Auto-responders considered harmful
Published: Sunday 2003-12-14.
In an attempt to stop spam, some people have started using a system that require the recipient to confirm his or her existence for the first mail to be delivered (so called TMDA). This system is broken by design — the vast majority of spammers fake the sender address. I get a lot messages like this every day, and even though I have filters that will throw away most of them (many megabytes a week), several slip through.
From: heiligergeist@neworleans.com
Reply To: heiligergeist-msvmcf-1071100421.10249.70d1c0@neworleans.com
To: random characters @softwolves.pp.se
Date: 10 Dec 2003 23:53:41 -0000
Subject: Please confirm your messageYour e-mail message with the subject of "PAR1S H1LTON Movie - It shows her boyfriend sucking on he d pgwkr" is being held because your address was not recognized.
To release your message for delivery, please send an empty message to the following address, or use your mailer's "Reply" feature.
heiligergeist-msvmcf-1071100421.10249.70d1c0@neworleans.com
This confirmation verifies that your message is legitimate and not junk-mail.
[ This notice was generated by VisualMail 4.0 TMDA, an automated junk-mail reduction system. ]
I’d rather call it an ”automated junk-mail system”.
Something else that is very usual is the automatic bounce telling a person is on vacation. If it is badly configured, it will bounce all messages, including spam.
From: "Vipond, Jonathan" <
xxx@xxx.xxx>
To: Judy Hancock <random characters @softwolves.pp.se>
Date: Sat, 13 Dec 2003 10:25:36 -0500
Subject: Out of Office AutoReply: coalition check out this diet quad reI will be out of the office on Thursday, December 11, 2003 and Friday, December 12, 2003 on various client matters. I will have no or possibly limited access to email and will have my cellphone at
xxx-xxx-xxxxif you need to reach me. I will also check my voicemail occasionally atxxx-xxx-xxxx. If you need immediate assistance, please contact my assistant Linda Weibley atxxx-xxx-xxxxor atxxx@xxx.xxxor my colleague Jude Musselman atxxx-xxx-xxxxor atxxx@xxx.xxx. Thank you.Above email is for intended recipient only and may be confidential and protected by attorney/client privilege.
If you are not the intended recipient, please advise the sender immediately.
Unauthorized use or distribution is prohibited and may be unlawful.
A reasonable vacation bouncer will only bounce to trusted addressees, but both problems really stem from the same thing, that vandals are using the openness of the Internet to send their crap to everyone and his mother. In a perfect world, neither TMDA nor spam filters would be necessary, there it would be just as easy to stop advertisements in e-mails as in regular post (here in Norway I go down to the post office and ask for a sticker to put on my letter box) or telephone (adding myself to the list for people who do not want advertisements). Or, even better, I should have to ask to receive advertisements to receive any.
I am starting to feel that it is time to give up e-mail as a communications medium and switch to something else, something better. SMS, perhaps? But the messages there are a bit too short (and expensive), and it’s not free of spam, either. At least I haven’t received any advertising MMS messages yet, but I assume that will come, too :-(
In the news
- Sweden beat Norway in IQ test: Aftonbladet (Sweden); Dagsavisen (Norway).
- Scientists discover world’s oldest penis.
- Microsoft removes swastika from Office.
This entry is referenced in: The war on “anti”-spam software
,
Project
and
People on vacation
.
Categories: links, spam. Share: Facebook, Google+, email
Comments
The article is older than a fortnight and has been closed for new comments.
Disclaimer: The comments are copyrighted by their respective authors. The web site owner takes no responsibility for the contents of the comments. Improper comments will be deleted.
- Datum: 2003-12-15 08.32.32 CET
- Namn: Anders Carlsson
- Sänt från: yestravel.com
Vad värre är, många oerfarna datoranvändare litar till 100% på e-posten. Att det inte går att fastslå om mottagaren har läst, att det går att förfuska och luras i inkommande meddeladen osv brukar komma som en stor överraskning, gärna flera gånger om då man inte tror på sanningen när man får höra den första gången utan måste fråga igen.

Vad skulle vara mer effektivt än e-post i fråga om snabb kommunikation? Oavsett kommunikationsform kommer vi att få leva med att ljusskygga individer använder det för syften som förargar oss andra. En enhetlig lagstiftning världen över, där de stora internetleverantörerna betalar tjänster för att spåra avsändare av spam. Kännbara straff i fråga om fängelsestraff vore att föredra.
Peter svarar: Det är det som är problemet, jag vet inte vad som skulle fungera bättre. Men Internet-e-post som det ser ut nu fungerar uppenbarligen inte. Det finns redan flera projekt vars mål är att göra om e-post-infrastrukturen så att den blir mer motståndskraftig mot angrepp av den här sorten, frågan är bara om/när man lyckas ta ett nytt system i bruk.