what I think about you:
( ) Sorry dude, but I don't think it would work.
(x) This is a stupid idea, and you're a stupid person for suggesting it.
( ) Nice try, assh0le! I'm going to find out where you live and burn your house down!
And, viola, my competitor receives loads of fake orders, becomes overwhelmed, goes out of business.
Maybe you're right, maybe it can't be done, but aren't we suppose to be problem solvers? :)
The spammers put incredible effort into quashing BlueFrog...
I was an early user of BlueFrog (and can confirm that the spammers didn't gain access to any addresses they didn't already have on their lists), and tried to contribute to followup efforts... it's a hard problem to solve, though -- how to make this kind of retaliation without exposing yourself to (possibly very serious) attack. We're all quite vulnerable online; it's surprisingly trivial for "the bad guys" to decide to permanently take your website (or the site of your company, etc.) offline.
If that's true and anybody has data to back it up, maybe publicizing it would be a worthwhile spam-combating measure.
What if some significant fraction of web servers did this? Wouldn't that make trolling for "IP theft" like Cyveillance does into an economically unfeasible activity?
What if nearly everyone pressed 1 when "Ann from Account Services" or "Rachel from Cardmember Services" calls, and then talked to the service rep for as long as possible?
In the case of web servers, the bad actors like Ahrefs often ask for things vaguely like known security problems - issues in PHP based BBS for example. Ahrefs asks for something and they get some data back. Is it my fault that they don't get back data with the exact semantics they wanted? No, as I am not a magician.
I just used my own judgement on it.
Trolling for "intellectual property" infringement for third parties also seems like a scummy line of work to me. It's in Cyveillance interest to find infringements, so there's no economic reason for them to get such findings correct.
So, I conclude they're a bad actor.
Don't think this worked out either.
http://scattered-thoughts.net/blog/2010/05/19/examining-scam...
Turns out its really hard to prevent malicious actors abusing it.
I'm in Bath.
Sometimes i think it is spam, but then I notice i signed up for it myself :p
To those who say, "stupid idea", I'm very disappointed both in the rudeness you show, and the smallmindedness you exhibit. Will this work? If implemented the way Boris writes, I believe it would for the reasons he stated. Those who say "stupid idea" have never had 4,000 orders to deal with - that's the only logical thing that can explain such reactions. The problem is in the implementation of course. Yes, it would be difficult. Yes, it would require adaptive techniques and technologies. But don't forget that people who have a really good and innovative idea don't just have one idea in their heads for their whole life. Ask PG about that...
It's a good idea. I think that, for it to succeed, you would have to work with one of the big credit card companies. If you could get them to provide honey pot-style credit card numbers, you would have something.
For those saying that competitors could be put out of business if this was misused, what's stopping that from happening 20 years ago, 10 years ago, now, 10 years from now? That's not a reason for this to not be considered, is it? That's like saying, "We shouldn't allow lawsuits because you could sue a competitor and he could lose his business defending the lawsuit due to the cost/distraction."
Also: Spam that gets sorted out automatically is like... whatever.. ?! [at least for me]
And like others pointed out: It's a pretty nonsense approach anyways (wondering why it got so many votes)
So now you basically are presenting a single course "solution" that - once trumped - leaves you with millions of dollars and a need to come up with a completely new idea.
Wholly faulted.
I get MAYBE 2 spam emails a month that gets through the filter, and my address is pretty easy to harvest.
So is this still a problem?
That being said, it's seems to be getting better as more companies embrace SPF.
A bigger annoyance is constant newsletters/emails sent from companies whom I might have transacted with long ago in the past. I have to take time to unsubscribe from all this stuff.
Edit: in 2010 they estimated 294 billion messages were sent per day, more than 2.8 million emails every second.
So maybe tell them that if you send personal messages and segment the market that would increase the response rate and reduce the spam?
Since I moved to GMail I don't know what spam is anymore: everytime people complain about spam I'm confuzzabled because I honestly thought the issue was solved.
It's great to run your own mailserver and be independant of the evil Google etc. but face the facts: people on GMail hardly get spam anymore...
Now as to how to fight spammers I'd suggest building a gigantic botnet, taking control of hundreds of thousands of credit cards numbers and ordering like mad from these spammers. Make it so big that credit cards companies start noticing the issue.
This of course should be done by someone who doesn't care about petty money...
Most of it seems to be of the form "Hi, this is Natalia from the dating site. I loved your photo and would want to speak with you, please reply soon! xxx" rather than "buy v1agr4 4 big dikk http://10.23.133.21/m4dsexcockpillz, so I guess harder to filter.
The more annoying thing with gmail is that most of my inbox is legit mail that was never intended for me. Since the gmail namespace is so cluttered there are a few people who have almost identical email addresses to me; so I get their mail in error often.
Also google seem to have merged my account with someone elses, so I get notifications about stuff that is definitely not mine.
Luckily I was expecting the mail, and there is a solution. I added a filter for that email address and say "don't mark these messages as spam". But "solved" would mean "spam doesn't exist anymore", in my book.
Nonetheless, I love Gmail and its spam filtering. I'm very happy to mark a few messages as spam for the greater good.
I too have a gmail address, and I'm getting spam in my inbox on a pretty regular basis (1-2 messages a week). Of course, it's about 1 message missed out of 1000+ spam messages, but that scarcity tends to add legitimacy to the message.
It also means I have to spend more time looking for the problem with potentially legitimate messages.