|
May 4, 2006Spam-Blogs + Ill-Prepared Hosts = Gated Futureby Joe Katzman at May 4, 2006 1:04 AM
Plagiarism Today has an excellent article about spamblogs, the problems faced by Google/Blogspot, its spread to MSN Spaces, and why this is likely to be a trend:
Yes. This has been a discussion topic on Winds following our (continuing) ban on blogspot.com in comments or trackbacks. Personally, I believe we're headed for a blog future in which owning your own domain will be the only viable option to avoid fairly widespread blacklisting. As the PT article notes:
I tend to agree; here's the whole piece if you want to read it. I see a future in which the free sites are training/experimental grounds, and the more all-inclusive ones like Blogspot or MSN Spaces are their own little gated communities, accepting each other's links but not accepted or accepting very much beyond that radius. That's sad, but the absence of meaningful penalties or enforcement against spammers makes it more or less inevitable. Tracked: May 4, 2006 8:00 PM
Junk futures from Thought Mesh
Excerpt: It looks like "other people are noticing":http://www.plagiarismtoday.com/?p=233 something I "posted about a few days ago":http://blog.thought-mesh.net/archives/2006/04/evolving_online_social_c.php (via "Winds of Change":http://www.windsofchange.net/arc...
Comments
Frankly, it's a problem of trust. The Internet was built on a model of complete openness and trust, and as someone who was on it before the Morris worm and spam and so on, it was wonderful. But it was unrealistic when placed outside of a controlled-access environment: the world is simply filled with assh*les, and we all have to get used to that. I believe that the Internet's life, as it currently is constituted, is quite limited. I think that there will be a successor with most of the following characteristics: - Low level transports (equivalent to TCP) featuring encryption as an option, and cryptographic signatures at each hop as a requirement, to provide privacy and non-repudiation (the latter being essential to stopping spammers) By building these features in to the communications stack itself, it is no longer necessary for every single site to be constantly fighting spammers and hackers - the network itself would remove the ability to hide (unless you trust anonymous connections, as some sites undoubtedly would), and would automatically squelch attacks or large-scale spamming. In other words, the network should be adaptive enough to take care of the vast majority of abuses that it does not make impossible. Joe those words are like music to my ears. I'm developing the a blog toolkit that works no matter what your domain is -- it's cross-domain. All the rest of the widgets lock you into a specific server. As the web becomes more "gated", there's still going to be a need for the domains to connect to one another, I believe. I can imagine groups of blogs -- flocks of blogs if you will -- all of people with similar interests. Tools are going to be needed to allow both the contributors and the readers to collaborate across domains. The problem with securing the network is that the web is built on anonymous communication. This goal is antithetical to coordinated usage, however. So there has to be a solution in which both goals are reached to some degree. I don't want spam, but I don't want to restrict folks in China from seeing and interacting with the real world either. It might all end up being team blogs. That seems to be very popular, and is a great way to keep fresh material coming out. Then perhaps the blog has some kind of admission test or registration that is controlled by the blog, not the hosting service. The hosting service could keep track of blacklists and such at the network level. On a personal note, I've been getting a boatload of spam from a hotm@@l this week. My hosting provider is offering a barracuda firewall for an extra three bucks a month, but I can't decide whether to get it or not. If I could turn trackbacks on, I might consider it. Does anybody have any experience with hardware firewalls/anti-spam devices and blogs? Daniel, we don't... And as folks might imply from the way he wrote it, (hot mail) is now on our blacklist for that very reason. Many of them were trackback spams, which means (since the service doesn't do web hosting) that they were EXPLICITLY SENT as nuisance spams. We've seen a sharp rise in that as well. Another brick in the wall. I might give it a shot and let you-all know. Any sort of hardware help couldn't be that bad. As I understand it, some of those hardware spam/spyware filters are getting very sophisticated nowadays. For $3, I'll have them hook it up and turn off my blacklist and turn on trackbacks. I'll let you guys know how it goes. Perhaps there is some help from all of this mess at the hardware level. I doubt it, but it doesn't hurt to try, right? Trackbacks are a particularly