No, there is no account compromise. It is simple spam by
spoofing: there is no authentication when sending email and
anyone can claim to be whoever they like when sending a message.

We have had a few instances in the past, but a specific spammer
has recently targeted vim_use and has sent warez spam using two
different spoofed addresses. I am not going to discuss the
particular cases in detail in public, but I will finish with a
general rant:

Google Groups is utterly broken, and the spam tide is very
likely to become overwhelming as other spammers realise how easy
it is to screw us.

There is a "help forum" for Google Groups but it consists
entirely of unanswered requests for help. Google staff never
gave useful help, but they have now abandoned the forum:
http://groups.google.com/group/Google-Groups-Guide

Spammers can buy a $60 program that generates five Google
accounts per minute (breaking the captcha). I suspect that
methods to automate spoofing will become more widespread.
To illustrate: vim_use has 3140 members of which 1247 are banned
spammers (over one third of the member list consists of
throw-away spam accounts).

In the past the mailing list was badly burned when a mail system
run by a volunteer collapsed. It seems unlikely that we will
return to a volunteer-run system, but continuing with Google
Groups may become untenable because I suspect that many of us
have a low tolerance for spam.

I found two threads where people from various groups are
complaining about the spoofing issue:
http://groups.google.com/group/is-something-broken/browse_thread/thread/bb1be2db0b9e2f0f
http://groups.google.com/group/is-something-broken/browse_thread/thread/2628577f40d32180

We can assume that the spoofing problem is very widespread
because most group admins would not bother posting on the
obviously defunct help forum.

John


--~--~---------~--~----~------------~-------~--~----~
You received this message from the "vim_use" maillist.
For more information, visit http://www.vim.org/maillist.php
-~----------~----~----~----~------~----~------~--~---

Reply via email to