626 karma · joined July 13, 2010
Edit: spelling
I ran a medium email ( late 90's ) mail server system on a dedicated 100mb/s line, on an older dual cpu Power Mac actually, but I pulled out all the GUI and tried to run it mostly as a server using the client OS and only the CLI, making it more like running FreeBSD or openBSD I suspect.
I got a /24 IP range out of Comcast which I think helped as it was a previously never used /24, or at least not in use long enough that it had fallen out of RBL's
I'm sure you are aware of the sites that checks your IP against all 200+ or so mainstream RBL's.
There are a few RBL's that block Comcast business as well as all cellular ranges and quite a bit more. I found RBL's to be more trouble than worth.
Ideally, you are dropping the connection at the very beginning, just after the EHLO/HELO., highly efficient, perhaps marginally more efficient CPU-wise than greylisting. Fail2Ban is probably your best friend. Do it closer to the network if possible.
The above, versus pushing the message through various spam filtering, address validation, and other measures. There's heavy CPU usage post greylisting, greylisting is great, but waiting that 5-15 minutes for the retry is too long, most users don't use a password manager. Their password manager is "forgot your password". Insane, but that's how I watch all my friends do it. They learned not to re-use passwords, but now they rely on third party email to send forgot password messages. At least people can tell which are not hashing/+salting their credentials. Though I doubt most blink an eye at a raw password in an email. Clients have email me their credit card data. I tell them delete their debt message, then dived 15 minutes doing tech support to help them locate the credit card sent email.
I was far too often adding whitelist entries, making certain clients ignore greylisting or drop down to 30 seconds, for which I saw no increase in spam. It's the retry value on the server that's set too high/long. Not to mention the 10% or so of older email servers that don't support greylisting so never retry. A clear RFC violation, but these are proprietary systems and not made with greylisting in mind. You could achieve it with a proxy running greylisting or ASSP if you want a full proxy with web admin and essentially a full MTA in a proxy all in one file of many tens of thousands of perl code. No version control, crazy version numbers, and I think still on SFNet ( Source Forge )
At some point you realize you have added aol, yahoo, gmail, etc., all the big guys, they need whitelisting because their IP ranges are huge, and ever changing. Keeping on top of which IP's they are publishing as public MTA based IP's, you can build a solid whitelistable IP range, but they change often enough it's not feasible. A SAAS that checked all this would be nice but latency may be too much. Less than the 5-30 minutes of greylisting though.
AOL fully ignores greylisting last I looked. Not to mention DNS TTL's are/were ignored. Sucked to set my MX TTL to 300 seconds, wait the 8 hours for my default DNS expiry, switch my DNS, and then wait 2 weeks for DNS proposition with aol. Not to mention all the paperwork that needs filling out to get into their MTA whitelist program which kicks your sending threshold up by a percentage so it's not a true whitelist. I had to renegotiate every time we added another 5000 to our outbound, it would flag me and I could see all the aol messages stuck in my outgoing queue. Two weeks was longer than my greylisting time, messages bounced because aol saw no server at the other end. I had to keep a "gateway" running, basically I set up a secondary MX to sit there and deal with the aol 2 week DNS propagation to happen.
Finally I gave up and added an external SMTP only machine in a colo. small machine, under 100.00 a month, all it did was SMTP. Deliverability was significantly better after that but ruined the notion of securing my data at my location. But it is relatively ephemeral in that its just SMTP, the data sends instantly, unless it hits greylisting servers or other things that initiate a SMTP retry. That leaves messages and retry logs on the remote server out of my control physically.
Most don't answer postmaster@ or abuse@ which are RFC. Some even bounce meaning they don't even have those addresses available. Having a support/postmaster/abuse @ address that you certainly should check. As I'm sure you are aware, some RBL's are more aggressive than others. Some are down-right draconian, and some are more like a whitelist in that they leverage grey listing so any outbound mail is given a few good points in it's total possible span score.
I ran a medium email server system on a dedicated 100mb/s line, on an older Power Mac actually, but I Pulled out all the GUI and tried to run it mostly as a server using client OS and only the CLI, making it more like running FreeBSD or openBSD I suspect. Added 2x SATA cards and an additional CPU to speed things up. IMAP is purely I/O limited and I wanted and had everyone in IMAP. but IMAP needs a few horses behind it, I wish SSD's were where they are now back in the 90's. That would have been great. I moved my 4GB IMAP account into pure ram disc. It was pretty amazing. Millisecond loading of a mailbox with push enabled in milliseconds to load many tens of thousands of messages and attachments.
