APLawrence - Information and Resources for Unix and Linux Systems, Bloggers and the self-employed
RSS Feeds Get APLawrence.com by RSS











(OLDER) <- More Stuff -> (NEWER) (NEWEST)
Home > News Posts > Spamassassin vs. whitelists
Printer Friendly Version




News Group Posts

Spamassassin vs. whitelists




From: "Ed Murphy" <emurphy42@socal.rr.com>
Subject: Re: Spammers LUV SpamAssassin
References: <slrnbkvnad.3ee.dhbrown@hobbes.dhbrown.net>
<biq0fk$lvg$2@pcls4.std.com>
<1954b.2181$Lk5.924@newsread3.news.pas.earthlink.net>
<bir1ko$vds$1@pcls4.std.com>
<7d84b.2300$Lk5.223@newsread3.news.pas.earthlink.net>
<slrnbl275s.1bf6.bit-bucket@localhost.config.com>
<cca4b.2526$Lk5.815@newsread3.news.pas.earthlink.net>
<bispnl$19i$3@pcls4.std.com>
<fwq4b.3824$Lk5.3575@newsread3.news.pas.earthlink.net>
<Xns93E94EE16FE8Fprjpp1516202119@210.49.20.254>
<slrnbl4s01.1cn.me@Athena.localdomain>
<QGu4b.4059$Lk5.195@newsread3.news.pas.earthlink.net> Date: Mon, 01 Sep 2003 06:51:07 GMT On Sun, 31 Aug 2003 22:31:12 +0000, Alan Connor wrote: > I have written a simple program that eliminates spam completely












You didn't provide URLs.  I can't imagine why; in your shoes, I
would stick 'em in my .sig, and otherwise trumpet them with alarming
regularity.  Anyway, here they are:

http://home.earthlink.net/~alanconnor/elrav1/elrav1.html
http://home.earthlink.net/~alanconnor/elrav1/files.html

Ack!  Why isn't it downloadable in .tar.gz format?  Your poor
presentation has just lost 90% of your potential audience!

Anyway, it appears to be a set of front-end scripts to procmail
that implements the following:

  1) Whitelisted senders are allowed
  2) Non-whitelisted senders are sent "Please reply to this with <key>"
  3) Messages with <key> become whitelisted

This is a valid approach (mostly, see next paragraph) - but look at
how you present it!  You could calmly explain the different approaches
used by SA and elrav1, and why you believe elrav1's approach is better;
but instead, you keep writing apoplectic rants.  Your poor presentation
has just lost another 90% of your potential audience!



This is a valid approach (mostly, see below) but IMO your /terrible/
attitude causes lots of people to refuse to listen to you.  Sorry, dude,
but stamping your foot and insisting the world come to your doorstep is
just /not going to work/.  You're going to have to actually learn a
modicum of diplomacy.  This is possible (provably; I did it).  No, it's
not always pleasant (I speak from experience there as well), but the
alternative 

Some Windoze viruses look at the victim's address book when forging a
From: line.  Such From: lines have a reasonable chance of being on
your whitelist.  (If you are their friend, then they might be yours as
well.)  Does elrav1 have any ability to detect forged From: lines?  (I
don't know; I'm asking.)

> You have an SA user with, among other things, what amounts to a list of 
> prohibited strings in the subject header and body. 
> 
> 
> Does he or she send this list to anyone likely to be sending them mail?

If any of my friends triggered enough of SA's heuristics that their
messages registered as spam, (a) I'd be very surprised and (b) I'd
re-evaluate whether they are still my friend.

> No. But they discuss it in public and semi-public forums with other SA users,
> don't they.

I assume you are referring to the publically disclosed list of heuristics
used by SA:

http://www.spamassassin.org/tests.html

Sure, a smart spammer could read that list and figure sneaky ways around
at least some of the rules.  But do they /actually do so/?  A quick
eyeballing of the rules, and of some of the spam I've received lately,
seems to indicate that they do not!

