On Jun 17, 2009, at 2:12 PM, Melvin wrote:

> Scott Haneda wrote:
>> In the same way it would not be fair to target the owner of a  
>> building
>> if a kid sprayp aints profane graffitti on it... I do not think you
>> can go after the ISP for users who abuse their network.
>>
>> Most do their best. I spoke with Comcast and suggested port 25
>> blocking or at least forced authentication to stop virus's from
>> zombied machines.
>>
>> Their valid point is how many users that would break email for  
>> because
>> they are not technically able to change settings in their email  
>> client.
>
> I find it extremely odd that anyone at Comcast would make that sort of
> claim while Bellsouth/AT&T and others who are much larger as well as
> most smaller ISPs are doing exactly that, at least in the U.S.

I suspect, though this is just from my mail usage, Comcast is a larger  
provider of email.  I get a solid order of magnitude more emails from  
@comcast.net email addresses, than from @att/bellsouth etc addresses.   
Grepping logs using | wc -l to get log lines for all of May 2009.

I think a lot of this comes from, at some point in the past, they had  
an installer, that would set up outlook for you, so there is a large  
base of users who use outlook as their client.  I do a good deal of  
tech support, I can say from experience, a port change is not  
something most of my clients can deal with on their own, requires a  
phone call and walking them through it.

I am going to move one server to use ASSP, and with that, mandate port  
587, and not accept any port 25 authenticated users at all, I  
personally am not looking forward to that day at all.

> If you
> don't authenticate you don't send mail.  I was told by several people
> whom I trust that Comcast does this also, but since I'm not on  
> Comcast I
> can't say from personal experience so I'll have to do some more  
> research
> in detail.

Comcast is a strange beast.  Almost everything that happens on their  
network depends on where you are. For example, I used to be on their  
24. block, basically my entire town.  When I was, port 25 was open, so  
long as you were connected through their modem.  I assume they do a  
MAC id check of some form, and that is their "blind" authentication.

I was then moved from 24. to 76., and that changed, I can not touch  
port 25 at all.  I bet a lot of this is carry over from the @home.com  
merger as well.

> However I do know that claiming that their users are
> 'technically unable' to make this change is at best ludicrous, at  
> worst
> an out and out lie.  I would be highly suspicious of your source on  
> that
> info.

I respectfully disagree.  Assuming that there are users who can send  
on port 25 using some form of cable modem id as their auth, then users  
being able to change outlook's settings will be an issue.  From my  
girlfriends father who can not deal with a password change in outlook,  
to the large majority of on site calls I get paid for, to simply  
"Setup email", this is an issue for sure.

Stand in line at a Best Buy or Apple Store and see how many people in  
30 minutes are getting just that solved, their email being set up, no  
more, no less.

My source was @comcastcares on twitter.  As much as I am not a fan of  
Comcast, that channel of support is very good.  They may not know  
everything, but they will get you in touch with people that do.

If twitter did not roll out tweets older than some arbitrary day, I  
could paste them in here.

Imagine this: 1 million users, 99% are all on port 587, TLS, working  
fine, 1% are on port 25, and the ISP throws the switch. That alone, is  
10,000 phone calls you are going to get.

I know the second that an ISP blocks port 25, and I support only  
thousands of domains.  But the second it happens, I know, because our  
phones will be ringing. When the lines light up, I know some ISP has  
port 25 blocked.

> I understand that things do change on a regular basis, but I
> would be extremely surprised to find the Comcast wasn't blocking 25.
> Most ISPs only allow SMTP to their mail servers for exactly this
> reason.  Even if they don't force authentication they can track the
> source of whatever mail comes into the server if they want to bother.

Thats the other problem.  "If they want to bother".  I think that is  
the core issues here to be honest.  Were I in their shoes, port 25,  
587, or any port for that matter... If I saw more than x mails over it  
in y time, I think some sort of event could happen.  Maybe as evil as  
a http redirect to a message telling them to call, who knows.  Either  
way, they have the ability to make all machines on their network  
clean, they just have to chose to "want to bother".

Probably email throttling is the best thing.  Allow one email per x  
seconds, more than that, drop the connection for y seconds.  I think  
this is perhaps the biggest mistake they could fix and not get many  
support calls at all:
  ( http://postmaster.comcast.net/ )

#9 Comcast allows 1000 recipients per message.

That is just insane, it is as if they are inviting spammers in to  
either CC or BCC a single message.  I have a lot of crap head friends  
who still think forwarding emails is cool, but to date, I have not  
seen anyone break 50 addresses.  I think 100 is more than than fair,  
above that, prove you are trusted, and get more.

Thanks for the reply and conversation.
-- 
Scott * If you contact me off list replace talklists@ with scott@ *


------------------------------------------------------------------------------
Crystal Reports - New Free Runtime and 30 Day Trial
Check out the new simplified licensing option that enables unlimited
royalty-free distribution of the report engine for externally facing 
server and web deployment.
http://p.sf.net/sfu/businessobjects
_______________________________________________
Assp-user mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/assp-user

Reply via email to