I got a /24 out of Comcast which I think helped as it was a previously never used /24, or at least not in use long enough that it had fallen out of RBL's
I'm sure you are aware of the sites that check your IP against all 200+ or so mainstream RBL's.
There are a few RBL's that block Comcast business as well as all cellular ranges and quite a bit more. I found RBL's to be more trouble than they are worth. Good in theory and a great thing to run your own local RBL as it's such a nice way to manage it, through DNS. Want to whitelist or block, just add a DNS entry after reversing the IP. Simple, immediate, understandable.
Ideally, you are dropping the connection at the very beginning just after the EHLO/HELO. Versus pushing the message through various spam filtering, address validation, and other measures. There's heavy CPU usage post greylisting, greylisting is great, but wIting that 5-15 minutes for the retry is too long, most users don't use a password manager. Their password manager is the "I forgot my password" mechanism.
I was far too often adding whitelist entries, making certain clients ignore greylisting or drop down to 30 seconds, for which I saw no increase in spam. It's the return value on the severe that's set too high/long.
Eventually I ran out of granularity per user to set things how I wanted. Setting up a server for a subset of users was asking for trouble.
At some point you realize you have added aol, yahoo, gmail, etc., all the big guys, they need whitelisting because their IP's are huge, and ever changing. Keeping on top of which IP's they are publishing as public MTA based IP's, you hBe a solid whitelist able IP, but they change often.
AOL fully ignores greylisting last I looked. Most don't answer postmaster@ or abuse@ which are RFC required for postmaster and suggested strongly for abuse@.
Oracle ended up in spamhaus, after weeks, I finally got I touch with their admin. ( grind worked there, could not email him ) He'd ( Oracle MTA Admin ) been trying to figure it out for 4 months of bounced emails. How they never had a forwarded email from a bounce that shows the 5.5.0 code is all they would have needed.
But that poses another problem. You have to whitelist abuse@ and postmaster@ or the data you send them will trigger everything, anti-spam, and bounce. But then you get tons of spam, fully unfiltered on those two accounts.
Then there's DKIM and the rest plus the rest of the DNS based pseudo AUTH mechanisms. But those too are problematic. Some can't forward without bouncing, under SPF I believe. Oracle ended up in spamhaus, after weeks, I finally got I touch with their admin. He'd been trying to figure it out for 4 months or bounced emails. How they never had a forwarded email from a bounce that shows the 5.5.0 code is all they would have needed.
But that poses another problem. You have to whitelist abuse@ and postmaster@ or the data you send them will trigger everything from anti-spam and bounce. But then you get tons of spam, fully unfiltered on those two accounts.
In the end, I'm basically tailing logs, massaging them into a SNMP walkable data point so I can graph and chart. All to find out managing a mail server really is a near full time job. Add a secondary and it's even worse as spammers will direct target your mx2 Which means filtering, whitelist, blacklist, greylisting, geographically separated, and network role separated ideally, etc., full parity on two physically disparate boxes.
I was pushing about a million messages a day across a few 10's of thousands of accounts, forwards, aliases, etc. all over Comcast business.
The upsides: 4 hour support window 24/7/365. Direct phone line that a person answers. That person is an engineer of some sort or will transfer you to someone. I've spoken to engineers that maintain DNS, mail, web, etc. you get as close to he source as possible and they know how to unpack a gzipped or tar'd log file batch if you can even get a contact address for them.
Sorry if there's duplication of content. Either something is up with HN or my phone is being my phone as usual. I apologize for the illegibility in places.
Anyone know if google at least does a better job. Some form of AUTH?
On OS X I can push ALL data through a VPN. Trouble is, it's based on a hostname. I put in anything from /* ( wild cards galore ), http://*, plus the SSL version and any other combination.
I, as well as many others, assuming Apple doesn't delete the thread from their support forums, have been trying to resolve this without running a separate dedicate VPN app that may or may not support auto-scanning type connections that tend to drop off and re-enable For now, 8+ years has never gotten VPN on demand triggered by a call to a hotname as the trigger. Calls from browser, shell, even higher level tools like dig, telnet, etc, do not instant AUTH a VPN connection. It has to be done manually.
