<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: ferris]]></title>
    <link>http://securityratty.com/tag/ferris</link>
    <description></description>
    <pubDate>Wed, 21 May 2008 12:26:50 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[One Spam to rule them all!]]></title>
      <link>http://securityratty.com/article/98ecd80e92097113f4263e7aaaa199fb</link>
      <guid>http://securityratty.com/article/98ecd80e92097113f4263e7aaaa199fb</guid>
      <description><![CDATA[If we only had a dollar for each spam we recieved, we could end the worlds money crisis


clipped from www.crime-research.org

40 Trillion Spam E-mails This Year



ComputerWorld did a nice story...]]></description>
      <content:encoded><![CDATA[<div > If we only had a dollar for each spam we recieved, we could end the worlds money crisis! </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/01DFE693-83B7-4810-AD2E-2CED7E7BF518/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/3a2e3708-2633-47c0-9ed8-7e1d97290b47/01DFE693-83B7-4810-AD2E-2CED7E7BF518/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.crime-research.org/news/10.10.2008/3618/" href="http://www.crime-research.org/news/10.10.2008/3618/" style="font-size: 11px;">www.crime-research.org</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.crime-research.org/news/10.10.2008/3618/ -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">40 Trillion Spam E-mails This Year
</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.crime-research.org/news/10.10.2008/3618/ --><DIV><br />
ComputerWorld did a nice story called Spam Filters: Making Them Work relying on the Ferris numbers. However, the lesson we should learn is buried deeper in the details: spam is no longer a nuisance that clogs inboxes, it&#8217;s a security issue. The majority of spam messages now try to breach security on the computer reading the message, or redirect the user to a Web site full of malware etc. </DIV></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/01DFE693-83B7-4810-AD2E-2CED7E7BF518/blog/" title="blog or email this clip"><img src="http://content7.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
<BR/><MAP name="bdv_RSS_Ad_111008113702"><AREA alt="Feed Ads By BidVertiser.com" shape="poly" coords="0,0,467,0,467,45,315,45,315,59,0,59" href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=111008113702&amp;click=1" target="_blank" /><AREA alt="Feed Ads By BidVertiser.com" shape="rect" coords="315,45,467,59" href="http://www.bidvertiser.com/bdv/bidvertiser/bdv_ref.dbm?Ref_PID=165886&amp;Ref_Option=main&amp;source=90614506" target="_blank" /></MAP><P><a href="http://secure.bidvertiser.com/performance/bdv_rss_rd.dbm?pid=165886&amp;bid=400950&amp;PHS=111008113702&amp;click=1" target="_blank"><IMG src="http://bdv.bidvertiser.com/BidVertiser.dbm?pid=165886&amp;bid=400950&amp;PHS=111008113702&amp;rssimage=1&amp;rSRC=2" border="0" usemap="#bdv_RSS_Ad_111008113702" /></a></P>]]></content:encoded>
      <pubDate>Sat, 11 Oct 2008 19:37:02 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/spam messages">spam messages</category>
      <category domain="http://securityratty.com/tag/trillion spam e-mails">trillion spam e-mails</category>
      <category domain="http://securityratty.com/tag/spam filters">spam filters</category>
      <category domain="http://securityratty.com/tag/worlds money crisis">worlds money crisis</category>
      <category domain="http://securityratty.com/tag/security issue">security issue</category>
      <category domain="http://securityratty.com/tag/breach security">breach security</category>
      <category domain="http://securityratty.com/tag/clogs inboxes">clogs inboxes</category>
      <category domain="http://securityratty.com/tag/web site">web site</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=640">One Spam to rule them all!</source>
    </item>
    <item>
      <title><![CDATA[Don't Mix MX And CNAME Records]]></title>
      <link>http://securityratty.com/article/004725fe5a13e6eeac176518aa1a62ec</link>
      <guid>http://securityratty.com/article/004725fe5a13e6eeac176518aa1a62ec</guid>
      <description><![CDATA[An ambiguity in RFC 2821 , which defines how email should be delivered, causes problems for some users, according to Ferris Research. In their first blog on the subject they relate a story of someone...]]></description>
      <content:encoded><![CDATA[An ambiguity in <A class=external href="http://www.faqs.org/rfcs/rfc2821.html" target=_blank>RFC 2821</A>, which defines how email should be delivered, causes problems for some users, according to Ferris Research.

In <a href="http://www.ferris.com/2008/09/07/beware-using-cname-and-mx-at-the-same-time/">their first blog on the subject</a> they relate a story of someone (names are expunged to protect the innocent from embarrassment) who decided to configure his DNS with both an MX record (which advertises the mail server) and a CNAME record defining where the web server was. More specifically, the CNAME defined "the-domain-in-question.com." to be "www.the-domain-in-question.com", the IP address of which was defined in a separate A record. After this, Mr. Anonymous's e-mail wasn't consistently reaching the mail server anymore. Some external servers were no longer finding the mail server.

The problem turns out to be that when a server has a CNAME record some sending mail servers will attempt to connect to that and not to the server pointed to by the MX record. So in the example, the outside mail was being sent to the web server, which of course didn't respond to it.

<a href="http://www.ferris.com/2008/09/08/why-you-shouldnt-mix-cname-and-mx/">The problem, says Ferris, is in an ambiguity in RFC 2821.</a> They have a point. The SMTP standard seems to <i>recommend</i> against mixing CNAME and MX records, but it doesn't prohibit it, and it's unclear on how the server should behave when it finds both.

