By Jack M. Germain TechNewsWorld Part of the ECT News Network
06/10/04 6:37 AM PT
"The Can-Spam Act was never intended as a silver bullet, but it is an important and necessary weapon in a more comprehensive antispam arsenal," Scott Chasin, CTO of MX Logic, told TechNewsWorld.
Think you have to compromise on security to save on costs? Think Again. Trend Micro™ Enterprise Security, powered by the Trend Micro Smart Protection Network™, can lower your content security management costs by up to 40%. Find out just how much you’ll save with our TCO Impact Calculator.
Spam is stuffing consumer and corporate e-mail inboxes with useless pitches for unwanted products and services. It is also clogging bandwidth and contributing to traffic congestion on the Internet.
Experts estimate that as much as 60 percent of all e-mail that enters inboxes every day is spam, unsolicited commercial e-mail that targets e-mail addresses randomly created or culled from the Internet and mass-marketing lists. The problem grows worse with each passing month. Some security experts worry that, if left unchecked, business e-mail will become far less useful as a marketing and communications tool.
In Part One of our Spam Wars feature [Jack M. Germain, "Spam Wars: The Ongoing Battle Against Junk E-Mail," TechNewsWorld, June 8, 2004], TechNewsWorld explored what security experts fear will be the next generation of spam attacks. Our inboxes will most likely be flooded with more sophisticated junk mail attacks. These attacks will combine the worst of today's network worms with the newest tricks created by virus writers.
In Part Two of the Spam Wars feature, TechNewsWorld takes a look at other issues involving junk e-mail.
Can-Spam Laws Dented
After several years of failed bills to stuff spam into an e-mail can, Congress finally passed a compromise law known as the Can-Spam Act of 2003. Officially dubbed The Controlling the Assault of Non-Solicited Pornography and Marketing Act, the legislation requires unsolicited commercial e-mail messages to be labeled and to include opt-out instructions, plus the sender's physical address.
The federal law, which took effect on January 1, 2004, also outlaws deceptive subject lines and false headers in messages. The federal legislation overrides less comprehensive antispam laws in 35 states. Although not required to do so, the FTC is authorized to establish a "do-not-e-mail" registry. Plans for such a registry are several years away.
Are these Can-Spam rules really stuffing junk e-mail into the can? So far, no. But industry watchers admit that more time is needed for prosecutors to use the teeth congress put into the first-time antispam law. So far, there haven't been any precedent-setting cases against spammers who spawn sexually oriented e-mail or Viagra offers, or anything else for that matter.
Under this new law, state attorneys general, the FTC and ISPs can seek civil enforcement. The law provides criminal penalties for hacking and sender falsifications. But the Can-Spam Act cannot address spam sent from outside the United States where much of the world's busiest spammers are located.
"The Can-Spam Act was never intended as a silver bullet, but it is an important and necessary weapon in a more comprehensive antispam arsenal," Scott Chasin, CTO of MX Logic, told TechNewsWorld. "We firmly believe that continued enforcement of the law, industry cooperation on e-mail authentication, continued technological innovation and end-user education and empowerment will reduce spam."
MX Logic provides subscribers with a managed e-mail defense service. It also offers an e-mail defense gateway service for e-mail service providers. Technology solutions such as the one MX Logic offers will have to work hand-in-hand with any legal assault the Can-Spam Act can muster.
Spammers can easily churn out millions of messages per hour and more than 60 percent of Internet e-mail traffic today is Spam, noted Chasin. In addition, it is costly and difficult to uncover the sender's identity. Spammers are using increasingly sophisticated software that makes them even better at covering their tracks and harder to find, he said.
Education Is the Key
Jeremy Poteet, author of the soon-to-be-released book Canning Spam: You've Got Mail (That You Don't Want) told TechNewsWorld that consumers don't know enough about spam to prevent the problems it causes. Most people get spam and are not aware of the viruses they can contain. "They need to take steps to minimize the damage," he said.
Felix Lin, CEO and cofounder of Qurb, couldn't agree more. His company provides software to protect against spam, spoofing and e-mail fraud. "Most people are far too trusting when it comes to opening e-mail. Spammers take advantage of brand name recognition," he said.
MS Logix's Scott Chasin said it is essential that industry leaders and policymakers help educate consumers on how to protect themselves from unwanted e-mail, viruses and other threats. He offered four rules to handle junk e-mail.
First, never open e-mail from unidentified parties. Second, do not purchase products from companies or individuals with whom they are not familiar. The Pew Foundation recently reported that seven percent of Americans have purchased something from an unsolicited commercial e-mail. "Until spammers no longer have a ready market, they will continue to send their bulk messages," said Chasin.
Rule three is to be wary about giving out e-mail addresses where they can be harvested. The biggest sources of confirmed e-mail are chat rooms, personal Web sites and blogs. The last rule is perhaps the most important one for consumers, who should make sure that their ISP has an effective antispam solution in place to protect them. An effective system will give consumers a way to manage personal spam quarantines. It will also have an easy response mechanism to report any undetected spam and block it immediately.
