Categories

  • Apple (15)
  • Coding (4)
  • del.icio.us (14)
  • General (136)
  • Life (10)
    • Remodel (1)
  • Politics (16)
  • Project Steamroller (1)
  • Spam (11)
  • Sysadmin (9)
  • Tech/Geek (15)
  • Uncategorized (52)

Ye Olde Posts

  • March 2010 (1)
  • January 2010 (3)
  • December 2009 (1)
  • November 2009 (1)
  • October 2009 (2)
  • September 2009 (1)
  • August 2009 (3)
  • July 2009 (3)
  • June 2009 (2)
  • May 2009 (2)
  • April 2009 (1)
  • March 2009 (4)
  • February 2009 (2)
  • January 2009 (1)
  • December 2008 (1)
  • September 2008 (1)
  • July 2008 (1)
  • May 2008 (5)
  • April 2008 (2)
  • March 2008 (9)
  • February 2008 (5)
  • January 2008 (6)
  • December 2007 (7)
  • November 2007 (2)
  • October 2007 (6)
  • August 2007 (7)
  • July 2007 (2)
  • June 2007 (3)
  • May 2007 (3)
  • April 2007 (8)
  • March 2007 (8)
  • February 2007 (10)
  • January 2007 (3)
  • December 2006 (2)
  • November 2006 (1)
  • October 2006 (2)
  • August 2006 (2)
  • July 2006 (2)
  • June 2006 (2)
  • May 2006 (5)
  • April 2006 (2)
  • February 2006 (1)
  • January 2006 (2)
  • December 2005 (2)
  • November 2005 (2)
  • October 2005 (3)
  • September 2005 (1)
  • August 2005 (1)
  • July 2005 (3)
  • June 2005 (3)
  • May 2005 (1)
  • April 2005 (1)
  • March 2005 (1)
  • February 2005 (4)
  • January 2005 (1)
  • December 2004 (3)
  • October 2004 (3)
  • July 2004 (1)
  • April 2004 (5)
  • March 2004 (5)
  • February 2004 (5)
  • January 2004 (3)
  • December 2003 (2)
  • November 2003 (9)
  • October 2003 (5)
  • September 2003 (4)
  • August 2003 (3)
  • July 2003 (2)
  • June 2003 (8)
  • May 2003 (5)
  • April 2003 (4)
  • March 2003 (10)
  • February 2003 (25)
  • January 2003 (12)

Monthly archives for April, 2006

Tivo and Meepio

Apr18
2006
Leave a Comment Written by Craig

So I’m reading my daily stories, and I see these items:

  • Barron’s: TiVo ripe for buyout?
  • Yahoo! Buys Out Meedio

And I’m thinking:

I called another one!

Posted in General
SHARE THIS Twitter Facebook Delicious StumbleUpon E-mail

Goodmail/AOL and the CA state senate

Apr04
2006
Leave a Comment Written by Craig

I testified today in front of a subcommittee of the California State Senate (actually, basically just Senator Florez); I basically discussed the technology underpinnings of email, how messages are delivered etc. My brief was “explain it at an elementary school level”, which I think I accomplished fairly well. I then hung around for the rest of the testimony from other folks, including AOL/Goodmail.

One thing I had encouraged the Senator to ask them about, was what sort of liability the two companies believed they might have in cases where illegitimate mail was “certified” by the companies, resulting in damage to an AOL user who relied on that stamp of trust. Amazingly, on the record, both companies emphatically stated that they would be fully liable in such a case. I was utterly amazed. The potential liability is enormous, and goes some good way towards possibly explaining why Goodmail charges such seemingly high rates for its stamps — Goodmail’s CEO said in testimony that the price sheet ranges from 1 cent per email at low volumes for commercial senders to 0.25 cents per email at high volume (over 1,000,000 stamps per month) to 1/25 cent per email for 501(c)(3) and 501(c)(4) not-for-profits. Ebay apparently sends somewhere on order of 1 billion emails per month, so a Goodmail stamp deal there at list price would generate somewhere on the order of 250 million in revenue per month for Goodmail. Now, I would expect Ebay is capable of bargaining themselves a discount. There aren’t any particularly good data on the financial scale of damages due to individual phishing attacks or virus outbreaks (if there are, I haven’t seen them anyway), but picture that a Goodmail stampee is somehow compromised, and a certified message is sent out which is either a phish, or is perhaps infected with a virus. That email arrives in AOL users’ inboxes with a “Certified utterly reliably good” stamp on it, and the user opens the mail, and hands over their entire life savings. Times a few hundred thousand AOL users. Now all of a sudden, $250MM per month isn’t looking like all that much revenue any more.

And of course that assumes that the spammers/phishers/virus-infectors will even bother compromising a valid Goodmail sender. If AOL continues to provide its “enhanced” whitelist which allows senders with historic patterns of good behavior to be able to include embedded images and links, then I can easily forsee spammers/phishers gaming that system to earn “enhanced whitelist” status, and then embedding the goodmail “CertifiedEmail” logo in the message body of a bogus email. I can tell you right now with no specific user testing on this, that a huge percentage of users wouldn’t notice that the “CertifiedEmail” stamp is in the message body, and not in a special area of the message display UI that the AOL client uses for valid use of that logo. Now in this situation, where Goodmail hasn’t actually certified the email, but it appears to AOL users that the email is indeed certified by AOL/Goodmail, and they lose their life savings, is AOL liable? Remember that AOL granted “enhanced whitelist” status to this sender. And remember that they were adamant in hearings in the CA Senate that they were liable.

Aside: Does anyone know if Goodmail’s message-hash-in-an-x-header system actually works in the face of the usual 2822 munging that goes on in the real world, or does it suffer from the same issues that DKIM seems to not have yet been able to solve, in that munging breaks the message hash? And if it does suffer from hash-breaking in some cases, then do you get a refund for those stamps which end up being useless?

Posted in Spam
SHARE THIS Twitter Facebook Delicious StumbleUpon E-mail

Translate

EnglishFrenchGermanItalianPortugueseRussianSlovenianSpanish

Search

Recent Comments

  • Craig on On the efficiency of Virtual Machines
  • flickr.com/photos/jm on On the efficiency of Virtual Machines
  • jmason on Neat. A new way to track website visitors!
  • jmason on On the time domain, with regard to spam
  • pooya on Interesting Tivo trivia bit

Meta

  • Log in
  • Entries RSS
  • Comments RSS
  • WordPress.org

EvoLve theme by Blogatize  •  Powered by WordPress Craigalog
Craig's musings