Thursday, March 19, 2009

Re: Email Addresses/Spam

While many of the suggestions made are/were best practices, over the past=
=A03 years most sites have simply begun publishing email addresses an imple=
menting aggressive spam filtering.=A0=A0Otherwise you are punishing good us=
ers on the theory that it reduces spam, when in fact bots scraping=A0organi=
zational websites=A0(by most estimates) account for less than 10% of emails=
harvested (according to Forrester but I can't find the source).=A0=0A=0ABy=
clearly publishing the email address you make communication with the organ=
ization simple and easy for legitimate customers and no amount of obfuscati=
on can prevent or even really limit spamming.=A0 The emails are gathered th=
rough bots, but many more are gathered in other ways including signing up t=
o mailing lists, viruses, and many more.=A0 Nearly every on on this list ha=
s their email address easily harvest-able from http://ised-l.blogspot.com/=
=A0.=A0
Even if it is never used, spammers use dictionary=A0attack methods =
for many=A0common=A0names.=A0=A0They simply take the domain name and run th=
rough the alphabet asmith@somewhere.com, bsmith@somewhere.com, etc.=0A=0ASo=
, even though the FTC recommended obscuring the email address based on a 20=
05 study (http://www.ftc.gov/opa/2005/11/spam3.shtm) they obfuscated it eve=
rywhere so it is an apple to oranges comparison.=A0 Even when they did this=
, their accounts still received spam (but only 1 as compared with 6000+ on =
the open emails).=A0 Since then, the bots have improved and can account for=
nearly every method designed to stop them=A0(except the form based one) an=
d I doubt you would see much difference.=A0(http://www.cryptologie.com/Spam=
Full.pdf
) If you use your email, it is almost certainly posted in public vi=
ew somewhere and you may as well make it easy for your parents because I wo=
uld bet on the spammers already have it (just check your filter for proof o=
r google you own email or check pipl ........).=0A=0A_J=A0_________________=
___________=0AJason at jasonpj@yahoo.com =0A=0A=0A=0A=0A___________________=
_____________=0AFrom: Jeanne Rice <jrice@schacademy.org>=0ATo: ISED-L@LISTS=
ERV.SYR.EDU=0ASent: Thursday, March 19, 2009 12:14:12 PM=0ASubject: Re: Ema=
il Addresses/Spam=0A=0AWe do not post e-mail addresses on our website.=A0 W=
e use the "survey tool"=0Athrough Finalsite to create text boxes that are s=
ent to a person's e-mail=0Aaddress to avoid posting any e-mail addresses on=
the website.=0A=0AWe use Barracuda... but still found a lot of spam gettin=
g into our e-mail.=0AWe switched over to g-mail, which is free...and can us=
e your own domain=0Aname...and since then, we are 99.9% spam free.=0A=0AJea=
nne Rice=0ASouthern CT Hebrew Academy=0Awww.schacademy.org=0A=0AOn Thu, Mar=
19, 2009 at 9:08 AM, CHRISTOPHER BUTLER <cbutler@stjohnsprep.org=0A> wrote=
:=0A=0A> Many websites these days use little javascript tools to mask email=
=0A> addresses=0A> on websites (our site which is managed by Finalsite does=
this).=A0 This=0A> leaves=0A> them clickable to end users, but invisible t=
o bots that scan the raw html.=0A>=0A> Many email addresses that spammers g=
et are obtained by bots that scan the=0A> raw html of webpages looking for =
content that is in the form of an email;=0A> that is, two blocks of text co=
nnected by the '@' symbol.=A0 The beauty of the=0A> javascript tool is that=
the raw html has nothing that looks like an email=0A> address, but the ren=
dered web page presents something that looks like an=0A> email address and =
that when clicked acts like a mailto: reference.=0A>=0A> As for the other q=
uestion about filters, currently I'm pretty happy with=0A> our=0A> Barracud=
a.=A0 We've got it locked down pretty tight with very few false=0A> positiv=
es and very little leakage of bad emails.=A0 It took a while to get it=0A> =
to this point but now needs very little maintenance.=0A>=0A> Christopher=0A=
>=0A> --=0A> Christopher Butler=0A> Academic Technology Director=0A> St. Jo=
hn's Preparatory School=0A> http://www.stjohnsprep.org=0A>=0A>=0A>=0A> [ Fo=
r info on ISED-L see http://www.gds.org/ISED-L ]=0A> Submissions to ISED-L =
are released under a creative commons, attribution,=0A> non-commercial, sha=
re-alike license.=0A> RSS Feed, http://listserv.syr.edu/scripts/wa.exe?RSS&=
L=3DISED-L=0A
>=0A=0A[ For info on ISED-L see http://www.gds.org/ISED-L ]=0A=
Submissions to ISED-L are released under a creative commons, attribution, n=
on-commercial, share-alike license.=0ARSS Feed, http://listserv.syr.edu/scr=
ipts/wa.exe?RSS&L=3DISED-L=0A=0A=0A=0A

[ For info on ISED-L see http://www.gds.org/ISED-L ]
Submissions to ISED-L are released under a creative commons, attribution, non-commercial, share-alike license.
RSS Feed, http://listserv.syr.edu/scripts/wa.exe?RSS&L=3DISED-L