Ads by TechWords

See your link here
Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
 

Sidebar: The Dark Side of Blacklisting

July 28, 2003 12:00 PM ET

Computerworld - When Chris Brown was working at Tivoli Software several years ago, the company took advantage of a black-hole list called the Open Relay Blocking System (ORBS) to fight spam. The list was eventually shut down, but not before Brown became disillusioned with the dark side of blacklists.
The reason for the disillusionment, he says, is that companies whose IP addresses were put on the list but were innocent of wrongdoing found it extremely difficult to get off the list. IP addresses typically get on the list when a blacklist's owners test and discover open-relay mail servers -- servers that are configured to relay mail on behalf of any sender -- or when mail administrators submit the addresses of mail servers they deem to be spam sources.
"At Tivoli, we toyed with blacklists, but we had numerous problems with customers trying to contact us for support and getting blocked, and that ended our foray into black-hole lists," says Brown, now a senior Unix systems administrator at Vignette Corp., a portal and content management provider in Austin.
The problem, he says, is that people can be overly aggressive when adding addresses to the system. For example, if a large company has a single misconfigured server reported to be an open relay, and that gets placed on a blacklist, its entire mail domain can be blocked, even if the company is entirely innocent of spam activity. Further, domains can get added after just a few reports of abuse -- a problem if someone is malicious or merely has incorrect information and reports it to a poorly managed list.
"Some blacklists have gotten into trouble because anyone can essentially report anyone else," says Matthew Berk, an analyst at Jupiter Research in New York. "The problem with this kind of community-based approach is that there can be network vigilanteeism. While it's a standard way of identifying people who've exhibited bad Internet behavior, getting off a blacklist is a nightmare."
Good blacklists, says Brown, share a number of traits. First, they establish a consistent set of criteria for putting an IP address on the list. Second, they rigorously test and retest suspect servers to verify the integrity of their databases. And third, they provide a process for domains to either prove they're on a list incorrectly or to correct what got them there in the beginning so they can be removed from it.
"Some services, such as ORBS, made it very difficult to get off the list. They also did a very poor job of retesting.There would be many servers that administrators had corrected that could not get off the list, and those companies would have trouble getting mail to customers, vendors or partners who used the ORBS lists," says Brown.
Today, he notes, blacklists are more trustworthy, and Vignette takes advantage of the ones configured in the PureMessage antispam software from ActiveState Corp. in Vancouver, British Columbia. "We can either enable or disable the RBL [real-time black-hole list] feature for various lists within PureMessage, and the product also allows us to subscribe to other lists as we see fit."
Gilhooly is a freelance writer in Falmouth, Maine. You can reach her at kymg@maine.rr.com.



Additional Resources

POLL RESULTS
Accelerate your knowledge of the IT world you inhabit by viewing the results of a series of polls taken by your IT peers. These polls of 100+ IT professionals each are available for full viewing. They cover key topics such as virtualization, processor performance, green IT, cloud computing and many others. Be a part of the buzz.
WHITE PAPER
Technology is complex. Keeping it running productively shouldn't be. To that end, you want to minimize the number of solutions needed in-house to simplify operations, maintenance, and support. Kodak offers a best-practices model. One company provides support for both scanner and software, for fast problem resolution without vendor finger-pointing. Download now!
WHITE PAPER
Utilizing demand intelligence improves the precision of pricing, product assortments, channel/store placement, and promotion, which are all essential for sustainable revenue management performance. Learn more, download this free whitepaper today.

White Papers & Webcasts

Natural User Interface for Enterprise Applications
Learn how a revolutionary user interface can make a complex enterprise application so intuitive even casual users can jump right in....  

Why Now is the Right Time for the Linux Desktop
(Source: Novell) Faced with tighter budgets, enterprises are rethinking their desktop strategies to deliver the same - if not better - services and...

Moving Beyond Monolithic - What's Next for Enterprise Application Architectures?
This white paper reviews the current state of enterprise application architecture and presents a prediction on what might come next....  

Novell Opens PR Video
Is the Linux desktop for me? Customers are looking for ways to be more flexible and save money. Using Linux offers a great...

SUSE Linux Enterprise Server Deployment Approach Guide
This document is intended for IT professionals and managers who are considering deploying SUSE Linux Enterprise Server. Novell has had a number of...  

Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....

SUSE Linux Enterprise Desktop Data Sheet
SUSE Linux Enterprise Desktop is the market's only enterprise-quality Linux desktop ready. It delivers seamless interoperability with existing enterprise systems and dozens of...  

The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....

SUSE Linux Enterprise Server Data Sheet
SUSE Linux Enterprise Server is a highly reliable, interoperable and manageable server operating system built to power mission-critical workloads in physical and virtual...  

SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....