ietf-asrg
[Top] [All Lists]

[Asrg] Blacklisting email accounts?

2011-08-30 17:08:48
(Maybe my google-fu isn't up to par and this has been discussed
previously - if so, my apologies)

With PCs being owned and email accounts being owned, has anyone
considered blacklisting individual email accounts? Within the past
month, I've gotten an influx of spam from people who I have
communicated with. Given the content, I doubt these people would be
sending me random links to foreign websites designed to own my PC.
Some of these senders are people who I haven't communicated with in
years, but my email address is probably in their email box or address
book. It's all been consumer-grade email (Comcast, AOL, Yahoo, etc.)
from people for whom it would not be a stretch to imagine them getting
owned.

Considering that some of these providers don't seem to be interested
in cleaning up their outbound mail, has anyone considered blacklisting
email accounts like we do IPs/hostnames? I do this for my personal
mail stream, and it scales - get a spam from an owned person I don't
need email from, drop 'em in the local BL. But for this to be
effective, there'd have to be some kind of DNSBL'ish thing to query.

I do understand that there are an infinite amount of email addresses
for freemail domains ;)  So this wouldn't stop spammer-created
accounts.

But if Aunt Tilly has to change her email address (or go through some
removal-from-blocklist stuff - possibly go through some education),
that could have the necessary impact to change her behavior so she
wouldn't get owned again. This could be use a strong password, don't
run an insecure OS, don't use insecure wiifi, whatever is deemed good
information to better their understanding of what they've done.

Or am I giving people too much credit in hoping they'd change after
they meet the clue by four?  For some, the aversion to getting another
email address might outlive the desire to be lackadaisical..

-- 
HTH, YMMV, HANW :)

Jason

The path to enlightenment is /usr/bin/enlightenment.
_______________________________________________
Asrg mailing list
Asrg(_at_)irtf(_dot_)org
http://www.irtf.org/mailman/listinfo/asrg

<Prev in Thread] Current Thread [Next in Thread>