I have just found this project, while updating info about us in
wikipedia.
We are doing something very similar; we build software that constantly
downloads stuff from spammer's websites trying to make it harder for
them to maintain websites.
we are a small group of friends that have started to do a project a
couple of days after bluesecurity has closed. I am wondering if there
is a way we can join forces...
we are now in the first beta stage (we have sent it to some other
friends to check how it works).
You are all welcome to take a look at http://www.spamdspammer.com/
Please let us know what you think and how we can join forces...
the idea behind our protection from attacks by spammers is based on the
following
1. The client will be placed on many different download sites (like
download.com, tucows,...)
2. The client comes with a metadata file (signed with a private key)
3. In the metadata file lists many different free sites that can
provide
a. Version updates
b. List of sites to attack
c. New metadata file
Everything is signed, so we believe it to be safe, and since we can use
as many "free host" to hold the metadata/list of sites to attack we
believe the system is very well protected
cheers,
Vish
I have just found this project, while updating info about us in
wikipedia.
We are doing something very similar; we build software that constantly
downloads stuff from spammer's websites trying to make it harder for
them to maintain websites.
we are a small group of friends that have started to do a project a
couple of days after bluesecurity has closed. I am wondering if there
is a way we can join forces...
we are now in the first beta stage (we have sent it to some other
friends to check how it works).
You are all welcome to take a look at http://www.spamdspammer.com/
Please let us know what you think and how we can join forces...
p.s.
I also agree. However....
>This is asking to get the men in suits kicking in
>your doors at 3AM.
The authorities are very well aware of the many and continuous attempts
at fraud, deception, solicitations to purchase pedophilic material,
illegal drugs and a hundred and one other illegal things that try to
gain entry to my inbox every day and so far they have done nothing
about
it. I suspect that that if they were to take me, or anyone, to task
over a few complaint emails, even if they were designed as a deliberate
ddos attack it would make the 6 o'clock news on the same day and they
would have a very difficult task when it comes to picking an unbiased
jury. So on balance I think you are being unnecessarily alarmist.
> Best of luck to your project,
Better still Vish, come and join us and remove the unnecessary
conflicts. It is the spammer whose time we want to waste not the local
police.
Maybe I should explain it a little better
We are not planning on doing DDos attacks.
We download bandwidth, but we set limits on the amount users can
download from a website.
The target is to make it harder to own a spammer website. While making
sure we don't kill the data center, hosting companies, or even shared
servers.
It is a little more similar to what Lycos did with their "make love not
spam"
We currently also have a lawyer checking for us the legal status of
such "attacks"
To the best of our current understanding, and the legal advice we have
received so far, this could be considered legal, we are still waiting
on some addition research
Our software will have many different attacks, we also intend to add
"BluesSecurity" like attack, our software client already support an
auto-update system, allowing us to extend it and add different
plug-ins...
What you wrote is basically what our lawyers said. That they doubt a
spammer would sue us or go to the FBI :)
As we wrote we do want to make sure that no bystanders get hurt and
this is why we have volunteers checking emails reported as spam and
this is why we put a limit on the potential overall bandwidth.
>>Better still Vish, come and join us and remove the unnecessary
>>conflicts.
That was exactly my reason for contacting this group the minute we
learnt about you; It would be great if we could find a way for joining
forces
>> It is the spammer whose time we want to waste not the local
>>police.
Well, I am not a big fan of the police, but you are right, I do believe
we only want to make a hassle for the spammers. But if we do make the
6-oclock news we hope it would add a couple of people to the cause.
Thanks
Vish
> What you wrote is basically what our lawyers said. That they doubt a
> spammer would sue us or go to the FBI :)
If it is of any interest to your lawyers it would appear that similar
opinions are shared by the rest of the world and personally I feel it
is something of a shame that it won't happen.
> It would be great if we could find a way for joining
> forces
I am a user and as such have little to do with the project at it's
current stage of development, except to add weight to the numbers and
offer ill informed opinion.
Take a full part in the relevant discussions, offer what you know
freely, be prepared for criticism and do bear in mind that those who
manage the project are there partly on the basis of a well expressed
paranoia gene.
.
Sure the spammers may not sue you, but the companies that are hosting
their websites may, or the ISP that the server's hosting the websites
may. The fact is what you are doing is illegal in most countries and
you are putting your users in risk. I am not saying I don't agree with
what you are doing personally, hell I would like to see people hack
their sites and such, but we can't just do stuff like that without
lowering ourselves to their level.
You claim to be "hackers" on your website, then you should know one of
the worst things you can do is advertise anything that will get the
feds snooping around you. They don't play around and politics can also
play a role in how much they want keep investigate you and your
operation. It is a dangerous game to play.
As I said before, best of luck to you guys. But for my part, that is a
dance I prefer to avoid.
So does Kaspersky.
Kaspersky does also.