Bottom line: Don't mix them.
<p><a href="http://feedads.googleadservices.com/~a/pPJkrG0shTbAW-nlDb8Q4C1Xj8c/a"><img src="http://feedads.googleadservices.com/~a/pPJkrG0shTbAW-nlDb8Q4C1Xj8c/i" border="0" ismap="true"></img></a></p><img src="http://feedproxy.google.com/~r/RSS/cheap_hack/~4/ntgwYENutcQ" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 10 Sep 2008 04:59:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mail">mail</category>
      <category domain="http://securityratty.com/tag/mail server anymore">mail server anymore</category>
      <category domain="http://securityratty.com/tag/mail servers">mail servers</category>
      <category domain="http://securityratty.com/tag/e-mail">e-mail</category>
      <category domain="http://securityratty.com/tag/mail server">mail server</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/cname">cname</category>
      <category domain="http://securityratty.com/tag/web server">web server</category>
      <category domain="http://securityratty.com/tag/record">record</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/ntgwYENutcQ/dont_mix_mx_and_cname_records.html">Don't Mix MX And CNAME Records</source>
    </item>
    <item>
      <title><![CDATA[8 ways to fight spam filter frustration]]></title>
      <link>http://securityratty.com/article/15a29dfce7de2df52c4a078d113dac89</link>
      <guid>http://securityratty.com/article/15a29dfce7de2df52c4a078d113dac89</guid>
      <description><![CDATA[Spam. It fills our in-boxes, wastes our time and spreads malware -- and it's only getting worse. According to Ferris Research, which studies messaging and content control, 40 trillion spam messages...]]></description>
      <content:encoded><![CDATA[Spam. It fills our in-boxes, wastes our time and spreads malware -- and it's only getting worse. According to Ferris Research, which studies messaging and content control, 40 trillion spam messages are expected to be sent in 2008, costing businesses more than $140 billion worldwide -- a significant increase from the 18 trillion spam messages sent in 2006 and the 30 trillion in 2007.]]></content:encoded>
      <pubDate>Wed, 06 Aug 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/spam">spam</category>
      <category domain="http://securityratty.com/tag/trillion spam messages">trillion spam messages</category>
      <category domain="http://securityratty.com/tag/trillion">trillion</category>
      <category domain="http://securityratty.com/tag/content control">content control</category>
      <category domain="http://securityratty.com/tag/ferris research">ferris research</category>
      <category domain="http://securityratty.com/tag/significant increase">significant increase</category>
      <category domain="http://securityratty.com/tag/billion worldwide">billion worldwide</category>
      <category domain="http://securityratty.com/tag/spreads malware">spreads malware</category>
      <category domain="http://securityratty.com/tag/in-boxes">in-boxes</category>
      <source url="http://www.networkworld.com/news/2008/080608-8-ways-to-fight-spam.html?fsrc=rss-security">8 ways to fight spam filter frustration</source>
    </item>
    <item>
      <title><![CDATA[Will Retention Policies Go Away?]]></title>
      <link>http://securityratty.com/article/e042a684cfe633270ad52e20024b73ae</link>
      <guid>http://securityratty.com/article/e042a684cfe633270ad52e20024b73ae</guid>
      <description><![CDATA[If you listen to lawyers talk about it, corporations have every right to establish document retention policies, including the destruction of documents, in the normal course of business. In my...]]></description>
      <content:encoded><![CDATA[If you listen to lawyers talk about it, corporations have every right to establish document retention policies, including the destruction of documents, in the normal course of business. In <a href="http://www.eweek.com/c/a/Security/Federal-Judge-Warns-of-eDiscovery-Pitfalls/">my interview with Judge John Facciola of the DC Circuit</a> he was clear about this, while pointing out that a document hold over pending litigation changes matters of course.

But such policies may be more trouble than they're worth. <a href="http://www.ferris.com/2008/05/20/records-retention-policies-to-go-away/">As David Ferris of Ferris Research argues</a>, the very small, and diminishing cost of storage makes it a tough choice to try to enforce such policies. It's easier and maybe even cheaper to get a policy of retaining everything right than to get your own retention policies right, and to implement them consistently. He actually predicts that most organizations will abandon retention policies. (The blog then inexplicably ends with three bulleted reasons not to abandon them.)<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=e72574e325079c1fdc3d20b32b6b1826" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=e72574e325079c1fdc3d20b32b6b1826" style="display: none;" border="0" height="1" width="1" alt=""/><img src="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~4/295306758" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 21 May 2008 12:26:50 +0000</pubDate>
      <category domain="http://securityratty.com/tag/retention policies">retention policies</category>
      <category domain="http://securityratty.com/tag/policies">policies</category>
      <category domain="http://securityratty.com/tag/abandon retention policies">abandon retention policies</category>
      <category domain="http://securityratty.com/tag/abandon">abandon</category>
      <category domain="http://securityratty.com/tag/ferris research argues">ferris research argues</category>
      <category domain="http://securityratty.com/tag/judge john facciola">judge john facciola</category>
      <category domain="http://securityratty.com/tag/david ferris">david ferris</category>
      <category domain="http://securityratty.com/tag/tough choice">tough choice</category>
      <category domain="http://securityratty.com/tag/lawyers talk">lawyers talk</category>
      <source url="http://feeds.ziffdavisenterprise.com/~r/RSS/cheap_hack/~3/295306758/will_retention_policies_go_away.html">Will Retention Policies Go Away?</source>
    </item>
  </channel>
</rss>