Have you *actually tested* SA on a plausible volume of e-mail?  How
about SA with Bayesian filtering activated?  You may still be able
to say "SA is not as good as elrav1" and be correct, but currently
you are saying "SA is terrible" and I suspect that's just not true.

> Want a list of spammers? Hit the archives and begin with searching for the
> string "MSP" and then "elrav1" which is what msp became after a major rework.
> 
> Focus on comp.mail.misc
> 
> Copy the headers from any posts that contain obviously unfair and unreasonable
> attacks on yours truly.

Unfair and unreasonable by whose judgment?  Yours?  You're biased.  First,
you have a direct interest in elrav1 (you're the author).  Second, at
least based on the posts of yours that I've seen in comp.os.linux.misc,
you are in a near-constant state of apoplexy.  "Follow my orders, you
idiot, or I'll subject you to the worst fate imaginable - I'll *killfile*
you!"  Terrible attitude, like I said earlier, and it's poisoning any
chance of elrav1 being given serious consideration.

For the record, I don't use any spam filter whatsoever.  I don't
particularly need one.  My typical daily mail volume consists of
several dozen messages from various mailing lists (which are sorted
into folders) and perhaps one or two dozen spams (which are left in
my inbox, and which take less than a minute to delete by hand).

I also haven't written any software comparable to either SA or
elrav1; it would take me at least a week to train up to the level
that I could do so.  If I did write such software, though, then
rest assured that I would pay the *utmost* attention to good
presentation - because my goal would be to write a program worthy
of widespread use, and actually get it into widespread use.

Maybe your goal is for elrav1 to be used only by those select few
users willing to ignore your apoplexy, overcome your lack of succinct
this-is-the-basic-concept explanation, and jump through your
wheel-reinventing hoops to unpack it.  If that is indeed your goal,
then your current approach is guaranteed to achieve it.

Oh, and if you feel like killfiling me, then don't waste your time
threatening me that you may do so.  (Unless you take pleasure in
writing such threats.  I suspect that this is the case.)  Just do
it and get it over with.  I'd consider it an honor.



If this page was useful to you, please click to help others find it:  

Your +1's can help friends, contacts, and others on the web find the best stuff when they search.

Comments?



Click here to add your comments



Don't miss responses! Subscribe to Comments by RSS or by Email

Click here to add your comments


If you want a picture to show with your comment, go get a Gravatar


cartoon
Versatile Site Map Generator $59.00
A1 Sitemap Generator

Have you tried Searching this site?

Unix/Linux/Mac OS X support by phone, email or on-site: Support Rates

This is a Unix/Linux resource website. It contains technical articles about Unix, Linux and general computing related subjects, opinion, news, help files, how-to's, tutorials and more. We appreciate comments and article submissions.

Publishing your articles here

Jump to Comments



Many of the products and books I review are things I purchased for my own use. Some were given to me specifically for the purpose of reviewing them. I resell or can earn commissions from the sale of some of these items. Links within these pages may be affiliate links that pay me for referring you to them. That's mostly insignificant amounts of money; whenever it is not I have made my relationship plain. I also may own stock in companies mentioned here. If you have any question, please do feel free to contact me.

Specific links that take you to pages that allow you to purchase the item I reviewed are very likely to pay me a commission. Many of the books I review were given to me by the publishers specifically for the purpose of writing a review. These gifts and referral fees do not affect my opinions; I often give bad reviews anyway.

We use Google third-party advertising companies to serve ads when you visit our website. These companies may use information (not including your name, address, email address, or telephone number) about your visits to this and other websites in order to provide advertisements about goods and services of interest to you. If you would like more information about this practice and to know your choices about not having this information used by these companies, click here.

g_face.jpg

This post tagged:

       - SCO_OSR5




Unix/Linux Consultants

Skills Tests

Guest Post Here