Aside: Clicking Reply-All in Microsoft Outlook only put Luis and Andy into the 
To: box. I had to manually add mailop.

My view is that (generally), Operations that're so big as to receive many 
reports a day, grossly under-resource their abuse-response capability and don't 
particularly care about 'minor' (read: non newsworthy) cases of abuse on their 
networks.

I once managed abuse@ for what in my country was officially a very large ISP - 
500k customers.  There was about 1.3FTE dedicated to abuse@ and I was the .3.
We made a valiant attempt to keep up with inbound complaint loading but all too 
often, the complaints would essentially roll-off the queue (complaints >1month 
old were harder to investigate as the logs required to track back offending 
users, were archived after that).

This is many years ago - early 2000's.  I don't imagine a lot has changed.

Mark.

-----Original Message-----
From: mailop [mailto:[email protected]] On Behalf Of Luis E. Muñoz via 
mailop
Sent: Wednesday, 28 August 2019 11:54 a.m.
To: Andy Smith <[email protected]>
Cc: [email protected]
Subject: Re: [mailop] SpamCop and listwashing

On 27 Aug 2019, at 16:23, Andy Smith via mailop wrote:
> So, where else can one go to streamline the spam reporting process?
> This page lists only SpamCop and Abusix:
>
>     https://en.wikipedia.org/wiki/Spam_reporting
>
> As far as I can see Abusix in this context is only an 
> IP-to-abuse-contact lookup tool.

Years ago, while in charge of anti-abuse operations for a sizable group of 
users, I tried hard to address this challenge. SpamCop was around, Abusix 
wasn't. Long story short, we ended up implementing direct abuse contact lookup 
using WHOIS — at that time this was still a feasible exercise. Our reports 
included logs about the incident — mail headers, ACL logs, whatever was 
appropriate — and we had actual people, me included, manning the Reply-To of 
those.

The results were mixed and in retrospect, perhaps interesting.

Operations that were large enough so as to receive many reports a day — we sent 
one report per "incident"/day — often complained or outright blocked / 
devnulled our reports. Complaint receivers that got lots of complaints often 
claimed that they were unable to process them in such volumes. Based on the 
traffic we saw from them, their lack of time wasn't related to preventing 
hostile traffic from leaving through their door.

Operators with only the occasional report were in some cases responsive, as we 
saw the abuse stopped. Some even responded. Some asked us to make special 
arrangements for their reports to go to a special address, which we were happy 
to oblige. We got to know who were the good guys and who were just making the 
right noises. As I'm sure does SC.

All this said and done, a huge proportion of the reports we sent to published 
points of contact for network level objects simply bounced.

I guess I'm trying to say is that getting abuse complaints to the right hands, 
at scale, is way harder than it seems. "Streamlining" the process is hard, and 
once you walk that path I'm sure you'll get to a similar
conclusion: Some folks don't deserve the bits used to send the complaint.

-lem

_______________________________________________
mailop mailing list
[email protected]
https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop


_______________________________________________
mailop mailing list
[email protected]
https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop

Reply via email to