Todd,

You are exactly right.  As far as I'm concerned (and I'm guessing others as
well), filtering and scanning are two VERY different things.  Let me explain
that a little...

I have to agree with Michael that if my ISP decided it was acceptable policy
to keep out viruses by simply filtering any executable file type, I'd be
irate!  From a business standpoint, that's a bad way to keep your customers.
>From a technical standpoint, that's an inadequate way to protect against
viruses.  I would never tell my customers that we have virus protection when
I was just filtering using rules.ima.

Now I'm not sure how Michael feels about virus filtering on the server, but
I DO agree with that.  As long as it gives detailed notification to the
sender and/or receiver that a virus had been caught and tell them the
subject of the message.  As you would guess, we do this with Declude.  This
way I never simply dump a message regardless of whether it had a virus,
based on the extension.  My users can rest assured that they get everything
that was intended for them except messages with a virus attached and in that
case, the sender gets a kind notification (with help on virus scanning)
telling them which message contained which virus.  But any EXE, SCR, VBS,
etc, attachments that are clean go right through.

I also would like to point out to Michael that not all on this list are
ISP's with paying customers.  I use IMail in two different jobs.  One is an
ISP (the scenerio above) and the other is a private company with internal
users.  Private companies may or may not have the money to implement virus
protection on their mail server so the use what they have.  In such a
situation, I would MUCH rather filter several know virus-ridden file types
(Lile PIF and SCR) knowing that literally hundreds or thousands of SirCams
and Magistrs slip through my mail server daily.  These things are completely
automated and I've never seen such an attachment sent by a real human.  Just
a virus on an Outlook-enabled computer.  It's also easier for me to deal
with one user that is unable to send a certain type of attachment than a
flood of SirCams infecting every computer in my company.  And don't forget
that it is entirely up to management to make the policy for such filtering.
The users have no rights here.  Yes, I would be upset, but the users need to
see that a little inconvenience is acceptable to prevent network chaos.
This is VERY different than for an ISP because an ISP does not have to
support the end-user's desktop.

My point there was that you should be aware that not all responses you get
are from ISPs that think filtering with rules.ima is a good idea.  Some are
private companies where they have every right and responsibility to do so.

Just listen to what some are saying and vote with your money.

--a different Todd.





----- Original Message -----
From: "Todd Holt" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, December 06, 2001 11:01 PM
Subject: RE: [IMail Forum] rules.ima


> I certainly appreciate your point(s).  I don't disagree with the filtering
> issue, but I think the user should be forced to accept that their mail
will
> be scanned for viruses.  There is no possible down side to this scanning.
> As for filtering, its prudent but solid business cases could be made
against
> it and should be left up to the customer.
>
> Thanks for the banter and I didn't mean to offend Michael.  I apologize if
I
> did.
>
> Todd
>
> -----Original Message-----
> From: [EMAIL PROTECTED]
> [mailto:[EMAIL PROTECTED]]On Behalf Of --> Kevin
> Coveney
> Sent: Thursday, December 06, 2001 8:25 PM
> To: [EMAIL PROTECTED]
> Subject: RE: [IMail Forum] rules.ima
>
>
> I have not posted much to this this lately, but have been closely
> following the concerns around Michael Welch's statements. In support
> of Michael as end-user and customer I feel compelled that I must voice
> my opinion on this matter.
>
> <SOAPBOX>
> 1. As ISP we should never forget that our end-users are our customers
>    and it is their needs (and money) that make our business a success
>    or failure. It is with their good graces that we receive the revenue
>    to support the delivery of email to them and as SERVICE PROVIDERS
>    let us not purport to be "all-knowing", we are simply and humbly
>    providing a service.
>
> 2. Censorship without permission is WRONG (at least from my point of
>    view) and who among us as ISPs have the "right" to determine what
>    are customers want to receive. As almost all of us hate SPAM, we
>    all recognize a users right to OPT-IN (as many due through their
>    so-called "Free" email accounts) to SPAM solicitations, and likewise
>    no customer should have their infected email prevented from being
>    delivered if it THEIR choice. (Although it's not mine!)
>
> 3. Now, that being said, from a Host/Network administrators perspective,
>    providing a service to employees, students, or other members; System &
>    Network security is a MAJOR concern. Virus attacks cause thousand of
> dollars
>    of damage to corporations - and they should have the right to determine
>    how their network is used - and NOT used. I am well aware of this
>    because I know how much we've charged companies this past year to
>    help clean up virus attacks. Even when they had desktop protection,
some
>    users still think they know better than the advice of the virus
> protection
>    software they've enlisted and try to open an infected document.
>
> In summary, Michael has the right to believe that his service provider
will
> actually provide him with the services he requested. Likewise if the
service
> provider does not want to service his customer Michael has the power to
take
> his money elsewhere. I know I've heard more than once around this list
that
> if your ISP blocks port 25 and they will not or cannot open it for you
that
> your should find another ISP - and I believe same reasoning should be
> applied
> here - Nothing should be blocked without the customers express permission
> unless it is clearly stated upfront in your TOS and/or AUPs.
>
> Why not just offer your customers the choice - full delivery, filtered
> delivery
> or a fully scanned delivery. And by the way... since these option require
> extra
> work on your behalf and your servers, why not up sell the options to
enhance
> your revenue.
> </SOAPBOX>
>
> I'm very sorry to possibly annoy someone and waste some of your bandwidth
> but
> I needed to get this off my chest. Hope you all have a fine day!
>
> Thanks for your time...
>
> Kevin Coveney
>
>
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>
> An Archive of this list is available at:
> http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
>
>
> Please visit http://www.ipswitch.com/support/mailing-lists.html
> to be removed from this list.
>
> An Archive of this list is available at:
> http://www.mail-archive.com/imail_forum%40list.ipswitch.com/
>
>


Please visit http://www.ipswitch.com/support/mailing-lists.html 
to be removed from this list.

An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/

Reply via email to