View Single Post
  #43   Report Post  
Old September 27th 03, 03:04 PM
Robert Bonomi
 
Posts: n/a
Default

In article YEcdb.2567$La.801@fed1read02, Ed Price wrote:



"--exray--" wrote in message
...
Chuck Harris wrote:
Michael A. Terrell wrote:


They should scan every received e-mail for virus or worms, and a


That fails when the virus/worm/trojan is modified even slightly. Ask
Norton, or McAfee why they have to update their virus scanners almost
daily.

valid FROM address.

How are you going to determine the from address is valid? email the
person at the address and ask them? What if the from address belongs
to someone other than the actual sender?


Infected e-mail should be deleted, and a message sent to the sender
that it was infected.


If you can determine who the sender really is. Sending email messages
to the forged email addresses that exist in the sender field of the
bad email just results in more needless email traffic.

The current email protocol provides no reliable way of validating the
sender's email address. It has needed upgrading for about 15 years
now.


Earthlink delivers E-mail with no FROM: information in the header.

If an ISP can't do this much, they need to go out of business.


Since no ISP can do what you are asking, I'd rather keep the current
"flawed" ISPs around for now, thank you.

Chuck, WA3UQV


I'm not sure of the mechanics of how it is actually done but there are
subscription services that ISPs can use to keep their mail services
clean and updated if they choose not to do it themselves.
Another "I'm not sure how it works" is with Mailwasher Pro...it will not
bounce to invalid yahoo addresses. Apparently some 'trial' ping is at
work, maybe in conjunction with Yahoo???.
Point being that these things can be accomplished although we are at a
early stage of seeing it actually happen.
-Bill


Exactly!! My company subscribes to a service like that; they get daily
updates for their filter software just like they get updates for their AV
file. At work, I am getting ZERO Swens. But at home, that's completely
different. I have a cable connection through Cox, and I'm getting 75 to 100
Swens per day. (The first couple of days, I had over a hundred per day.)
Sure, there's a few variations, but the 106 kB attachment is a real obvious
sign. Evidently, Cox doesn't care, and doesn't filter at all.

I don't leave my machine run 24/7, so the Swen IS a problem for me. Since
Cox only allows a 10 MB mailbox, about 90 Swens fills it. Then, Cox
graciously starts bouncing ALL my emails, since my box is now full. In
effect, an email DOS fringe benefit for the Swen.

My question is, why can't Cox afford a filter system for incoming email? And
my next question is why don't all reputable ISP's have a filter on outgoing
email? There's still a whole lot of the clueless who are yet to be infected,
and Swen attachments will be flowing for quite a while to come.


The answer to _any_ question that starts off "why don't they..." is *always*
"money".

How much more are _you_ willing to pay for your Internet access to cover
scanning of _your_ outgoing mail for viruses?

How much more are you willing to pay for virus-scanning of your incoming mail?
The commercial filtering services get $3-5 per mailbox, per month, in 'whole-
sale' quantities. And even the best of 'em don't catch everything.