easy thing for spammers to exploit. Joe, if you're interested, I have a small Python script and basic explanation here which shows you just how easy it is to send a trackback ping. On that note, WordPress and its Akismet anti-spam plugin rock for preventing spams from trackbacks and comments. Movable Type is particularly vulnerable because of how badly exposed its trackback and comment scripts are to spammers. It is not where you are located. It is who do you trust. Software that integrates trust is the answer. White lists as well as blacklists. This is a subject I follow, and it seems to me that the primary impetus to colonize hosting services such as Blogspot is to evade the domain costs imposed by the efforts at domain banning. If you go back and read material a year or two old about junk, you will note one key theme was to increase junker costs by requiring them to cycle through domains, each of which costs money. What we are seeing now is a solution to that problem, where the junkers avoid the domain cycling costs by using someone else's domain. What I have seen in a few places is a requirement for a credit card, even if it is a free service. This makes the transaction sufficiently heavy weight to reduce the problem to acceptable levels. I suspect that is more the wave of the future than gated communities. MikeT; There are some simple tweaks to MovableType that (in my observations, at least) greatly reduce the amount of trackback junk. Basically, the TB interface is changed to use the basename of the post, instead of a numeric identifier, which stops junks from "running the numbers". It doesn't stop it, but it does seem to slow it down significantly. I'm not knowledgeable in this area of spamming, but I'm confused on how blogspot could be used for trackback spam when they require a CAPCHA entry for every new post. #10 knox has a very valid point. Since I started using the blog-spot provided turing test I have gotten one spam bit in 6 months. Before that I was getting around 10 a day. And even the 1 spam was manually entered. And it was hidden in a bunch of old spam I had not yet deleted. Joe - perhaps the answer is a better test. If we did web-of-trust I wouldn't have to obfuscate my blog URL (look at my blogparent). knox; One doesn't need to have any posts on blogspot to do trackback junk. The trackbacks are not sent from blogspot, but from other zombie machines via techniques similar to what MikeT describes. I should not post this, but then the odds of a novice spammer wandering across this instead of some other of the millions of web pages that have it are low. The way you defeat a capcha is to get the image and check the bitmap against a database. If there is a match, use that word. If there is not, put that into a list of capchas to be decoded. Then, send out spam emails to the list you've already bought or harvested, offering free porn with no charge: all you have to do is go to the handily provided URL and type in this word (at which point insert the capcha). When you get a hit at the URL, which conveniently has a number identifying which capcha was used, you take the "secret word" entered, and put it into the database for that capcha. Over time, you can get a pretty complete list of all of the capchas used at a given site. All for the cost of a web site (available free but for your time), a database (available free but for your time) a host to run the database ($1000 or less), a list of email addresses (you can use your database host to run a free harvesting bot), and a couple of porn CDs (less than $100 additional cost), or rip off free porn sites on the Internet already. Jeff, Neat trick. Now what if the capchas are changed at random for every post? You would have to keep your posting window open and it would have to be non-timed (i.e. if no post in x minutes a new capcha is called for) As I said - the one bit of spam I got looked like a guy being his own bot.
Post a comment
Here are some quick tips for adding simple Textile formatting to your comments, though you can also use proper HTML tags: |
You're Reading an Individual Post!
If you want to head to the main blog page, just follow the "Main" link in the navigation up top underneath our blog's name. Or click here:
Winds of Change.NET Home
Winds of Change Library
Support VictoryPAC
Recent Entries
· Hero Mouse
· A Few Reasons Why "The Ayers Argument" Isn't An Election-Winner · Speaking of Baked Goods · On Memory, Coincidence, And Missy Cross' D**n Good Banana Bread · In The "Trivial, But Funny" Department · Nostra-Armed Liberal Speaks · Tonight's Debate · Baseball: 9 = 4. · Levy: "Left In Dark Times" · Fun With History · As Long As We're Talking Business - Verizon, Chapter 2 · Shameless Product Plug · The Debate - L'Esprit d'Escalier · So The Debate Is Starting... · Berg v. Obama
Support Winds of Change.NET!
Your support & assistance is greatly appreciated, and makes a difference!
The Winds Crew:
Town Founder: Joe Katzman joe {at} windsofchange. net Joe's Normblog Interview Left-Hand Man: Marc 'Armed Liberal' Danziger armed {at} windsofchange. net A.L.'s Normblog Interview Other Winds Marshals 'AMac', aka. Marshal Festus (AMac@...) Robin "Straight Shooter" Burk 'Cicero', aka. The Quiet Man (cicero@...) David Blue (david.blue@...) 'Lewy14', aka. Marshal Leroy (lewy14@...) 'Nortius Maximus', aka. Big Tuna (nortius.maximus@...) Other Regulars 'Callimachus' (callimachus@...) 'Demosophist' (demosophist@...) Rev./Maj. Donald Sensing 'Molon Labe' (molon.labe@...) 'Neo Neo-Con' Tarek Heggy (tarek@...) Semi-Active: Arthur Chrenkoff 'Gabriel Gonzalez' (in Paris) Tim Oren (tim@...) Trent Telenko (trent@...) Posting Affiliates Athena: Terrorism Unveiled Chester: The Adventures of Chester Dave Schuler: The Glittering Eye Grim: Grim's Lair et. al. Joel Gaines [Russia] Michael Totten MILblogging.com: The MilBlogs directory Murdoc [Military] Situational Awareness team [Military] Nathan Hamm [Central Asia] Randy Paul [Latin America] Robert Koehler [Koreas] Robi Sen [India & S. Asia] Nitin Pai [India & S. Asia] Simon [China & E. Asia] Yehudit: Kesher Talk Emeritus: Adil Farooq (adil@...) Andrew Olmsted [KIA, Iraq] Celeste Bilby (celeste@...) Dan Darling Gary Farber (gary@...) Hossein Derakhshan (hoder@...) T.L. James (tljames@...) Robin Burk (robin@...)
Winds of Change.NET Blogkids & Affiliates
· The Argus: covering Central Asia · Canis Iratus: Glen Wishard · Correct-Amundo: Tech & society · Discarded Lies: Ev & Zorkie · The Flying Kiwi: Donovan Janus · The Glittering Eye: Dave Schuler · Gumptionology: Nortius Maximus · Hot Needle of Inquiry: 'Jinnderella' · Laughing Wolf: C. Blake Powers · Out The Mazoo: 'Mazoo' · Power and Control: M. Simon · Praktike's Place: 'Praktike' · Random Probabilities: Robin Burk · Siberian Light: covering Russia · The Spirit of Man · Good News From the Front · WATCH/: covering the war on terror
Archives By Category
-FEATURES: 48 Ways to Wisdom (24)
-FEATURES: Diaries & Roundups (10) -FEATURES: Military Transformation Uplink (12) -FEATURES: New Energy Currents (20) -FEATURES: Reader Highlights (2) -FEATURES: Regional Briefings (166) -FEATURES: Sufi Wisdom (158) -FEATURES: The Bard's Breath (32) -FEATURES: Winds of Discovery (6) -FEATURES: Winds of War [WoT] (445) 4 HA: 4th-Gen Warfare (103) 4 HA: al-Qaeda (159) 4 HA: Crime, Organized (26) 4 HA: Evil Exists (111) 4 HA: Intelligence/Spycraft (100) 4 HA: Military (530) 4 HA: Nukes, Poisons, Germs (135) 4 HA: Statecraft (29) 4 HA: War on Terror articles (708) Best Of... (180) BIZ: Business & Organizations (135) BIZ: Economics (99) BIZ: Energy (73) CIVIS (233) CIVIS: Copyright Wars (25) CIVIS: Drug Wars (18) CIVIS: Edu-Kooks (76) CIVIS: Free Societies (293) CIVIS: Hall of Shame (163) CIVIS: Hatred Rising (114) CIVIS: Journalism & Media (410) CIVIS: Spirit of America.NET (32) CIVIS: War Within the West (310) COLUMNISTS: M. Simon (13) COLUMNISTS: Tarek Heggy (33) GEO: Afghanistan (79) GEO: Africa (104) GEO: Asia (117) GEO: Aussies & Kiwis (20) GEO: Canada (70) GEO: China (87) GEO: Europe (182) GEO: France (71) GEO: India-Pakistan (113) GEO: Iran (223) GEO: Iraq (966) GEO: Israel (247) GEO: Koreas (64) GEO: Latin America (63) GEO: Middle East (256) GEO: