The Washington Post has an article on an interesting new piece of malware.
Captchas are those weird little blocks with numbers and letters all jumbled up and fairly difficult to read. They are there to check whether the user is a human or a computer pretending to be a human. They essentially prevent hackers from automating things that server owners would prefer them not to automate.
An example is - when you sign up for a mail account you have to decipher the captcha so that you can have the email account. This is to prevent spammers from signing up with free accounts 100 or 1000 at a time and using them to send spam, repeating the process when they are shut down. captchas have a lot of negative points but they have been rather effective.
The new malware is essentially a picture of a blond lady who will do a strip show for you. The catch is that you need to decipher some captchas, for each one she has less and less clothing. This sounds like a nice trade-off but each captcha that you enter basically signs a spammer up for a free email account. They are using you (being a human) as the middle man.
I hate spammers with a passion but I have to admit that this is a piece of genius.
Showing posts with label spam. Show all posts
Showing posts with label spam. Show all posts
Monday, November 5, 2007
Wednesday, July 25, 2007
spamspamspamspam...pdfs..baked beans...spreadsheets and spam!

It seems that everyone is reporting on new spam techniques. But here goes anyhow:
Spammers are using pdfs and zipped up excel spreadsheets to send spam.
This is not really all that surprising because traditional spam checkers don't look inside these kind of documents or block based on whether a mail has one.
So, its back to the drawing board for spam blockers, they need to check pdfs.
The scary thing about this is that the risk for false positives is much higher with a pdf or office document (I doubt that excel will be the only spam transport chosen) because genuine business documents are usually in these formats.
If you are a broker and someone sends you an excel spreadsheet of their stock picks and you miss it because your spam checker thinks it may be "pump and dump" spam - you could end up in a lot of serious trouble.
Spam is horrible stuff but there obviously is a market for cheap Viagra with no prescription.
Thursday, February 8, 2007
Intra-company PreCommunication Policy Exchange
You heard it here first!
I'm sure that someone out there is going to try patent this idea so let me put it out on the Internet first. I'm not interested in the patent - if I make this I'll try my best to be the best and beat competitors that way.
Right - I will try explain this in simple terms.
(As I see it) The problem with mail these days is
Then companies saw this marketing opportunity - free mail! And decided to abuse it. Hence spam. Now everyone only relays their own mail. And we still have spam.
The other issue with mail's naive beginnings is that anyone could pretend to be anyone. It was based on trust. After the first few times of pretending to be someone else the fun wears off. Not for spammers - they need to pretend to be someone else all the time. Otherwise they would be simple to block and everyone would except for idiots who want to lose money on the stock exchange and make up for it with huge..well... pfiser's blue pills.
Wouldn't it be great to be able to only receive mail from companies we deal with? I think so. setup an information account that can still receive spam and all sorts of junk but have regular users only get mail from companies that are trusted.
The other issue is that email was just for fun - first for geeks, then for cool geeks, the for cool people (like wow!) and then for the man in the street (and his tech savvy kids). Then more and more business people saw the advantage of cheap and quite written communication - untrusted as it was.
And more business information was exchanged over email. As information decided it wanted to stay as bit and bytes and not ink spots on a page the definition of "document" as a piece of paper became increasingly wrong. (I remember a story about this - I will put it in my next post). The laws became wrong and they were changed. South Africa made a new law called the "ECT Act" which mainly extended the definition of "documents".
The law was slow to recognise email as a legitimate business tool but so were the geeks. Email today is the same as email of when it was not important to business. All of a sudden email was important - deals could be made through email. Decisions could be made. Companies could be sued. People could be fired. All through a medium that can be very easily spoofed or lost. How does one know exactly who sends an email? You can't, not easily. Not yet.
So companies have been scared of the laws and scared of the power email has the disclaimer was born. The disclaimers used to say "if you are not the intended recipient of this email - destroy it and forget what you have read,please". Now they are more complex but they say "if you are the recipient of this mail and we have written anything that we may want to take back at a later stage - we can!". I know a company that says the above and adds "The law that makes this a document - ignore that law". Its a technology company.
But then what is the point of email?
I think that it would be a great idea to work out all the companies that your company emails. This may be a mission at first but I doubt it would be as bad as people may think. Then work out what sort of relationship you have with the company. Make out a few contracts - one for suppliers, one for once-off-suppliers, one for customers, etc. Then approach them and ask them to enter into a contract. I will provide an example contract soon. Once that is done - no need for spam checking.. just have a white list. No need for disclaimers. You want to do ordering through email and have it binding - perfect - it can be done legally and (now) safely.
More on this soon.... but, remember, you heard it here first!
I'm sure that someone out there is going to try patent this idea so let me put it out on the Internet first. I'm not interested in the patent - if I make this I'll try my best to be the best and beat competitors that way.
Right - I will try explain this in simple terms.
(As I see it) The problem with mail these days is
- Spam
- Contract law
Then companies saw this marketing opportunity - free mail! And decided to abuse it. Hence spam. Now everyone only relays their own mail. And we still have spam.
The other issue with mail's naive beginnings is that anyone could pretend to be anyone. It was based on trust. After the first few times of pretending to be someone else the fun wears off. Not for spammers - they need to pretend to be someone else all the time. Otherwise they would be simple to block and everyone would except for idiots who want to lose money on the stock exchange and make up for it with huge..well... pfiser's blue pills.
Wouldn't it be great to be able to only receive mail from companies we deal with? I think so. setup an information account that can still receive spam and all sorts of junk but have regular users only get mail from companies that are trusted.
The other issue is that email was just for fun - first for geeks, then for cool geeks, the for cool people (like wow!) and then for the man in the street (and his tech savvy kids). Then more and more business people saw the advantage of cheap and quite written communication - untrusted as it was.
And more business information was exchanged over email. As information decided it wanted to stay as bit and bytes and not ink spots on a page the definition of "document" as a piece of paper became increasingly wrong. (I remember a story about this - I will put it in my next post). The laws became wrong and they were changed. South Africa made a new law called the "ECT Act" which mainly extended the definition of "documents".
The law was slow to recognise email as a legitimate business tool but so were the geeks. Email today is the same as email of when it was not important to business. All of a sudden email was important - deals could be made through email. Decisions could be made. Companies could be sued. People could be fired. All through a medium that can be very easily spoofed or lost. How does one know exactly who sends an email? You can't, not easily. Not yet.
So companies have been scared of the laws and scared of the power email has the disclaimer was born. The disclaimers used to say "if you are not the intended recipient of this email - destroy it and forget what you have read,please". Now they are more complex but they say "if you are the recipient of this mail and we have written anything that we may want to take back at a later stage - we can!". I know a company that says the above and adds "The law that makes this a document - ignore that law". Its a technology company.
But then what is the point of email?
I think that it would be a great idea to work out all the companies that your company emails. This may be a mission at first but I doubt it would be as bad as people may think. Then work out what sort of relationship you have with the company. Make out a few contracts - one for suppliers, one for once-off-suppliers, one for customers, etc. Then approach them and ask them to enter into a contract. I will provide an example contract soon. Once that is done - no need for spam checking.. just have a white list. No need for disclaimers. You want to do ordering through email and have it binding - perfect - it can be done legally and (now) safely.
More on this soon.... but, remember, you heard it here first!
Subscribe to:
Posts (Atom)