Re: Spam-Problem

Marco Colombo (marco@esi.it)
Thu, 19 Aug 1999 17:51:33 +0200 (MET DST)


I vote for a closed list: the list has been targeted with a very simple
attack, but it has been quite effective. David has been forced to change
the address, and someone will have to screen messages that arrived to
linux-kernel meanwhile. Note that the list will probably be subscribed also
to those list that require some kind of feedback, as the attacker can read
the list. Unsubscribing to hundreds of list can be a time consuming job.
Screening "real" lk messages from other lists messages will also take a while.
Nothing prevents the same guy to play the same trick with the new address.
Nothing prevents some other guy to use the list address as envelope sender
address for his 500000-target spam.

I think that even if the list will remain open, there should be some kind
of protection system ready to be activated by list managers in case of
attack. Closing the list for a few days may be the best thing to do.
Frequently posters will hardly note the difference, only non-members will
have their messages delayed a bit. Moderators will have the burden to filter
out unwanted messages, add new posters to the "allow list" (if needed), but
since 95% of the messages will pass through automagically, it won't be that
hard, and it has to be done only for a few days.

If attacks are frequent, just keep the list closed, and find a way to
better share the load of moderating it.

We redistribute lk locally, so none of us will have a From: header with
the same address we are subscribed with. On the other hand we usually
just read, so some filtering won't be a problem. Anyway, the "allow list"
should be different from the list of subscribed recipients.

BTW, moderators add some other value to the list: messages which are clearly
off-topic will receive a standard reply. The same for those that contain
only FAQs. Whether or not to post the messages (and replies) to the list
is a just matter of taste (I prefer yes, so someone else can privately
send more detailed answers, or get involved in off-topic discussions).

.TM.

-- 
      ____/  ____/   /
     /      /       /			Marco Colombo
    ___/  ___  /   /		      Technical Manager
   /          /   /			 ESI s.r.l.
 _____/ _____/  _/		       Colombo@ESI.it

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/