<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: EarthLink has just 31 challenge-response CAPTCHAs</title>
	<atom:link href="http://www.lightbluetouchpaper.org/2006/02/12/earthlink-has-just-31-challenge-response-captchas/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.lightbluetouchpaper.org/2006/02/12/earthlink-has-just-31-challenge-response-captchas/</link>
	<description>Security Research, Computer Laboratory, University of Cambridge</description>
	<pubDate>Sun, 27 Jul 2008 09:20:53 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: Richard Clayton</title>
		<link>http://www.lightbluetouchpaper.org/2006/02/12/earthlink-has-just-31-challenge-response-captchas/#comment-72</link>
		<dc:creator>Richard Clayton</dc:creator>
		<pubDate>Tue, 14 Feb 2006 16:04:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2006/02/12/earthlink-has-just-31-challenge-response-captchas/#comment-72</guid>
		<description>I'm appalled that EarthLink's spam detection is such that they have now sent me 325 challenges in the period since the 20th December. If they knew it was spam, they would not challenge. Nevertheless, to an academic, time spent educating users [turn the system OFF!] can surely never be time that is wasted?</description>
		<content:encoded><![CDATA[<p>I&#8217;m appalled that EarthLink&#8217;s spam detection is such that they have now sent me 325 challenges in the period since the 20th December. If they knew it was spam, they would not challenge. Nevertheless, to an academic, time spent educating users [turn the system OFF!] can surely never be time that is wasted?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Stiennon</title>
		<link>http://www.lightbluetouchpaper.org/2006/02/12/earthlink-has-just-31-challenge-response-captchas/#comment-71</link>
		<dc:creator>Stiennon</dc:creator>
		<pubDate>Tue, 14 Feb 2006 15:48:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2006/02/12/earthlink-has-just-31-challenge-response-captchas/#comment-71</guid>
		<description>While I applaud your vigilance I am appalled that you had time to capture 32 CAPCHTA's from Earthlink. 

Thank you for spending time the rest of us don't have to discover this.</description>
		<content:encoded><![CDATA[<p>While I applaud your vigilance I am appalled that you had time to capture 32 CAPCHTA&#8217;s from Earthlink. </p>
<p>Thank you for spending time the rest of us don&#8217;t have to discover this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Clayton</title>
		<link>http://www.lightbluetouchpaper.org/2006/02/12/earthlink-has-just-31-challenge-response-captchas/#comment-69</link>
		<dc:creator>Richard Clayton</dc:creator>
		<pubDate>Mon, 13 Feb 2006 22:04:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2006/02/12/earthlink-has-just-31-challenge-response-captchas/#comment-69</guid>
		<description>Blocking the EarthLink Challenge-Response emails is hardly rocket science... and has been described in many places &lt;a href="http://tqmcube.com/earthlink.php" rel="nofollow"&gt;such as here&lt;/a&gt;. It is of course an EarthLink specific detection rule (useless on other systems) -- and failing to accept these messages does nothing towards getting the EarthLink customers to turn them off! So although it would help me to block these messages, it does nothing to help the rest of the Internet. Which is where we came in!</description>
		<content:encoded><![CDATA[<p>Blocking the EarthLink Challenge-Response emails is hardly rocket science&#8230; and has been described in many places <a href="http://tqmcube.com/earthlink.php" rel="nofollow">such as here</a>. It is of course an EarthLink specific detection rule (useless on other systems) &#8212; and failing to accept these messages does nothing towards getting the EarthLink customers to turn them off! So although it would help me to block these messages, it does nothing to help the rest of the Internet. Which is where we came in!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Justin Mason</title>
		<link>http://www.lightbluetouchpaper.org/2006/02/12/earthlink-has-just-31-challenge-response-captchas/#comment-67</link>
		<dc:creator>Justin Mason</dc:creator>
		<pubDate>Mon, 13 Feb 2006 20:46:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2006/02/12/earthlink-has-just-31-challenge-response-captchas/#comment-67</guid>
		<description>Nicely spotted. ;)

I have a good SpamAssassin ruleset which blocks these -- mail me if you'd like a link.  It catches almost all of these mails.   I still hand-confirm the ones that get past, of course, as a protest against the offensive cost-shifting that C/R represents.</description>
		<content:encoded><![CDATA[<p>Nicely spotted. <img src='http://www.lightbluetouchpaper.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>I have a good SpamAssassin ruleset which blocks these &#8212; mail me if you&#8217;d like a link.  It catches almost all of these mails.   I still hand-confirm the ones that get past, of course, as a protest against the offensive cost-shifting that C/R represents.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris Walsh</title>
		<link>http://www.lightbluetouchpaper.org/2006/02/12/earthlink-has-just-31-challenge-response-captchas/#comment-66</link>
		<dc:creator>Chris Walsh</dc:creator>
		<pubDate>Mon, 13 Feb 2006 16:57:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2006/02/12/earthlink-has-just-31-challenge-response-captchas/#comment-66</guid>
		<description>I am very happy to have learned of this blog, and want to thank you in advance for all the good things you will be treating us to.</description>
		<content:encoded><![CDATA[<p>I am very happy to have learned of this blog, and want to thank you in advance for all the good things you will be treating us to.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tyler Moore</title>
		<link>http://www.lightbluetouchpaper.org/2006/02/12/earthlink-has-just-31-challenge-response-captchas/#comment-65</link>
		<dc:creator>Tyler Moore</dc:creator>
		<pubDate>Mon, 13 Feb 2006 11:09:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.lightbluetouchpaper.org/2006/02/12/earthlink-has-just-31-challenge-response-captchas/#comment-65</guid>
		<description>So now we have peer-to-peer spam filtering!  No longer do ISPs have to make the blocking decision or carry the costs of filtering; they've shifted liability onto end users.  Such a liability shift would only make sense if users were better placed to invest in spam defence than ISPs, which they clearly are not.  ISPs are better placed to fight spam because they examine much more email than a user ever could and they have the authority to filter spam out in the first place.  

So this technique creates an added inconvenience, transferring spam from the original recipient to the spoofed originator.  The net effect on spam is nil (if you equate the original spam with Earthlink's spam response).  Though interestingly, enabling 'Suspect Email Blocking' makes sense to an individual Earthlink user since it diverts all of its spam over the Internet.  Only with widespread adoption will the individual benefits of the blocking strategy diminish, as the Earthlink users begin receiving fake challenges from AOL, Hotmail, and Gmail users.</description>
		<content:encoded><![CDATA[<p>So now we have peer-to-peer spam filtering!  No longer do ISPs have to make the blocking decision or carry the costs of filtering; they&#8217;ve shifted liability onto end users.  Such a liability shift would only make sense if users were better placed to invest in spam defence than ISPs, which they clearly are not.  ISPs are better placed to fight spam because they examine much more email than a user ever could and they have the authority to filter spam out in the first place.  </p>
<p>So this technique creates an added inconvenience, transferring spam from the original recipient to the spoofed originator.  The net effect on spam is nil (if you equate the original spam with Earthlink&#8217;s spam response).  Though interestingly, enabling &#8216;Suspect Email Blocking&#8217; makes sense to an individual Earthlink user since it diverts all of its spam over the Internet.  Only with widespread adoption will the individual benefits of the blocking strategy diminish, as the Earthlink users begin receiving fake challenges from AOL, Hotmail, and Gmail users.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
