Wednesday, 24 January 2007

Why spam a blog?

This has to be the lowest bottom-feeding trick in the book. As soon as the URL for my blog shows up on a search engine, I get comment spam. Do these dickheads actually think we're going to follow their links and buy into their retarded, broken English pitches?

So, fine. I close off comments to everybody but registered users. "But you could use spam filters!". I could, and in different circumstances, I probably would. Let's jump to a different part of the story for a moment.

I still have the first email address I ever had; it's been something like a dozen years. Back in those days, it was perfectly reasonable to post your email address on your web site or in newsgroups. Sometime between then and now, the spammers figured out that web pages and newsgroups were a good source of email addresses, so we all removed our email links and started using fake addresses on the newsgroups. I expect I still get a spam now and again due to some spider hitting The Wayback Machine.

That probably wouldn't be so bad, but like an idiot, I used that address to sign up for an MSN account. What the hell was I thinking? Either Microsoft sold their list, or somebody managed to access it, because since then my rate of spam emails has skyrocketed. At last estimate, it's about 75 a day. Ack.

Sure, the junk filters work great, but it's an inexact science. Software has bugs and spammers change their tactics. So while 95% of the spam gets binned, I still have to mark a few "legitimate" emails as spam, and (rarely) I have to rescue a binned message and mark it as not spam. So the only real difference between using a spam filter and not, is that now I have to check all the messages in two folders instead of one. How is this saving me any time?

Back to the blog. The concept is exactly the same; I could use filters, but I still have to check every post, just in case something legitimate gets binned, or something illegitimate doesn't. I'm told that many Captcha implementations have been defeated, and with that kind of AI it's a good bet that any similar sort of scheme will be beaten quickly enough. Screw it, I have better things to do - I'll just lock them out and be done with it. Cracking long passwords is still out of the reach of mere mortals, and the spammers won't bother - there's still plenty of people out there so desperate for attention that they leave their blogs open.

Follow the money.

5 comments:

  1. Out of curiosity, what did you get in your comment spam?

    I've been getting some spam in my phpBB forums (which is how I know that captchas don't work). When a bot gets an account, it posts 4-6 variations of it's message, and it's always something like "visit dub-dub-dub-britney-screws-the-pooch-dot-com, omg lol!"

    Then again, it could be cheap labour registering the accounts and then feeding account credentials to botnets for the spamming to begin. But to date, none of the spammers have had multiple incidents. I haven't even had to ban the accounts. The moderators (me and grayson) just have to delete the offending posts and that's it...

    In summary: spam sucks.

    ReplyDelete
  2. Pretty much the same thing, only it almost looks legitimate at first glance. The first ones started out by saying "I've submitted these links for your approval", and then lays down half a dozen porn sites. It actually had a legit looking name in the Author field and proper (if not fake) email addresses and everything.

    After that it was all downhill. The whole thing is pretty much URLs now - author name, email address, all the other info lines, and on it goes.

    ReplyDelete
  3. Long as we're talking about it, I have noticed that Wordpress has the nice feature in that if you approve a comment once, the author is considered "safe" and you don't have to approve him again, and the reverse is true for spammers. So I suppose the legit stuff *won't* get thrown away once you authorize all the right people.

    ReplyDelete
  4. Why doesn't this surprise me? It's always the most opinionated people that don't like others opinions.

    This is an extremely slippery slope you are attempting to navigate. What's next - racial profiling? Blocking comments based on religious affiliations??

    THESE PEOPLE HAVE THE RIGHT TO POST COMMENTS!

    Oh... and by the way.

    V * I * A * G * R * A available at dub dub dub til-the-cows-come-home dot com

    Todd ;-)

    ReplyDelete
  5. Mea culpa, you got me. I'm not interested in anybody else's opinion. And I hate you guys.

    ReplyDelete