Jules Verne Forum

<jvf@Gilead.org.il>

[Email][Members][Photos][Archive][Search][FAQ][Passwd][private]

Re: I am sorry to state that the forum has become a target for scammers

From: Richard Gombert <rgombert~at~yahoo.com>
Date: Mon, 16 Aug 2010 05:58:50 -0700 (PDT)
To: Jules Verne Forum <jvf~at~gilead.org.il>


I agree with leaving the list as it is.

I personally have not seen any spam come across from the jvf~at~--- address. This
would lead me to believe that a system with the list address stores was hacked
and then the email address was spoofed.

Re: Norm's email. I maintain several email addresses. On is just for Banking and
Financial services, one is for list memberships, another is for family, and one
is for general usage. I get spam on the latter, but very little (or none) on the
others.

Cheers,

 Richard Gombert
Yahoo Mail Account rgombert_AT_yahoo_DOT_com
=========================================================================
It's such a cloudy day I can see myself tomorrow
Seems we'll never see the sun, a little further down the road
and still the day has possibilities - Dave Cousins
 - With apologies to Neal Peart "Further Down the Road"


                     good friends help you move books!


                  Rusted and ropy. Dog-eared old copy.
                  Vintage and classic, or just plain Jurassic:
                  all words to describe me.
                      - Ian Anderson "The Dog-ear Years"
=========================================================================
READ CAREFULLY. By reading this email, you agree, on behalf of your employer, to
release me from all obligations and waivers arising from any and all
NON-NEGOTIATED agreements, licenses, terms-of-service, shrinkwrap, clickwrap,
browsewrap, confidentiality, non-disclosure, non-compete and acceptable use
policies ("BOGUS AGREEMENTS") that I have entered into with your employer, its
partners, licensors, agents and assigns, in perpetuity, without prejudice to my
ongoing rights and privileges. You further represent that you have the authority
to release me from any BOGUS AGREEMENTS on behalf of your employer.
=========================================================================




________________________________
From: Nadav Har'El <nyh~at~math.technion.ac.il>
To: Jules Verne Forum <jvf~at~Gilead.org.il>
Sent: Sun, August 15, 2010 3:02:55 PM
Subject: Re: I am sorry to state that the forum has become a target for scammers

On Sat, Aug 14, 2010, Harry Hayfield wrote about "I am sorry to state that the
forum has become a target for scammers":
> Could I ask whether it is possible to remove the e-mail addresses from the
> membership roster on the website and only have them available to actual
> members (with several criteria: for instance member for more than 12
> calendar months who has posted at least one a week in the first year on
> purely Vernian topics)?

Hi,

As the person who (after my father's death) has been looking after this
mailing list, I thought I should reply and explain the situation, as I see it,
and look for advice from the forum members.

When he set up the forum, my father, Zvi, tried to strike a balance between
avoiding spam, and keeping the forum open and friendly to everyone - current
subscribers, potential subscribers, and casual readers.

His first order of business was to get rid of the run-of-the-mill spam sent
to the list. You may not be aware of this (nor should you), but the list's
address (jvf~at~gilead.org.il) gets literally dozens of spam messages a day.
To filter these out, he used a simple measure: Whenever non-members posts,
their post gets held-up until a moderator (which in the last couple of years
was me) accepts it manually. Moreover, he decided that for foiling spammers
from subscribing-and-then-spamming, new subscribers will also be moderated
for a week.

The next spam problem that became apparent was that spammers could no longer
send mail *through* the list, but could send it directly to invidiual list
subscribers. They were crawling web sites, including JVF's membership roster
and the message archive (today spanning 13 years and around 13,000 messages!)
and collecting email addresses they find there. What my father did was to
use very simple counter-measures to foil these attempts: If you look at the
forum's archive you'll see that addresses like someone~at~somewhere.com were
replaced by "someone~at~somewhere.com", while in the membership roster,
the "~at~" was replaced by a picture of the "~at~" symbol. The idea was that humans
will easily be able to read the email addresses, while spammer's robots
couldn't.

These counter-measures always had two problems. First, they were vulnerable
to improvements in spammer technology: It is possible that spammers today have
crawlers which understand the phrase "~at~" or images replacing "~at~", which
they didn't have several years ago. The second problem is that it was always
vulnerable to human scammers, who can look at the list and easily pick out
addresses by hand.

Before we go around fixing the problem, if at all, we (the forum members)
will need to decide what balance we want to strike between openness and
privacy. I want to raise several issues that can be discussed:

1. Is the membership roster, http://jv.gilead.org.il/forum/members.html,
   which includes names and email addresses (and more), still considered
   a useful service to the public?
   I know I've used it in the past to look for an address of an individual
   forum member. Are people happy to appear on this list, or afraid of the
   consequences of being there?

2. If we attempt some "weak" protection of the roster (e.g., you need to be
   a member first), a dedicated scammer could easily circumvent it (by
   becoming a member) and see the roster anyway. Are we trying to avoid
   the common case, or avoid any email address leak in any way?

3. Do people consider it important, or desirable, to have email addresses
   on the forum's archives? The original intention was that someone that finds
   a message, say I find a 5 year old message in Google, could easily write to
   the person who wrote this message.

4. I can "strengthen" the obfuscation of email addresses (on the roster and
   in the archive) to make it harder for spammers to understand them. But,
   if I keep them readable to humans, human scammers will still be able to
   read them, and eventually, spammers will get hold of the address. Is this
   aceeptable, or must we avoid "leaking" email address completely?

Finally, I hope that everyone realizes that no matter what kind of
protection I set up for email addresses in the roster and archive, the
moment you actually *post* a message, you are sending your email address
to all other members. One of these members might be a lurking spammer, and
worse - there have been documented cases where virus writers specifically
wrote viruses which infect ordinary people's machines, and then send every
email address that this machine sees to the spammer for future use. This
way spammers can discover email addresses that have never been published
on the Internet, anywhere!

Because every counter-measure we come up with can be countered back by the
spammers (as explained above), in my opinion, the question is when do we stop
treating email addresses as secrets, and go (back) to treat them as completely
open. I've been using the same email address for 20 years, so by now every
spammer on the planet already has it. Whatever spams I get (probably several
dozens every day) are easily eaten by my spam filter, so why should I care?
And at the same time, I can remain calm and don't need to worry all the time
if my address "leaks" or not. It can't leak more than it already has ;-)

After this introduction, I'll try to summarize the options we have, as I see
them:

1. Regarding the membership roster, should we:
   A. Leave it as-is (lightly obfuscated addresses).
   B. Strengthen the address obfuscation but leave it human-usable.
   C. Make the roster readable only to members (and spammers who become members)
   D. Delete it altogether.

2. Regarding the list archive, should we:
   A. Leave it as-is (lightly obfuscated addresses).
   B. Strengthen the address obfuscation but leave it human-usable.
   C. Make the addresses readable only to members (this will be difficult...)
   D. Delete addresses altogether from the archive messages.

Am I missing any options? Which option do people prefer?

Thanks,
Nadav Har'El.

-- 
Nadav Har'El                        |         Sunday, Aug 15 2010, 6 Elul 5770
nyh~at~math.technion.ac.il             |-----------------------------------------
Phone +972-523-790466, ICQ 13349191 |Windows-2000/Professional isn't.
http://nadav.harel.org.il           |
      
Received on Mon 16 Aug 2010 - 15:58:59 IDT

hypermail 2.2.0 JV.Gilead.org.il
Copyright © Zvi Har’El
$Date: 2010/08/16 21:00:03 $$