Jules Verne Forum

<jvf@Gilead.org.il>

[Email][Members][Photos][Archive][Search][FAQ][Passwd][private]

Re: I am sorry to state that the forum has become a target for scammers

From: Peter Ikin <pacli22~at~hotmail.com>
Date: Wed, 18 Aug 2010 14:05:54 +1000
To: <jvf~at~gilead.org.il>



Hi Nadav,

Thanks for the work that you do behind the scenes that keeps the forum running smoothly.

Over the years I've had a couple of scam emails and some spam in Hebrew that I think came from membership in the forum but it's no real problem. Like most posters so far I don't feel a need for a change. So I'm in favour of A on both counts.

Thanks again,
Peter

> Date: Sun, 15 Aug 2010 22:02:55 +0300
> From: nyh~at~math.technion.ac.il
> To: jvf~at~Gilead.org.il
> Subject: Re: I am sorry to state that the forum has become a target for scammers
>
> On Sat, Aug 14, 2010, Harry Hayfield wrote about "I am sorry to state that the forum has become a target for scammers":
> > Could I ask whether it is possible to remove the e-mail addresses from the
> > membership roster on the website and only have them available to actual
> > members (with several criteria: for instance member for more than 12
> > calendar months who has posted at least one a week in the first year on
> > purely Vernian topics)?
>
> Hi,
>
> As the person who (after my father's death) has been looking after this
> mailing list, I thought I should reply and explain the situation, as I see it,
> and look for advice from the forum members.
>
> When he set up the forum, my father, Zvi, tried to strike a balance between
> avoiding spam, and keeping the forum open and friendly to everyone - current
> subscribers, potential subscribers, and casual readers.
>
> His first order of business was to get rid of the run-of-the-mill spam sent
> to the list. You may not be aware of this (nor should you), but the list's
> address (jvf~at~gilead.org.il) gets literally dozens of spam messages a day.
> To filter these out, he used a simple measure: Whenever non-members posts,
> their post gets held-up until a moderator (which in the last couple of years
> was me) accepts it manually. Moreover, he decided that for foiling spammers
> from subscribing-and-then-spamming, new subscribers will also be moderated
> for a week.
>
> The next spam problem that became apparent was that spammers could no longer
> send mail *through* the list, but could send it directly to invidiual list
> subscribers. They were crawling web sites, including JVF's membership roster
> and the message archive (today spanning 13 years and around 13,000 messages!)
> and collecting email addresses they find there. What my father did was to
> use very simple counter-measures to foil these attempts: If you look at the
> forum's archive you'll see that addresses like someone~at~somewhere.com were
> replaced by "someone~at~somewhere.com", while in the membership roster,
> the "~at~" was replaced by a picture of the "~at~" symbol. The idea was that humans
> will easily be able to read the email addresses, while spammer's robots
> couldn't.
>
> These counter-measures always had two problems. First, they were vulnerable
> to improvements in spammer technology: It is possible that spammers today have
> crawlers which understand the phrase "~at~" or images replacing "~at~", which
> they didn't have several years ago. The second problem is that it was always
> vulnerable to human scammers, who can look at the list and easily pick out
> addresses by hand.
>
> Before we go around fixing the problem, if at all, we (the forum members)
> will need to decide what balance we want to strike between openness and
> privacy. I want to raise several issues that can be discussed:
>
> 1. Is the membership roster, http://jv.gilead.org.il/forum/members.html,
> which includes names and email addresses (and more), still considered
> a useful service to the public?
> I know I've used it in the past to look for an address of an individual
> forum member. Are people happy to appear on this list, or afraid of the
> consequences of being there?
>
> 2. If we attempt some "weak" protection of the roster (e.g., you need to be
> a member first), a dedicated scammer could easily circumvent it (by
> becoming a member) and see the roster anyway. Are we trying to avoid
> the common case, or avoid any email address leak in any way?
>
> 3. Do people consider it important, or desirable, to have email addresses
> on the forum's archives? The original intention was that someone that finds
> a message, say I find a 5 year old message in Google, could easily write to
> the person who wrote this message.
>
> 4. I can "strengthen" the obfuscation of email addresses (on the roster and
> in the archive) to make it harder for spammers to understand them. But,
> if I keep them readable to humans, human scammers will still be able to
> read them, and eventually, spammers will get hold of the address. Is this
> aceeptable, or must we avoid "leaking" email address completely?
>
> Finally, I hope that everyone realizes that no matter what kind of
> protection I set up for email addresses in the roster and archive, the
> moment you actually *post* a message, you are sending your email address
> to all other members. One of these members might be a lurking spammer, and
> worse - there have been documented cases where virus writers specifically
> wrote viruses which infect ordinary people's machines, and then send every
> email address that this machine sees to the spammer for future use. This
> way spammers can discover email addresses that have never been published
> on the Internet, anywhere!
>
> Because every counter-measure we come up with can be countered back by the
> spammers (as explained above), in my opinion, the question is when do we stop
> treating email addresses as secrets, and go (back) to treat them as completely
> open. I've been using the same email address for 20 years, so by now every
> spammer on the planet already has it. Whatever spams I get (probably several
> dozens every day) are easily eaten by my spam filter, so why should I care?
> And at the same time, I can remain calm and don't need to worry all the time
> if my address "leaks" or not. It can't leak more than it already has ;-)
>
> After this introduction, I'll try to summarize the options we have, as I see
> them:
>
> 1. Regarding the membership roster, should we:
> A. Leave it as-is (lightly obfuscated addresses).
> B. Strengthen the address obfuscation but leave it human-usable.
> C. Make the roster readable only to members (and spammers who become members)
> D. Delete it altogether.
>
> 2. Regarding the list archive, should we:
> A. Leave it as-is (lightly obfuscated addresses).
> B. Strengthen the address obfuscation but leave it human-usable.
> C. Make the addresses readable only to members (this will be difficult...)
> D. Delete addresses altogether from the archive messages.
>
> Am I missing any options? Which option do people prefer?
>
> Thanks,
> Nadav Har'El.
>
> --
> Nadav Har'El | Sunday, Aug 15 2010, 6 Elul 5770
> nyh~at~math.technion.ac.il |-----------------------------------------
> Phone +972-523-790466, ICQ 13349191 |Windows-2000/Professional isn't.
> http://nadav.harel.org.il |
                                               
Received on Wed 18 Aug 2010 - 07:06:03 IDT

hypermail 2.2.0 JV.Gilead.org.il
Copyright © Zvi Har’El
$Date: 2010/08/18 18:00:03 $$