Re: For Alan Cox ...

From: Mike Coleman (mcoleman2@kc.rr.com)
Date: Thu May 11 2000 - 17:08:42 EST


willy@thepuffingroup.com writes:
> On Thu, May 11, 2000 at 03:59:29PM +0100, Mark O'Neill wrote:
> >
> > I am sending you response via Rutgers as it appears that you have an
> > "adminstrative prohibition" on yr direct mail!
>
> you're in ORBS. complain to your admin/ISP.

For what it's worth, I sent an email to my ISP (RoadRunner, which is heavily
ORBed), and received this reply in return. I'm hardly a RR partisan, but
their reply seemed a lot more reasonable to me than the attacks on the ORB
site.

In a nutshell, RR seems to be saying, we care about spam, but we don't want
external entities probing our customers' hosts. We'd rather handle it
ourselves. ORBS seems to be saying (on their site), anyone that won't let us
probe them is almost certainly incompetent or trying to hide something (i.e.,
that they're spamming, I guess).

If you're thinking about ORBS, you might want to consider whether the cure
isn't worse than the disease.

--Mike

From: "W. Mark Herrick, Jr." <markh@va.rr.com>
Subject: Re: question re ORBS
To: Mike Coleman <mcoleman2@kc.rr.com>
Date: Wed, 05 Apr 2000 13:08:32 -0400

Hello,

We are currently experiencing problems delivering email to some ISPs. This
is due to a manual block from the ORBS system of which those ISPs
subscribe. Although we have a thorough anti-SPAM policy and properly
address these issues, Road Runner has been manually added to the ORBS list
due to a request we made to the ORBS administrators. (see HISTORY) With
analysis and discussions with other providers, we believe that the impact
of the ORBS block is very minimal and easily corrected on a case-by-case
basis. We are currently only hearing 1 or 2 reports per day from our entire
customer base. We will take the information provided and work with each
provider to correct it with them directly.

I can assure you that the IP address that ORBS is currently blocking is in
no way an open relay, and that it is being blocked solely due to ORBS'
testing servers being refused at our border routers. Road Runner takes the
issue of open relay servers very seriously, and, in addition to immediately
closing them as they are detected, performs proactive relay detection
checks on its own network. Likewise, Road Runner also takes the issue of
unauthorized probes very seriously, and as such has taken steps to minimize
potential abuse from outside sources. Many other major Internet Service
providers, such as Above.net, have taken this stance along with us. You may
wish to take a look at http://www.orbs.org/hallofshame.html to see who else
is "spite listed" by the ORBS project.

Sincerely,
  W. Mark Herrick, Jr. <markh@va.rr.com>
       Operations Security Manager
      Team Lead - Usenet Operations
   Road Runner Security - 703.345.2477
<abuse@rr.com><security@rr.com><fraud@rr.com>

HISTORY:

Road Runner customers and Affiliates initially contacted us with a security
issue. They were concerned with their privacy and security when an unknown
entity (to them) began scanning them without permission. We initially tried
to address this case by case and later contacted the ORBS administrators
and requested this unwelcome scanning terminated. This is analogous to
someone requesting they be removed from a list that they did not subscribe
to. With this request, all Road Runner IP space was unexpectedly added to
the ORBS list with a public statement on the ORBS WWW site, as well as the
bounce message which our subscriber has received. As scanning continued
against our repeated requests, the individual ORBS scanning hosts were
filtered out of our network.

Although we strongly believe in stopping SPAM on the Internet, as well as
respect the initial work and charter ORBS has been under in the past, we
have serious concerns at the current methods and actions that are taking place:

e.g.
- Scanning of private networks without permission from targets
- No REMOVE capability from the ORBS scanner
- When someone tries to stop or block the ORBS scans, they are blocked by ORBS.
- No warning, as well as false public statements about the individuals
scanned or their provider. THAT IS: If you have a relay (known, or unknown
to you) you are called a SPAM supporter publicly without any warning to
correct it before ORBS adds you.
- Misinformation on ORBS' own web site
(http://www.orbs.org/whatisthis.html) "What is ORBS? The short answer: ORBS
is a validated database of open mail relays and open mail relay output
points, accessable via DNS lookup."
- The addition of Road Runner hosts to a "secret" database. Road Runner
hosts are not listed via their normal web lookup at
http://www.orbs.org/verify_1.html

Road Runner believes strongly in the fight against SPAM. We have address
it with strong policies, enforcement and our own relay detection
methods. We will continue this effort, work together with other providers
and the Internet community (including ORBS) to make a difference. However,
we reserve the right to assess the methods used, by whom and determine the
best way to accomplish the desired results for our business.

-- 
Any sufficiently adverse technology is indistinguishable from Microsoft.

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu Please read the FAQ at http://www.tux.org/lkml/



This archive was generated by hypermail 2b29 : Mon May 15 2000 - 21:00:18 EST