Russia (83) GEO: Saudi Arabia (64) GEO: Sudan (36) GEO: U.K. (70) GEO: U.N. (60) GEO: U.S. of A (506) HUMANITY (88) HUMANITY: Art & Culture (160) HUMANITY: Art - Music (32) HUMANITY: Art - Poetry (6) HUMANITY: Christianity (53) HUMANITY: Heroes & Achievements (231) HUMANITY: History (126) HUMANITY: Islam (183) HUMANITY: Judaism (137) HUMANITY: Love (32) HUMANITY: Philosophy (49) HUMANITY: Spirituality & Religion (74) HUMANITY: Zen & Buddhism (28) Humour (198) Misc. (43) NET: Blogosphere (396) NET: Cyber-Security (16) NET: Grid Computing (3) NET: Spam (24) NET: The Internet (36) NET: The Open Source Meme (18) Personal (196) SCI-TECH: Biotech & Medical (83) SCI-TECH: Eco-tech (82) SCI-TECH: Nanotech (27) SCI-TECH: Science (112) SCI-TECH: Space (75) SCI-TECH: Technology (145) SPORTS (45) SPORTS: Baseball (76) Trends (65) USA: America Catch-all (19) USA: Anti-Americanism (6) USA: California Politics (8) USA: Conservatives & GOP (40) USA: Dem Party Renewal (76) USA: Domestic Issues (54) USA: Elections (111) USA: Grand Strategy (15) USA: Homeland Security (106) VictoryPAC (3) Winds of Change.NET (53)
Archives by Date
October 2008
September 2008 August 2008 July 2008 June 2008 May 2008 April 2008 March 2008 February 2008 January 2008 December 2007 November 2007 October 2007 September 2007 August 2007 July 2007 June 2007 May 2007 April 2007 March 2007 February 2007 January 2007 December 2006 November 2006 October 2006 September 2006 August 2006 July 2006 June 2006 May 2006 April 2006 March 2006 February 2006 January 2006 December 2005 November 2005 October 2005 September 2005 August 2005 July 2005 June 2005 May 2005 April 2005 March 2005 February 2005 January 2005 December 2004 November 2004 October 2004 September 2004 August 2004 July 2004 June 2004 May 2004 April 2004 March 2004 February 2004 January 2004 December 2003 November 2003 October 2003 September 2003 August 2003 July 2003 June 2003 May 2003 April 2003 March 2003 February 2003 January 2003 November 2002 October 2002 September 2002 August 2002 July 2002 June 2002 May 2002 April 2002 Joe's Old Archives, By Title: April - June 2002 July - December 2002
Winds Blogroll
Top Prospects
SP Normblog (LHP) SP Solomonia (RHP) RF Mader Blog CF Donklephant LF Harry's Place C Critical Mass 1B Tigerhawk 2B Gideon's Blog SS Alexander the Average 3B Democracy Arsenal UT INF Pundita DH Counterterrorism Blog PEN Liberals Against Terrorism CL Gates of Vienna MASCOT Huffington's Toast MGR Robert Tagorda GM Conservative Grapevine Humour Blogs
Support VictoryPAC· Cox & Forkum (cartoons) · Day By Day (cartoons) · User Friendly (cartoons) · Iowahawk (satire) · Scrappleface (satire) Religious Blogs · Conscientia (baha'i) · Unlearned Hand (bud) · Eve Tushnet (cath) · Muslim Under Progress (isl) · Ideofact (isl) · Kesher Talk (jew) · Rabbi Lazer Brody (jew) · Rishon Rishon (jew) · Rev. Donald Sensing (prot) Other Team Memberships · AlwaysOn [JK] · Blogcritics.org [JK] · Tech Central Station [JK] Blog Services< · NZ Bear's Ecosystem · Blogstreet · Daypop Top 40 · Technorati · Movable Type.org · New York Times Permalinks · Write A Better Blog |
http://www.windsofchange.net/windsopcentre-cms/trackback.cgi/6304
Listed below are links to weblogs that reference
"Spam-Blogs + Ill-Prepared Hosts = Gated Future"