On 04/05/2014 07:33 PM, John Hardin wrote:

The masscheck spam corpus isn't pathetically small, but at the moment
it's *strongly* biased towards the traffic *you* are seeing. Your spam
is 490k+ of the 510k total corpus.

Should I feel guilty for only masschecking the last 21 days?


That was only an example. There are other rules for spam that I'm
receiving, and I have some contact with a fairly large ISP that has been
seeing similar traffic and reporting FNs to me, but the rules aren't
doing well in masscheck.
My personal message traffic is pretty small, and I don't know whether
the ISP can devote any resources to performing masschecks.

I've offered to run masschecks if ppl can't setup themselves but if I don't get the data...
DNSWL was feeding me a spam trickle but that has dissapeared as well.

I've been considering publishing a separate rules feed for
apparently-useful rules like this that masscheck doesn't seem to
consider worthy, I may have to consider that idea more seriously.

I'm personally in favour of ppl running separate repositories, a la SARE, but that seems against the project's aims.

For the moment, though, I think I will "tflags publish" a couple of my
recent high-S/O rules. I wasn't proposing doing it en masse.

imo, if we all start doing this for a couple of rules which perform well in a small eco system the collective turns into "en masse".

but then... go for it

Reply via email to