Skip the navigation
)

Sidebar: The Dark Side of Blacklisting

By Kym Gilhooly
July 28, 2003 12:00 PM ET

Computerworld - When Chris Brown was working at Tivoli Software several years ago, the company took advantage of a black-hole list called the Open Relay Blocking System (ORBS) to fight spam. The list was eventually shut down, but not before Brown became disillusioned with the dark side of blacklists.
The reason for the disillusionment, he says, is that companies whose IP addresses were put on the list but were innocent of wrongdoing found it extremely difficult to get off the list. IP addresses typically get on the list when a blacklist's owners test and discover open-relay mail servers -- servers that are configured to relay mail on behalf of any sender -- or when mail administrators submit the addresses of mail servers they deem to be spam sources.
"At Tivoli, we toyed with blacklists, but we had numerous problems with customers trying to contact us for support and getting blocked, and that ended our foray into black-hole lists," says Brown, now a senior Unix systems administrator at Vignette Corp., a portal and content management provider in Austin.
The problem, he says, is that people can be overly aggressive when adding addresses to the system. For example, if a large company has a single misconfigured server reported to be an open relay, and that gets placed on a blacklist, its entire mail domain can be blocked, even if the company is entirely innocent of spam activity. Further, domains can get added after just a few reports of abuse -- a problem if someone is malicious or merely has incorrect information and reports it to a poorly managed list.
"Some blacklists have gotten into trouble because anyone can essentially report anyone else," says Matthew Berk, an analyst at Jupiter Research in New York. "The problem with this kind of community-based approach is that there can be network vigilanteeism. While it's a standard way of identifying people who've exhibited bad Internet behavior, getting off a blacklist is a nightmare."
Good blacklists, says Brown, share a number of traits. First, they establish a consistent set of criteria for putting an IP address on the list. Second, they rigorously test and retest suspect servers to verify the integrity of their databases. And third, they provide a process for domains to either prove they're on a list incorrectly or to correct what got them there in the beginning so they can be removed from it.
"Some services, such as ORBS, made it very difficult to get off the list. They also did a very poor job of retesting.There would be many servers that administrators had corrected that could not get off the list, and those companies would have trouble getting mail to customers, vendors or partners who used the ORBS lists," says Brown.
Today, he notes, blacklists are more trustworthy, and Vignette takes advantage of the ones configured in the PureMessage antispam software from ActiveState Corp. in Vancouver, British Columbia. "We can either enable or disable the RBL [real-time black-hole list] feature for various lists within PureMessage, and the product also allows us to subscribe to other lists as we see fit."
Gilhooly is a freelance writer in Falmouth, Maine. You can reach her at kymg@maine.rr.com.

Read more about Networking in Computerworld's Networking Topic Center.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Desktop Apps White Papers
Practice Management: Double Billing Rate and Improve Patient Services
Would you like to double your billing rate and achieve faster payment for services?

Download this customer success story to see how One Health...
Mission Critical Data Explosion and Customer Case Study
Would you like to double your tier 1 storage capacity while simultaneously reducing your storage footprint?

Download this customer success story to see how...
Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios
Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.
Database Activity Monitoring Is Evolving
Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.
Establishing a Strategy for Database Security is No Longer Optional
The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three...
All Desktop Apps White Papers
Desktop Apps Webcasts
Distributed Database Security with Real-time Monitoring
View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with...
InfoSphere Warehouse Packs Demo
These flash modules make warehousing more tangible and relevant to business users through detailed explanations of the InfoSphere Warehouse Packs.
Delivery Management -- Extending Lifecycle Management
Date: Wednesday, June 20, 2012, 1:00 PM EDT

Siloed organizations continue doing the wrong things and doing things wrong, leading to increased costs,...
Leverage automation today to reduce IT complexity
Date: Tuesday, June 5, 2012, 2:00 PM EDT

Whether your B2B complexity is caused by multiple technologies due to M&A, business or application specific...
Redefine Expectations in the Data Center
Need to do more with less? Watch this video to learn how HP ProLiant Gen8 servers can help your business deploy servers three...
All Desktop Apps Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs