BUT this only occured if the spamvertised site did not respond to an
initial request from BS for them to download their list scrubber app
and clean out their lists.
This then throws a warning and the onus to the spamvertiser to delete
Okopipi subscribed members.
As a separate function BS would report obvious frauds or illegal
operations to the appropriate authorities (to what success, who
knows?). Such frauds included pump and dump stocks, perscription only
medicines, pirated software and so on.
The automated form fillers for the spamvertized sites is the only thing
that gave the frog teeth - or poison if you like... This being the
achilles heel of the spamvertized sites, I wonder how easily spammers
could protect these sites from people who are demanding to opt-out, vs.
the few idiots who might actually be trying to order something from
them?
One method seems obvious - simply don't save/process form data that
does not contain a valid CC number. I'm not so sure that a LOT of
spamvertized sites don't do this already, and if the few who don't use
this filtering mechanism started to get bombarded with out-outs, I
don't think it would take long before they figured it out.
Anyone know how BS dealth with this? Perhaps they DIDN'T - perhaps they
only sent opt-out requests to sites where forms appeared to save some
data before actually asking for and processing credit card info.
Finding a way to get our opt-out requests beyond any filtering
mechanisms would seem to be an enormous challenge. Even if the valid
credit card issue could be overcome, it would seem that there would be
many other ways that complaints could be automatically distinguished
from real orders and complaints simply tossed in the bit-bucket.
Am I missing something here?
Failing that then may be an email address as a very last resort.
And if we really want to play dirty (not to mention illegal) there are
plenty of CC number generators out there. But hey I am not suggesting
we actually do this.
The other thing is this is a tit for tat scenario. One visit from the
client for each reported instance of spam in a members mailbox. As
mentioned this visit is to either the order form or the contact us form
or an email to a listed, and proven, email address.
Spoofing HTTP client details is a no brainer! No not a problem.
Although spammers probably get more spam than anyone else, and this
won't do anything but piss them off:
http://it.slashdot.org/article.pl?sid=03/07/07/1130226
Or will we have to be like that line from mississippi burning:
"these people came up out of the gutter, we've got to go down in their
to get to them", or something like that. It's a great line.
This can practically kill any automated form-filling application. In
fact, if the Okopipi network is impossible to bring down, I expect this
is exactly what will happen. It will rended the clients useless, and
will leave us nothing to do except DDoS these sites.
As for sending opt-outs via 'contact us forms' or email - good luck.
I've looked at a fair number of spamvertized sites to see how
complaints might be entered and found that very few of them have
mechanisms for contacting them. They are only interested in your name
and credit card number. There is typically no doorway to ask questions,
chit-chat, or complain.
Um, the implications of this statement are either hilarious or
depressing. You choose :P
However, that's underestimation: Don't forget there are many
influential people around the globe who for some reason or another keep
talking about things that perhaps are of no real impact upon them,
simply because they have some Messiah complex or whatever.
Newsreporters keep publishing articles about human rights violation in
China and other countries, so we have to accept the fact that someone
somewhere WILL talk about Okopipi (btw, in my native language, OKO =
Eye, Pipi is a childish adress to a hen :-) , and if we try to use
something even slightly illegal, they might hold us responsible and
liable. (Hope I'm using the right words, I'm not English and these
words can get confusing...)
So, my vote: We cannot use anything that cannot be successfully
defended at the court as "absolutely legal". Otherwise we would put our
own people at risk that one of them, someone who joined just to help
internet, would be caught and used as "the Example" of how badly you
might end if you mess up with law. There are still ways how to salt
someone's life and still being perfectly legal.
Than, at first we have to define the term "legal". Legal in which state?
Only US? That wouldn't be neither fair nor right, since this is an
international project. Europe? At least we don't have to fear the RIAA
or something ;)
Every country? Impossible. I bet there is always a country with a law
against this or that feature...for example in China it is completely
forbidden to visit some special "capitalistic" websites, afaik.
Second, which country should hunt us down for these lawbreaks? All of
them? This won't work. And what if, like the author of the quoted text
wrote, some journalists from a "foreign" state write about okopipi being
illegal in their country?
The best choice would be to make it legal for some state in Africa or
s/t, where they don't have any laws against internet-crimes ;)
just my 2 Cents
cu
stahlsau
> The best choice would be to make it legal for some state in Africa or
> s/t, where they don't have any laws against internet-crimes ;)
That's what the spammers do... "fighting fire with fire" is an
enticing concept, but something is to be said for "not stooping to
their level", too.
A form consists of several fields. The original discussion concerned
the spammers protecting "complaint-forms" with CAPTCHA, and BS
responded that opt-out request can be easily filled into "order-forms"
(I believe I saw an example where the script filled something like
this:
Name: You are sending unsolicited
Surname: bulk e-mail to adresses of the Blue Community
Adress: Please download the cleaning...
Order item 1: ...
...
...
of course, there is always the problem that the spammer could simply do
" delete from orders where name like 'You are %' "
(which would purge the DB of all such complaints)
I, too, would be willing to devote some time to this.
