Jules Verne Forum

<jvf@Gilead.org.il>

[Email][Members][Photos][Archive][Search][FAQ][Passwd][private]

Re: I am sorry to state that the forum has become a target for scammers

From: Chris Leather-jvforum <chrisleatherjvforum~at~yahoo.co.uk>
Date: Wed, 18 Aug 2010 13:26:18 +0000 (GMT)
To: Jules Verne Forum <jvf~at~gilead.org.il>


I don't comment much on the forum - but I like reading most of the messages. I have been getting upwards of 3-4 spams a day (sometimes more). From my point of view as soon as I saw that Harry had had the same email as me I created a web-based email (I use WebMail Notifier more often now) account and deleted my main email address from the listing. Since Saturday I think I've had 2 spam emails (compared to the 16 or so I might have expected). ________________________________ From: Peter Ikin <pacli22~at~hotmail.com> To: jvf~at~Gilead.org.il Sent: Wed, 18 August, 2010 5:05:54 Subject: Re: I am sorry to state that the forum has become a target for scammers Hi Nadav, Thanks for the work that you do behind the scenes that keeps the forum running smoothly. Over the years I've had a couple of scam emails and some spam in Hebrew that I think came from membership in the forum but it's no real problem. Like most posters so far I don't feel a need for a change. So I'm in favour of A on both counts. Thanks again, Peter > Date: Sun, 15 Aug 2010 22:02:55 +0300 > From: nyh@math.technion.ac.il > To: jvf@Gilead.org.il > Subject: Re: I am sorry to state that the forum has become a target for >scammers > > On Sat, Aug 14, 2010, Harry Hayfield wrote about "I am sorry to state that the >forum has become a target for scammers": > > Could I ask whether it is possible to remove the e-mail addresses from the > > membership roster on the website and only have them available to actual > > members (with several criteria: for instance member for more than 12 > > calendar months who has posted at least one a week in the first year on > > purely Vernian topics)? > > Hi, > > As the person who (after my father's death) has been looking after this > mailing list, I thought I should reply and explain the situation, as I see it, > and look for advice from the forum members. > > When he set up the forum, my father, Zvi, tried to strike a balance between > avoiding spam, and keeping the forum open and friendly to everyone - current > subscribers, potential subscribers, and casual readers. > > His first order of business was to get rid of the run-of-the-mill spam sent > to the list. You may not be aware of this (nor should you), but the list's > address (jvf@gilead.org.il) gets literally dozens of spam messages a day. > To filter these out, he used a simple measure: Whenever non-members posts, > their post gets held-up until a moderator (which in the last couple of years > was me) accepts it manually. Moreover, he decided that for foiling spammers > from subscribing-and-then-spamming, new subscribers will also be moderated > for a week. > > The next spam problem that became apparent was that spammers could no longer > send mail *through* the list, but could send it directly to invidiual list > subscribers. They were crawling web sites, including JVF's membership roster > and the message archive (today spanning 13 years and around 13,000 messages!) > and collecting email addresses they find there. What my father did was to > use very simple counter-measures to foil these attempts: If you look at the > forum's archive you'll see that addresses like someone@somewhere.com were > replaced by "someone~at~somewhere.com", while in the membership roster, > the "@" was replaced by a picture of the "@" symbol. The idea was that humans > will easily be able to read the email addresses, while spammer's robots > couldn't. > > These counter-measures always had two problems. First, they were vulnerable > to improvements in spammer technology: It is possible that spammers today have > crawlers which understand the phrase "~at~" or images replacing "@", which > they didn't have several years ago. The second problem is that it was always > vulnerable to human scammers, who can look at the list and easily pick out > addresses by hand. > > Before we go around fixing the problem, if at all, we (the forum members) > will need to decide what balance we want to strike between openness and > privacy. I want to raise several issues that can be discussed: > > 1. Is the membership roster, http://jv.gilead.org.il/forum/members.html, > which includes names and email addresses (and more), still considered > a useful service to the public? > I know I've used it in the past to look for an address of an individual > forum member. Are people happy to appear on this list, or afraid of the > consequences of being there? > > 2. If we attempt some "weak" protection of the roster (e.g., you need to be > a member first), a dedicated scammer could easily circumvent it (by > becoming a member) and see the roster anyway. Are we trying to avoid > the common case, or avoid any email address leak in any way? > > 3. Do people consider it important, or desirable, to have email addresses > on the forum's archives? The original intention was that someone that finds > a message, say I find a 5 year old message in Google, could easily write to > the person who wrote this message. > > 4. I can "strengthen" the obfuscation of email addresses (on the roster and > in the archive) to make it harder for spammers to understand them. But, > if I keep them readable to humans, human scammers will still be able to > read them, and eventually, spammers will get hold of the address. Is this > aceeptable, or must we avoid "leaking" email address completely? > > Finally, I hope that everyone realizes that no matter what kind of > protection I set up for email addresses in the roster and archive, the > moment you actually *post* a message, you are sending your email address > to all other members. One of these members might be a lurking spammer, and > worse - there have been documented cases where virus writers specifically > wrote viruses which infect ordinary people's machines, and then send every > email address that this machine sees to the spammer for future use. This > way spammers can discover email addresses that have never been published > on the Internet, anywhere! > > Because every counter-measure we come up with can be countered back by the > spammers (as explained above), in my opinion, the question is when do we stop > treating email addresses as secrets, and go (back) to treat them as completely > open. I've been using the same email address for 20 years, so by now every > spammer on the planet already has it. Whatever spams I get (probably several > dozens every day) are easily eaten by my spam filter, so why should I care? > And at the same time, I can remain calm and don't need to worry all the time > if my address "leaks" or not. It can't leak more than it already has ;-) > > After this introduction, I'll try to summarize the options we have, as I see > them: > > 1. Regarding the membership roster, should we: > A. Leave it as-is (lightly obfuscated addresses). > B. Strengthen the address obfuscation but leave it human-usable. > C. Make the roster readable only to members (and spammers who become >members) > D. Delete it altogether. > > 2. Regarding the list archive, should we: > A. Leave it as-is (lightly obfuscated addresses). > B. Strengthen the address obfuscation but leave it human-usable. > C. Make the addresses readable only to members (this will be difficult...) > D. Delete addresses altogether from the archive messages. > > Am I missing any options? Which option do people prefer? > > Thanks, > Nadav Har'El. > > -- > Nadav Har'El | Sunday, Aug 15 2010, 6 Elul 5770 > nyh@math.technion.ac.il |----------------------------------------- > Phone +972-523-790466, ICQ 13349191 |Windows-2000/Professional isn't. > http://nadav.harel.org.il |
Received on Wed 18 Aug 2010 - 20:52:26 IDT

hypermail 2.2.0 JV.Gilead.org.il
Copyright © Zvi Har’El
$Date: 2010/08/19 14:00:03 $$