Re: [funsec] Public Policy and Consumer ISP Hygiene (was Comcast pop-ups)

2009-10-17 Thread Rich Kulawiec
On Fri, Oct 16, 2009 at 12:04:08PM -0500, Dan White wrote: > So if I have a customer on Facebook that sends sPaM to another Facebook > user (that happens to be using AOL), do I or AOL get the blame? No, even > though we blindly relayed that message. If you relay spam, then you share a measure of t

Re: [funsec] Public Policy and Consumer ISP Hygiene (was Comcast pop-ups)

2009-10-17 Thread G. D. Fuego
On Oct 17, 2009, at 5:32 AM, Rich Kulawiec wrote: > On Fri, Oct 16, 2009 at 12:04:08PM -0500, Dan White wrote: >> I'm proposing a little more thinking outside the box here. SMTP >> does need >> to go way, and be replaced by something better: Something that does >> not >> inherently suffer

[funsec] Delta hacked my email, says passenger rights chief

2009-10-17 Thread Juha-Matti Laurio
"An airline passenger rights advocate is accusing Delta Air Lines of hacking into her computer and e-mail accounts to sabotage her organization's attempts to mandate basic services during flight delays. Kate Hanni, a resident of California, is the founder of the Coalition for an Airline Passeng

[funsec] Milw0rm.com has no updates since 21st Sep

2009-10-17 Thread Juha-Matti Laurio
http://milw0rm.com/ is up now, but it has been offline many times during Sep and Oct. The latest postings are dated 21st September. There is no explanation posted to http://twitter.com/str0ke Juha-Matti ___ Fun and Misc security discussion for OT pos

Re: [funsec] Public Policy and Consumer ISP Hygiene (was Comcastpop-ups)

2009-10-17 Thread Larry Seltzer
>> With a fully authenticated protocol we could limit the valid source >>addresses of the spam to the one associated with the compromised user. That reduces it to a trust decision, right? We've had this option for years with DKIM, at least at the domain level, and it doesn't seem to have changed

Re: [funsec] Public Policy and Consumer ISP Hygiene (was Comcastpop-ups)

2009-10-17 Thread G. D. Fuego
On Oct 17, 2009, at 9:31 AM, "Larry Seltzer" wrote: >>> With a fully authenticated protocol we could limit the valid source >>> addresses of the spam to the one associated with the compromised >>> user. > > That reduces it to a trust decision, right? We've had this option for > years with DKI

Re: [funsec] Public Policy and Consumer ISP Hygiene (was Comcastpop-ups)

2009-10-17 Thread chris
--- On Sat, 10/17/09, G. D. Fuego wrote: > DKIM is optional and not widely implemented.  .snip. > Of course none of this matters unless we could coordinate a > shift off of smtp, which would likely be about as fast as > the IPv6 migration unless there was a simple migration path. This is the

Re: [funsec] Oops. Sorry, wrong boat. Could we have a do-over?

2009-10-17 Thread Remo Cornali
chaim.rie...@gmail.com ha scritto: > Gadi is awol, prolly hangin out in a harem in the desert. > Doh, I didn't know he is an Arab Sheikh. ;-) Ciao! Remo ___ Fun and Misc security discussion for OT posts. https://linuxbox.org/cgi-bin/mailman

Re: [funsec] Public Policy and Consumer ISP Hygiene (was Comcastpop-ups)

2009-10-17 Thread Rich Kulawiec
On Sat, Oct 17, 2009 at 09:31:08AM -0400, Larry Seltzer wrote: > That reduces it to a trust decision, right? We've had this option for > years with DKIM, at least at the domain level, and it doesn't seem to > have changed things much. It hasn't. It won't. DKIM/SPF/SenderID/etc. all fall under wh

Re: [funsec] Oops. Sorry, wrong boat. Could we have a do-over?

2009-10-17 Thread Paul M Moriarty
Hmm... or a eunuch systems administrator? On Oct 17, 2009, at 8:11 AM, Remo Cornali wrote: > > > chaim.rie...@gmail.com ha scritto: > >> Gadi is awol, prolly hangin out in a harem in the desert. >> > > Doh, I didn't know he is an Arab Sheikh. ;-) > > Ciao! > Remo > > > > __

Re: [funsec] Oops. Sorry, wrong boat. Could we have a do-over?

2009-10-17 Thread steve pirk [egrep]
On Sat, Oct 17, 2009 at 08:29, Paul M Moriarty wrote: > Hmm... or a eunuch systems administrator? > > O! Kind of like my mother was a daemon and my father was a unix? [not sure I got the mom part right, might have been a Vax ;-] --steve > On Oct 17, 2009, at 8:11 AM, Remo Cornali wrote: > >

Re: [funsec] Milw0rm.com has no updates since 21st Sep

2009-10-17 Thread Jon Kibler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Juha-Matti Laurio wrote: > http://milw0rm.com/ is up now, but it has been offline many times during Sep > and Oct. > The latest postings are dated 21st September. > > There is no explanation posted to > http://twitter.com/str0ke > > Juha-Matti I

[funsec] Metasploit Unleashed

2009-10-17 Thread Jon Kibler
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The guys and gals over at Offensive Security have up the online version of their Metasploit Unleashed course. I have been using metasploit for years, and I am learning things about it that I had never known. Highly recommend you check it out. Jon - -