Certainly it’s important to stop spam links, but if a site is genuinely the authoritative source on a matter it seems like it has earned and deserves its Google juice.
22 January 2007
04 May 2006
QDN: The dishonor of Blue Security
QDN: The dishonor of Blue Security
The cause of the Six Apart network outage the other day was an anti-spamming firm hoisting their problem on 6A’s servers.
04 October 2005
On Cillit Bang and a new low for marketers... (plasticbag.org)
On Cillit Bang and a new low for marketers… (plasticbag.org)
Marketing firm latches onto a story about someone reuniting with their father. Blech.
25 August 2005
TrackBack: A Tragedy in Three Acts
TrackBack: A Tragedy in Three Acts
Oh the geeky hilarity!
01 February 2005
Law Barring Junk E-Mail Allows a Flood Instead
Law Barring Junk E-Mail Allows a Flood Instead
Spam volume has increased by a third since the CAN-SPAM legislation went into effect.
19 October 2004
DomainKeys Versus the Spam Kingdom
As slashdot reported yesterday, Gmail has begun signing all its outgoing mail using Yahoo!’s DomainKeys. The system works like a very complicated wax seal. Imagine that I told everyone that I’d never send a letter without melting my seal onto it, and imagine that it’s impossible to duplicate my seal and only I have access to it. If you got a letter from me bearing my seal, you’d know I that it was from me and no one had already opened it. If you got a letter that didn’t have a seal, you’d know it might not be genuine. Google is the first major mail provider to support the technology (including Yahoo!, even though they invented it), but hopefully their backing will get other services to jump onboard.
An interesting consequence of this is that lots of legitimate services are going to start getting themselves into trouble. Say you read a news story you think a friend might find interesting. You might click their little “email this” button, fill out your name and address, their name and address, and click “send.” Many sites will send the email with your address as the sender. The problem is that you didn’t really send this email, the news site’s server did, and it’s just pretending to be you*. This doesn’t seem like that big of a deal, but generally I don’t want any email going out from my account if I didn’t actually type the message.
Since Gmail is now signing all of its messages with a domain key, you can be certain that any unsigned mail from a Gmail address was not sent by that address’s owner. In the above example, the email sent from the news site wouldn’t be signed, as it didn’t go through your email provider. Gmail has already started putting in a warning message whenever an unsigned letter comes in, so if you get a news snippet it might register as suspect because they spoofed your address. This is a good thing, because hopefully it’ll put the pressure on legitimate sites to stop spoofing.
Most email has very little security built in. Spammers use that fact to send out millions of messages using fake email address. Virus writers use that fact to send out malicious code using your address. From what I can tell, DomainKeys is a good, open service that anyone can use for free. If enough email providers jump on board, it could virtually eliminate spam.
*Yahoo! does this correctly. It sends all its mail from “refertofriend@reply.yahoo.com” and puts your address in the “reply-to” field. Many websites get it wrong, including the comment notification systems in Movable Type and TypePad.
16 December 2003
Spam Laws: CAN-SPAM Act of 2003
The President signed into law today the “Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003,” oh-so-cleverly known as CAN-SPAM. It goes into effect January 1, 2004. I’ll be interested to see how it works out.
11 November 2003
Kalsey's Comment Spam Manifesto
Comment Spam is becoming a problem for webloggers. Adam Kalsey has written a Comment Spam Manifesto declaring war on people who want to use our pages as advertisement and abuse our hard-earned Google rankings. While I haven’t yet been a victim of this problem, I sympathize with those who’re getting hundreds of fake comments a day. We run our websites because we enjoy them, and getting preyed on isn’t cool.
What worries me about the new war on spam is that it could lead to some legal troubles. If people really start going after alleged spammers and succeed in getting their ISPs to shut their sites down, a lot of lawsuits could spring up. What the weblogging world needs is a common comment spam policy. It needs to lay out exactly what an offending post will be, dictate what the host must be able to demonstrate in order to make a claim, and prescribe a list of conditions that must be documented. Likewise, it must also provide legitimate ways an innocent accused party can show that he didn’t do anything wrong. This policy should be something that lots of people agree on, freely distributed, and should be documented on every site that uses it.
Suggestions and TrackBacks are welcome (but not from spammers).