Beware Hidden Dangers in Spam
MX Logic research has found that nearly half of spam is bugged with malicious scripts. To ensure an address is valid and ripe for future spamming, spammers embed "Web bugs" or "spam beacons" -- pieces of HTML code -- into their spam messages, Chasin told TechNewsWorld.
Spam beacons are a variant of Web bugs. Web marketing companies traditionally use them to measure page views and track Web surfing behavior. Once a user opens or even previews an e-mail containing an embedded spam beacon, it sends its signal back to the spammer, validating the address. Chasin said the spam beacon is a query or script string that can contain an encoded form of the recipient's e-mail address embedded in a Web request.
"Millions of users are unaware that spammers have the ability to track them when they view and open their e-mail. While Web bugs are not a new phenomenon to the Internet, MX Logic's data shows that nearly one out of two spam messages now contains these beacons. This reinforces the fact that spammers are using increasingly deceptive tools to invade end users' privacy and harvest valid e-mail addresses," Chasin said.
Old Internet Needs Makeover
The message is clear, according to security experts. Industry groups must work together to improve the security in e-mail protocols and identity management. Short of rebuilding the Internet protocol and infrastructure, spam and worm or virus attacks will never go away.
Chasin agrees with that view. SMTP is fundamentally insecure. As an open recipient protocol, recipients generally have to accept the e-mail that is sent to them, even when it is malicious or junk.
"So the short answer is 'yes.' Until the messaging protocols of the Internet are made more secure, e-mail and the computers of e-mail users will always be susceptible to a variety of attacks," Chasin said. "In the meantime, assuming that new protocols in the future would be sufficient to prevent these attacks, e-mail security will continue to involve four parts: technology, legislation, end-user education and industry cooperation."
Computer Glitches and the Windows Mentality June 10, 2004
In every single one of these cases, people's lives were affected while the news media devalued the consequences by describing entire event cycles as mere glitches. That's the Windows mentality at work; in the Windows world, there are no consequences to failure: just reboot and move on.
Related Stories
Spam Wars: The Ongoing Battle Against Junk E-Mail June 08, 2004
"We believe that technology is the most powerful tool against spam. Technology is critical not only to protecting end users from unwanted e-mail, but from protecting users from other, often more devastating e-mail threats, including viruses, worms, blended threats and denial-of-service attacks," said Scott Chasin, CTO of MX Logic, whose company provides innovative e-mail defense technologies.
Priority for Internet Users: Porn June 04, 2004
"This is one of the big, untouched research areas," Pew research specialist Mary Madden told TechNewsWorld. "For many reasons, it's incredibly difficult to get an accurate reading." Madden added that while it is an "incredibly thorny subject," the extent to which American Internet users consume pornography online is also "an incredibly important one."
Experts See Sharp Rise in Malware Attack Probability June 04, 2004
What worries Louis Cheng, spokesperson for Finjan Software security products, is how easily uninformed computer users become victims of spyware and other malware products. With the increase in threat levels, more damage will occur.
Sun Java Desktop System, Release 2 June 01, 2004
Java Desktop System 2 enables system administrators to set policies and configurations for individuals, groups or the entire organization, providing the ability to lock down user desktop systems.
Spamhaus Sets Up Shop in China June 01, 2004
According to a recent survey by Commtouch, a Mountain View, California-based maker of antispam software, in April alone, 71 percent of all URLs that appeared in spam e-mails were linked to Chinese Web hosts, with the United States a distant second at 22 percent.
More by Jack M. Germain
Microsoft FOSSifies .Net Micro Framework November 18, 2009
Microsoft has declared its .Net Micro framework open source under the Apace 2.0 license. Not all bits of .Net Micro are covered, however. Its TCP/IP stack has been stripped, as has its cryptography libraries. Rights to the TCP/IP stack aren't Redmond's to give, and the cryptography libraries are used outside of the scope of the .Net Micro framework, according to the company.
New Ubuntu OS Features Create Good Karma November 13, 2009
Amidst the OS upgrades from Apple and Microsoft over the last few months, the Linux OS Ubuntu got a version bump of its own. Ubuntu 9.10, or Karmic Koala, is well worth the effort to upgrade, and its developers have made the process easier -- if you're using the full-sized desktop/notebook version. The Remix version, intended for netbooks, caused quite a few headaches.
Samsung Chimes In With Bada Mobile OS November 11, 2009
With Android, iPhone, BlackBerry, WinMo, Symbian, WebOS and plenty other mobile platforms fighting for space, is there room for one more? Samsung believes there is, and it's announced a new open mobile platform called "Bada." The company, which already makes handsets for several existing platforms, says Bada will make app-making easy for developers. The first Bada handset should be out in the first half of 2010.