Advertisement
Promo

Online business Toolkit

Uncle spam needs you

Stefanie Olsen, CNET News.com CNet

Published: 05 Feb 2002 15:39 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Larry Kilgallen got so fed up with junk email that he finally decided to do something about it.

Kilgallen, a business owner, says he takes about five minutes each day to fire off email complaints to spammers and Internet service providers that relay their payload to his in-box.

"It's civic duty," said Kilgallen, who uses a free online reporting service called SpamCop to help filter the junk and identify the culprits. "It probably takes me 10 seconds to report a spam. But the only reason the filtering is good is through the people who report it."

The battle against junk email, or spam, has numerous allies: Legislators have enacted laws targeting it, trade groups have crafted voluntary guidelines to govern it, and software developers have created weapons of mass deletion to thwart it.

Last week, the US Federal Trade Commission said it plans to launch a "systematic attack" on deceptive email, including law enforcement action against spammers.

But as is often the case, the last line of defence lies with consumers like Kilgallen, who are increasingly using spam filters supplied by ISPs, Web-based mail programs and software developers.

Their self-appointed task is daunting. Last year, the number of spam attacks to mailboxes increased by nearly 200 percent, according to filtering company BrightMail. Spiritual-related email was the fastest-growing form of junk to consumer in-boxes.

Looking ahead, experts predict junk email will soon grow to incomprehensible volumes. Within four years, consumers can expect to receive an average of 1,400 pieces of junk email per day, according to Net researcher Jupiter Media Metrix.

So what's a Web surfer to do until the federal government outlaws the practice? One option is to grin and bear it; another is to embrace a growing range of desktop anti-spam tools.

Either way, spam veterans say Net surfers shouldn't expect much relief, noting that even the best filters have vulnerabilities.

"With every advance in spam filter technology, spammers constantly invent ever more ways to circumvent filters," said Steve Linford, director of the London-based Spamhaus Project.

Sisyphean task
That hasn't stopped software developers from trying.

The onslaught of unwanted email has inspired many types of filter tools, including email forwarding services, software plug-ins, and built-in filters for Web-based mail such as Yahoo! Mail or for applications such as Microsoft Outlook.

Emailias, launched last fall, is designed to shield a consumer's primary email address from spammers. Emailias or other services, such as SpamMotel or Mailshell, allot an unlimited number of fake, or alias, addresses for the consumer to use when filling out forms, posting to newsgroups or signing up to mailing lists, where they can subsequently be "harvested" by spammers.

For $4.95 per month or $19.95 per year, Emailias' plug-in sits in a browser's "favourite links" or on its task bar. When consumers are asked for an email address, they can click on the link to retrieve a pop-up window with an address specialised for that page.

Email sent to that address is forwarded to the consumer's primary account. Subscribers can discontinue the address at any time -- for example, when an e-commerce company sends unsolicited mail from "partners."

Another tool, Novasoft's SpamKiller, costs $29.95 and is one of the most popular tools at Download.com, a site run by CNET Networks, publisher of ZDNet UK.

Among other filtering techniques, the software lets consumers block messages by the sender's address, message subject or headers, and message text. For example, customers can dump all email with the words "make money from home" within it.

SpamCop, Kilgallen's choice, costs $3 monthly, with a free service for reporting spammers. It filters mailboxes based on "whitelists," or a list of acceptable addresses to receive mail from, and "blacklists," unacceptable sources of mail. The service filters the IP addresses used by rogue marketers in real time so complaints may help improve the filters. With the account, subscribers also get an alias address.

Even with regular filter updates or new blocking inventions for consumers, however, spammers often find a way to infiltrate the most guarded in-boxes.

A method called "harvesting" involves scraping email addresses posted in newsgroups or message boards, from which the spammer compiles a bulk-mailing list.

"Nefarious people have created robots to go and harvest your email address from discussion groups and then spam you," said Paul MacIntosh, chief technology officer of New Jersey-based Emailias. "Normally, an address will get tainted, and there's no way to take back that address or stop the spam other than changing that address."

Spammers may also use what's known as a "dictionary attack" in which they guess every possible user name in a domain.

On the opposite extreme, spam filters are frequently accused of being overly zealous in weeding out email, capturing good messages along with the bad. Filters have been known to redirect email from a company's help desk from the in-box into a "killed" email box, for example.