If I could feel safe, a setting of, "any packet start of packet egress will stall the connection until VPN is up so zero Dara goes over a non VPN line. A VPZn should get around Sprint's idiocy in throttling video to 600k meaning once you add in audio, 320 is probably the best resolution you will be getting. With a VPN they should not be able to detect the traffic. I'm thinking VPN with all love pointed to a log server remotely stored and that nukes logs pretty quick or send logs to /dev/null but that may make debugging hard.
Edit: tons of spelling, grammar, and additions for clarity—mobile is really a terrible platform for typing ore than what you push to trigger. :)
OT: with the proliferation of xfinitywifi, I have joined at my home when the internet was down on one channel but the xfinitywifi worked. Now I notice when I am out and about, I auto join any wifi named xfinitywifi.
Is it now that simple? With most having joined Xfinitywifi at some time, I can just buy a cheap router, give the SSID xfinitywifi, and people will auto join and I can middle them all day long?
I think one of the main issues with DB is that it is too little space and too much cost to add more. Considering what they pay for bandwidth, any paid plan really should be unlimited.
She said she supports herself on tours, five more music away, you should get more people at her tours. Same for the new band, you don't get discovered on the radio, 5K and they will play your song, it's that easy. Never works.
Play shows for 5 - 10 years, you may make it, or be coached and molded like Taylor, that Canadian Kid, and the ret of them.
In reality, an anti depressant for example, probably works out to something like: it works about 50% of the time, with a bit of a lean over 50%, but if we calculate in spontaneous remission, placebo effect, and some other variable, now it looks like it is either a net zero effect, or in many cases, like AA meetings, statistically detrimental. But the general public will need a binary answer.
And I consider myself part of this general public, I just know there is more than meets the eye on anything, and in general I feel correlation and causation more often then not don't agree.
I don't personally agree with them, there are cases where not wearing them save you. Mt brother was tossed out of the windshield instead of getting crumpled into a small box of metal that was once a car.
Motorcyclists would be hitching a ride on a death trap if they were strapped, whereas, even at 50+ you can, if practiced, sort of roll out of a fall and you just slide on the pavement. You may get a little banged up but rarely a trip to the hospital. Impact another car or object and you are probably screwed, but I would say no more screwed than being in a car and getting tossed out the window at 50+mph.
I always felt it my decision to handle my life how I desire, so if I want to die and don't care, I can not wear my seatbelt, if they catch me, I am happy to pay the fine.
I have since long ago just started wearing it as every car I get into I get told to put it on, so it has just become habit. But I hate the way they ride on my neck, tighten on my stomach, and are generally restricting and uncomfortable. I spend more time adjusting with my eyes off the road than is probably safe, and this can't be don't pre-driving as belts tend to creep up on my like a loose pair of underwear :)
There is a How it's Made episode on school busses that explains it in short detail.
I can say, in my area, public transportation has never had sear lets, and do not to this day. The school busses are still all very old, and I doubt they have them. They did not when i went to school, and I don't see retrofitting them without full seat replacements as they are designed to break away and assume you are not connected to the seat.
I then later, many years later, was given a Mac Plus. I could use BBS software to chat, but remember thinking, it is very hard to even type a conversation back and forth to a user elsewhere with a modem. There really was no software for it, or if there was, it was hard to find or even know about.
How did you know to learn C and then get a compiler? And how did you afford the software to develop back then? Wasn't code warrior around several thousand?
I would like an app like this in the event I ever need to prove my location. And I think it would be cool to see where I go on a map.
I always wondered why there was a separate layer for VPN's when you can so easily use ssh for a VPN at least for a secure way to use the internet. I suppose if you want it for the act of "being" on a remote network as if you are local is a VPN advantage, but I'm pretty sure ssh has a way to make that happen as well.
If I get this correct, it is a good idea to use ssh as a chat app's security methods?
function secondsSince (when) {
var now = new Date ();
when = new Date (when);
return ((now - when) / 1000);
}
I'm assuming now returns seconds since some fixed point in time ( epoch ) when when someone passes in the 'when' argument, it must already be formatted a certain way, or node/js somehow managed to figure out the input? How would it deal with 5/8/2015 vs 8/5/2015Or this is just a very case specific function and the input is already sanitized in a way that is prepared for this function?
github is here: https://github.com/scripting/pagepark/blob/master/lib/utils....