Provocateur Comes Into View After Cyberattack
nytimes.com
nytimes.com
Raw, brutish racism/culturalism doesn't help your message. At all.
I read a line like this:
"Spamhaus acted, he wrote, 'without any court verdict, just by blackmail of suppliers and Jew lies.'"
And regardless of whether he's right or not about Spamhaus, his credibility in my eyes has gone straight to absolute zero.
Wasn't that entirely the point of the article, to attack his character?
If he was some lawyer stiff, people wouldn't be reading this - they enjoy reading content-light articles that spin caricatures of charismatic individuals. Assange all over again!
It's hardly debatable whether he would have gotten media exposure like this if he didn't behave in such a manner; I think that overall this exposure will help his cause, not hurt it. Even if a majority discard STOPhaus claims immediately on the basis that their spokesman appears to be a nut, the minority dwarfs anything they would have reached otherwise.
tl;dr you only saw this message because it was raw, brutish, and insensitive.
That's the issue. It sucks to wake up one day and find out that your mail server has been blacklisted. All your customers are now affected and it's too late. If they added whole IP blocks to the list it might be even more annoying.
That said it's not like Spamhaus is charging you to be removed from their list, it just takes a little bit of time once you cleanup. http://www.spamhaus.org/faq/section/Spamhaus%20SBL#137
The full quote is 'Spamhaus acted, he wrote, “without any court verdict, just by blackmail of suppliers and Jew lies.” When I read that, I get a very different picture than simply one of an aggrieved businessman working in a grey area.
It also makes me wonder: How legit are the people running Spamhaus? If someone decides he wants to make a quick buck, is it possible for him to just arbitrarily add a site's IP ranges to the routing blacklist, and then send the site's operators a cash demand, like DDOS operators sometimes do?
The way the Internet has worked since day 1 is as a bunch of relatively independent groups deciding who they'll talk to and in what fashion.
If a bunch of people don't want to talk to your ISP because of who the ISP hosts, that seems pretty sensible to me. And if they have decided to trust Spamhaus to make those calls, that also seems reasonable.
Supposing you get your wish and Spamhaus disappears tomorrow. What's your proposed solution? With the kind of money that on-line crime like spamming and phishing makes, it's easy enough to find somewhere to buy protection from law enforcement. Or just buy laws.
Either we decide not to talk to the bad neighborhoods, or the globally connected nature of the Internet means that we all live in the worst neighborhood.
Anyway, you're missing my point: Why on earth do you have to blacklist the entire ISP to deal with one customer? Presumably if you are certain that one specific customer is to blame, and you're demanding that customer be disconnected, you know which IPs the customer is using and you can block them. Or you are otherwise able to identify the customer, say through headers - in which case, you should filter those headers. Blacklisting the ISP should only be necessary if the ISP is intentionally helping its customer obscure their identity and disguising spammy/malicious traffic as normal traffic.
There is no excuse for punishing innocent web users and businesses for the actions of third parties, or for holding those innocents hostage in order to force their ISP to do something you want. The fact that the ISP later complained to the authorities suggests to me that this is exactly what happened. Is it really impossible from a technical perspective to do anything other than blackhole the entire ISP? I'll admit I'm not an expert on IPv4, but that seems implausible to me.
The problem with these policies and principles you're defending is that they can be equally applied to innocents in order to do harm. I'm not claiming I have some perfect alternative; I am merely pointing out that Spamhaus' means don't seem legitimate, even if their ends are legitimate. And in this case, the legitimacy of the ends can come into question as well.
There's a gray area between obvious spam (penis pills, etc) and obvious solicited mail (personal mails between individuals) - Twitter sends me emails regularly containing tweets by people I follow, because I have an account, but I never solicited that email. Is it spam? What if there are other people who do want those emails, even if I don't? Is it really appropriate to blacklist Twitter?
The Twitter example isn't a fantasy, either; Gmail automatically started sending those things to my Spam folder without my intervention, and I've seen it do that to other content in the past. Would you be happy if Spamhaus added the IP ranges of businesses and ISPs you interact with to its blacklists? What if they blacklisted your home ISP?
If Spamhaus blacklisted my ISP and had reasonable evidence that they were harboring spammers, I wouldn't yell at Spamhaus. I'd tell my ISP to kick out the spammers or I'd leave. This isn't a hypothetical for me: I moved a cabinet of gear out of an ISP precisely because they were dealing with the devil.
I can't remember now if Spamhaus was involved, but I was definitely grateful to find out that the ISP was harboring spammers. It was a clear sign that they were in financial difficulty and were being run by idiots. They were out of business less than a year later because of those financial difficulties, and because their good staff didn't want to work for assholes.
If you want to run a blacklist in a way that you think is better than Spamhaus, nobody's stopping you. If you are right, then presumably people will pick yours up and drop theirs. But my guess is that they'll retain their popularity, because people who actually have experience dealing with network abuse are pretty happy with their approach.
I'd argue that 99% of businesses are better served letting a third-party deal with marketing and transactional emails and only use outgoing SMTP for their own emails.
Reality is, you have to totally ignore complaint after complaint about spam coming from your network before you end up on any blacklist.
Most common form of negligence often came from some management decision to let role accounts like abuse@ get handled by non-technical communication or support people with zero authority to escalate the problem. If that still happens in 2013, fuck them.
Bottom line is that only willful negligence or deliberate support to spammers can get you blacklisted. If you are in no hurry to remove spammers, don't expect Spamhaus e.a. to be in any hurry to un-blacklist you.
http://www.nytimes.com/2013/03/30/business/global/after-cybe...
Nobody is forced to use Spamhaus, right? They aren't dictating what is on the Internet, they are offering a list to filter what they think is junk and people can choose to use that or not.
Also, I am curious, did he ever care about Spamhaus before he started to get included in their blacklists?