Thor Ivar Ekle, creator of SpamKiller, admitted that his system is designed to catch 97 percent of mass emails, including help-desk mail.

Some consumers say that this is reason enough to declare spam filters a failure.

"I have plenty of client filters, and I still see lots of spam slip right through...and lots get trashed. It's a losing battle from the consumer side. It's in the hands of the ISPs," said one woman who is a self-professed spam fighter.

A higher-level solution
Three years ago, most ISPs saw spam filters as dangerous or censorious because they could block valid email. But in the last two years a dramatic rise in spam and complaints from customers has prompted a shift.

Now, behind the scenes, many Net access providers and anti-spam agents are labouring to block spam from moving through Internet pipelines. The all-hours battle is costing ISPs an enormous amount of time and resources. Last year, the European Union estimated the global cost of spam at $8bn annually.

"The ISP industry attitude changed from 'We won't filter spam' to 'Which filters shall we use?'" Spamhaus' Linford said.

America Online calls junk email "public enemy No. 1" on behalf of its 34 million subscribers. Despite its in-house spam team working to block known bulk mailers and the plethora of filtering options it gives consumers to manage email, AOL spokesman Nicholas Graham said commercial email still manages to creep into mailboxes.

ISPs such as EarthLink, MSN, AT&T WorldNet and Verizon Communications have enlisted spam-filtering software from San Francisco-based BrightMail to help shield consumers from bulk mail. About a third of ISPs also use block lists based on the worldwide DNS (domain name system) to refuse spam at their mail servers before it gets into subscriber mailboxes.

Well-known blocklists from groups such as the Mail Abuse Prevention System and Spamhaus work to keep track of IP addresses used to send spam, in an effort to block them altogether.

BrightMail's service, which operates a spam-detection center called BLOC, works by updating "mail rules," or filtering guidelines for the newest spam senders, every five minutes to seven minutes and sending them to customers.

Such systems are focused on trying to pinpoint patterns in incoming mail and filter based on repetitions and keywords.

But filtering systems that let consumers block email based on the wording contained within the message often fail because spammers are always tweaking language. For example, a consumer may set up a filter on "win a free car." But after using that terminology, the spammer might tweak the language to say "won a free car."

Some state laws, including those in California and Washington, give consumers some legal recourse against junk mailers, but many anti-spam advocates say they don't root out the problem. Because the laws require consumers to "opt out" of receiving junk mail, advocates say the action costs people more time than they have.

In some states, marketers are required by law to add the prefix "ADV:" to commercial e-mail. But spammers are learning to beat the system. They get around filters by using variations such as "[Ad V]" or "."

Marketers use such tactics because email is quickly becoming the lifeblood of sales.

Jerry Cerasale, senior vice president of government affairs at the Direct Marketing Association, said his organisation is trying to define spam and set guidelines for its 5,000 members to avoid bringing government regulations into the fold.

"It wouldn't be spam if the sender has had a prior business relationship with the consumer or he has joined a list" to receive sales pitches, Cerasale said.

Still, anti-spam advocates say such policies won't solve the problem anytime soon.

"The filter war is an arms race which neither spammers nor consumers can win and which can only be stopped by outlawing spam," Spamhaus' Linford said.


For everything Internet-related, from the latest legal and policy-related news, to domain name updates, see ZDNet UK's Internet News Section.

Have your say instantly, and see what others have said. Go to the Telecoms forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
24 out of 52 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Sentry Posts Blog

Motorola Droid Drops Today: Happy Droi...

Motorola Droid Drops Today: Happy Droid Day America! Author: Eric Everson, Mobile Security Expert If you’re wondering what all of the buzz is about with words like Droid and Android... More

Post a comment

Mobile Security Profile: BlackBerry St...

Mobile Security Profile: BlackBerry Storm2 Author: Eric Everson BlackBerry handsets are a staple of office culture; from syncing calendars to sharing business-related data,... More

Post a comment

South Korea plans to fingerprint visit...

The South Korean authorities could fingerprint and photograph foreign visitors from 2012, the Korea Times reported on Tuesday. Barring diplomats and government operatives, all visitors... More

Post a comment

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters