360 million newly stolen credentials on black market
reuters.com
reuters.com
This really bugs me. It seems like many companies are either completely unaware that a breach has occurred, or know about it and are taking their time notifying customers (for PR or other purposes). Either way, customers are not getting this information in a timely manner, and that needs to change.
This is grossly underestimating how hard it is to have a bullet-proof system. Some of the best security people in this planet use disconnected systems when they want to be sure it is safe.
Anyone have a copy of the dump?
[1] http://gmailblog.blogspot.com/2008/03/2-hidden-ways-to-get-m...
The problem for me is inconsistent support. For example, when validation allows it, but the server-side strips the +. I recently booked a flight with Monarch (UK super budget), email address:
example+monarch@gmail.com
This got stripped to examplemonarch@gmail.com which I'm sure doesn't exist for my name. I couldn't change the email because.. surprise.. you need a confirmation email to do it. Fortunately you only need the booking reference and the address to check in, but it was a bit annoying.
I used Google Apps for my personal email, and I'm pretty happy with the spam protection. (Although I don't check my spam folder for false positives, so who knows?)
Anyway, can anyone who has switched from Gapps/Gmail to their own installation of SpamAssassin comment on how that worked out for them, and how much time they spend maintaining their setup?
I've started doing this occasionally, and while false positives are rare, they do happen and are sometimes pretty important! It's useful that it tells you why mail is in the folder, though sometimes the explanations are more informative than others. One funny one was that it trashed a mail because it contained Danish text, a language it says I don't correspond in. I do indeed not correspond in Danish, but I do live in Denmark, so getting Danish email isn't so surprising, and usually is actually important (e.g. from the tax authority). That one was interesting in that it seems to indicate they don't tune the spam filter using all the personal profile data they have (Gmail certainly knows I log in from a Danish IP).
I know it's a popular domain to spoof, but you'd think that at least with @google.com they could do a quick validation step!
Yeah, this is infuriating. I had gmail silently spam-filter an email on the grounds that it came from an @qq.com address (QQ is a large chinese social network). While I had never corresponded with that particular QQ address, I had correspondence from several other QQ addresses in my inbox. Also in my inbox: correspondence with an @foxmail.com address displaying the same sender name as the mail that was supposedly spam. I don't see how it could have been more clear, contextually, that I wanted to receive that mail.
A combination of SA and Spamhaus's zen and dbl blocklists catches the vast majority of spam coming into my server, but I still usually end up with at least a few per day on average.
I can go weeks without looking at the server at all. But when something does go wrong it can take some time. Right now I'm trying to figure out why SA has started silently dropping certain messages to certain addresses after it figures out they're not spam, rather than piping them back into Postfix as it should. This is obviously not good.
The average amount of maintenance time is very low, but the distribution is not even - if it breaks, Murphy's Law guarantees it will be at the least convenient time. Like when you're on holiday or expecting an important email.
You could even add the ability to verify that a given email/password combo does not appear in the list :)
Deleted comment
"redhat.com mailing list memberships reminder"
It's bullshit when people send my password in plaintext to my email account and they ignore my complains when they said "if you have questions send to this owner emaiil." Bullshit. Why do they need to remind me about my password in the first place?
From what I can tell mailman stores thing in plaintext. I personally don't see why anyone can't write 20 lines of code to do a crypt with sha256/sha512 (crypt$5, crypt$6). It's almost idiotic.
Why can't we do this when the EU can pass useless cookie directives?
This is not exactly the case -- the amount needed to pay the fraud detection services will surely be passed on to the credit card users in the form of higher APRs.
These days I'm wondering how to go about changing my Internet to a new, secure one, where there are no financial predators.