No, we couldn't. With 200 spams per day, no sane person will ever fill
200 CAPTCHA tests. But as I wrote in "I don't think it will work"
thread, OCR/ICR (Optical Character recognition and Intelligent
Character Recognition, the latter being use for hand-writing and
otherwise damaged or slanted letters) should work very well on this,
because spammers cannot employ the harder types of CAPTCHA, otherwise
their customers wouldn't be able to fill them correctly and thus
wouldn't buy anything.
Still haven't heard a good explanation on how you can get past a
requirement to enter a valid credit card number... If a valid card
number is not entered, then ALL of the data (our opt-outs) can get
tossed in the bit-bucket. I'm sure that the credit card companies don't
like getting flooded with bogus CC numbers, and that could leave us in
a very questionable legal position. SO... will Okopipi opt-out scripts
use valid CC numbers - and valid CC owner names? (I don't think so)
This concerns me because it means that our opt-out requests would
likely NOT be saved... Why would they save them? I'm sure they don't
want to be bothered reading through order-form data that contained no
valid payment for their crap!
Filling out forms with opt-out requests that never get saved or read
may create a traffic bottleneck - especially if many are done at the
same time. But, it's NOT going to be hassle for anyone or anything
aside from loading down their servers.
So, if we are trying to opt-out, but their forms won't let us, what do
we do?
Sooner or later, they'll have to find out that SOMEONE is sending them
valuable information. Their traffic logs will reveal the cause. I think
that's the only thing we can do.
UNLESS....
Remember Bart Simpson? He would give names to Moe and Moe would repeat
them aloud, and everybody would laugh at him.
So... here's the idea (muahahahaha *insert evil smirk here* )...
Name: Dawn. L'ad Dunot Intrudleest (sounds: Download donot intrude
list)
Address: Le Poisson Phrog Ave R. #33617
City: Okopippe town
State: Ma
Country: US
CC Number: (Insert valid but fake CC number here)
Here's others:
Ayem Anuyed Baijurs Pam (Sounds: I am annoyed by your spam)
P. Lisa S. Tapson Dingar Badge. (Sounds: Please stop sending garbage)
Jaur Cladding Aureen Pox. (Sounds: You're clodding our inbox)
Ree Movmee Fromm Eurleest (Sounds: Remove me from your list)
I think we can get imaginative enough to come up with one or two
hundred names, then we can use them. Notice that I used *REAL* names
and surnames in here (or at least words that have a meaning in at least
one language). Ayem... Lisa... Tapson, Dingar, Badge... Aureen, Fromm,
so they sound credible enough.
Why will it work: There aren't phonetic filters in spam. If the
spammers decided to filter the words, they might be losing potential
customers. Note that not only the names could be given the message,
also the street. So, we could have common names (John Doe) and adresses
like:
Unsoly zeted Lettars #25 (Unsolicited letters)
Donsenz paam #13 (Don't send spam)
Kleenup JoorLizts #140 (Clean up your lists)
Plis topmae linus #874 (Please stop mailing us)
Here we don't need as much imagination. Just mixing up the vowels and
consonants with equivalents. A program to do that is very easy to do.
Or we can even send blantantly fake names with the above streets, but
different numbers:
John F. Kennedy
Elizabeth Hurley
Reed Richards
Stan Lee
Nelson Mandela
Mahatma Gandhi
Indiana Jones
Lara Croft
But we should use diversity. Like, a percentage of users would use
phony names with the messages, other users would use the phonics
addresses, a minor percentage would use famous but fake names... and
another percentage which MUST be present would use the typical message
"Your are receiving this because".
This guarantees that at least some of the messages will pass thru the
filters.
also, i have seen many spam order pages using captcha, so we will have
to get around it somehow. alcator is right, no one is going to fill in
200 captcha tests a day, but i think a lot would fill in 10-20 a day,
which would take only a few minutes. they could come in Que from the
network and people could fill in others forms when they have time. I'm
not sure how this would work, as i am not extremely technical.
I would consider doing this. Like you I've seen captcha used on some
sites. I think there maybe enough volunteers to help in this way.
Technically, I doubt that this would be hard. But each person would be
able to fill in information for 1 email each time he compteted a
captcha.
Still, if we could on average do 5 per person, that would make a
difference. But if we are going to make things that labor intensive and
actually make people go to the site, we have already conceded to the
spammer what he wanted in the first place.
True.
The people working on this project are doing it for free. Spammers on
the other hand make a profit for what they do. You could say they get
paid for it, LOL, no matter how wrong it is. Anything we do here hurts
their livelihood. They will fight back. As we saw what happened to BS
(Blue Security).
I have no idea of what BS was doing but whatever it was, it was
working. For the first few months I didn't notice much at all, but
after that I saw a significant decease in spam I was getting. In one
email account the spam dropped next to nil. I can only guess why that
is (another topic) but whatever they did worked. Spammers fought back
and BS lost.
People here have decided to pick up where BS left off, from scratch,
the best I can tell. In the beginning when I signed into this group
- truth be told - I didn't take them seriously. Later I come to
realize they really are serious. They decided to take a bite out of a
very huge pie. They decided to fight back against the spammers.
If OKOPIPI is going to have any chance of winning this war, they will
need our support. You can't win a battle if you don't fight.
As has been said many times before, if you can keep the spammers from
cashing in on the spam; the spam will go away on its own.
Kind of like drugged up lab mice; always pressing the button for the
drugs, even in preference to food pellets.+