[funsec] "Zuck" mail?

2010-12-26 Thread Rob, grandpa of Ryan, Trevor, Devon & Hannah
I received a notification from Facebook that I had new notices. Since I don't visit often this is possible, but I was looking at the headers, trying to find some overt indication that this was spam, when I noticed: X-Mailer: ZuckMail [version 1.00] Isn't that taking ego a bit too far? ===

Re: [funsec] "Zuck" mail?

2010-12-27 Thread Thomas M Carlsson
On 25/12/2010 18:27, Rob, grandpa of Ryan, Trevor, Devon & Hannah wrote: > I received a notification from Facebook that I had new notices. Since I > don't visit > often this is possible, but I was looking at the headers, trying to find some > overt > indication that this was spam, when I notic

Re: [funsec] "Zuck" mail?

2010-12-27 Thread Rich Kulawiec
On Sat, Dec 25, 2010 at 10:27:42AM -0800, Rob, grandpa of Ryan, Trevor, Devon & Hannah wrote: > I received a notification from Facebook that I had new notices. Since I > don't visit > often this is possible, but I was looking at the headers, trying to find some > overt > indication that this

Re: [funsec] "Zuck" mail?

2010-12-27 Thread Nick FitzGerald
Rich Kulawiec wrote: > Not surprising; spammer filth like Zuckerberg often display enormous egos. Mate -- don't be shy! Why hold back like that? Tell us what you really think... Regards, Nick FitzGerald ___ Fun and Misc security discussion for O

Re: [funsec] "Zuck" mail?

2010-12-27 Thread Valdis . Kletnieks
On Mon, 27 Dec 2010 07:27:54 EST, Rich Kulawiec said: > Not surprising; spammer filth like Zuckerberg often display enormous egos. OK Rich, I'll bite. Now that you've blown "spammer filth" for Zuckerberg, what pejorative term are you going to use for the botnet herders, the fake penis-enlarging

Re: [funsec] "Zuck" mail?

2010-12-28 Thread Rich Kulawiec
On Mon, Dec 27, 2010 at 06:23:32PM -0500, valdis.kletni...@vt.edu wrote: > OK Rich, I'll bite. Now that you've blown "spammer filth" for Zuckerberg, > what > pejorative term are you going to use for the botnet herders, the fake > penis-enlarging pill sellers, the whole 419 scene, the dirty-as-sin

Re: [funsec] "Zuck" mail?

2010-12-28 Thread Valdis . Kletnieks
On Tue, 28 Dec 2010 06:34:08 EST, Rich Kulawiec said: > Slightly more seriously: there is no substantive difference between any > of these other than their tactics. I guess we'll have to agree to disagree then. Somehow, I think when you conflate Facebook's sending overenthusiastic invite reminde

Re: [funsec] "Zuck" mail?

2010-12-28 Thread Rich Kulawiec
On Tue, Dec 28, 2010 at 07:15:23AM -0500, valdis.kletni...@vt.edu wrote: > On Tue, 28 Dec 2010 06:34:08 EST, Rich Kulawiec said: > > > Slightly more seriously: there is no substantive difference between any > > of these other than their tactics. > > I guess we'll have to agree to disagree then.

Re: [funsec] "Zuck" mail?

2010-12-28 Thread Joel Esler
Jealous? On Dec 25, 2010, at 1:27 PM, Rob, grandpa of Ryan, Trevor, Devon & Hannah wrote: > X-Mailer: ZuckMail [version 1.00] > > Isn't that taking ego a bit too far? ___ Fun and Misc security discussion for OT posts. https://linuxbox.org/cgi-bin/m

Re: [funsec] "Zuck" mail?

2010-12-28 Thread Rob, grandpa of Ryan, Trevor, Devon & Hannah
From: Joel Esler Date sent: Tue, 28 Dec 2010 10:47:07 -0500 > Jealous? True ... == (quote inserted randomly by Pegasus Mailer) rsl...@vcn.bc.ca sl...@victoria.tc.ca rsl...@computercrime.org Ignorance is never out of style. It was in f

Re: [funsec] "Zuck" mail?

2010-12-28 Thread der Mouse
> And I think that a plausible argument can be made that what Facebook > et.al. are doing is worse -- in the long run, not in the > obvious/immediate sense. I think I agree. It accustoms people to think that spamming is OK, when you're...I don't know, popular? rich? big? enough. /~\ The ASCII

Re: [funsec] "Zuck" mail?

2010-12-28 Thread Valdis . Kletnieks
On Tue, 28 Dec 2010 12:54:24 EST, der Mouse said: > > And I think that a plausible argument can be made that what Facebook > > et.al. are doing is worse -- in the long run, not in the > > obvious/immediate sense. > > I think I agree. > > It accustoms people to think that spamming is OK, when you'

Re: [funsec] "Zuck" mail?

2010-12-28 Thread security curmudgeon
On Tue, 28 Dec 2010, valdis.kletni...@vt.edu wrote: : On Tue, 28 Dec 2010 06:34:08 EST, Rich Kulawiec said: : : > Slightly more seriously: there is no substantive difference between any : > of these other than their tactics. : : I guess we'll have to agree to disagree then. Somehow, I think wh

Re: [funsec] "Zuck" mail?

2010-12-29 Thread Paul Vixie
r...@gsp.org (Rich Kulawiec) writes: > And I think that a plausible argument can be made that what > Facebook et.al. are doing is worse -- in the long run, not in the > obvious/immediate sense. if you limit it to "in the long run" i'm inclined to agree. noting that with half a billion users, fa

Re: [funsec] "Zuck" mail?

2010-12-30 Thread Rich Kulawiec
On Tue, Dec 28, 2010 at 03:16:38PM -0500, valdis.kletni...@vt.edu wrote: > Letting your dog crap on your neighbor's lawn is not OK. > > Dumping your nuclear power plant's waste on your neighbor's lawn > is also not OK. > > But they're certainly *not* the same amount of "not OK" (unless maybe your

Re: [funsec] "Zuck" mail?

2010-12-31 Thread Florian Weimer
* security curmudgeon: > I have been using this e-mail address for around 10 years, and I cannot > recall getting a single spam e-mail advertising kiddie-porn sites in that > time. There has been a redirector-based spam campaign for a Russian-language site which appeared to host child abuse ima

Re: [funsec] "Zuck" mail?

2010-12-31 Thread Florian Weimer
* grandpa of Ryan Rob: > X-Mailer: ZuckMail [version 1.00] > > Isn't that taking ego a bit too far? The "z" could be voiceless. -- Florian Weimer BFK edv-consulting GmbH http://www.bfk.de/ Kriegsstraße 100 tel: +49-721-96201-1 D-76133 Karlsruhe f

Re: [funsec] "Zuck" mail?

2010-12-31 Thread der Mouse
> i don't know how to be in the business facebook is in without an > error rate which when multiplied by their transaction volume and > customer base size does not result in unwanted bulk e-mail. Quite so. But there is no need for the mail to be egregious ads. There is no need for it to be as eas

Re: [funsec] "Zuck" mail?

2011-01-06 Thread Rich Kulawiec
On Wed, Dec 29, 2010 at 11:38:54PM +, Paul Vixie wrote: > what advice -- useful, pertinent, realistic advice -- can we give to facebook? As other folks have noted here: 1. Do not create an account until/unless confirmation email is acted on. Set a sunset date for that (a week?). Track IP ad