Spamming
Electronic spamming is the use of electronic messaging systems to send unsolicited messages (spam), especially advertising, as well as sending messages repeatedly on the same site. While the most widely recognized form of spam is email spam, the term is applied to similar abuses in other media: instant messaging spam, Usenet newsgroup spam, Web search engine spam, spam in blogs, wiki spam, online classified ads spam, mobile phone messaging spam, Internet forum spam, junk fax transmissions, social spam, television advertising and file sharing spam. It is named after Spam, a luncheon meat, by way of a Monty Python sketch in which Spam is included in every dish.[1] The food is stereotypically disliked/unwanted, so the word came to be transferred by analogy.
Spamming remains economically viable because advertisers have no operating costs beyond the management of their mailing lists, and it is difficult to hold senders accountable for their mass mailings. Because the barrier to entry is so low, spammers are numerous, and the volume of unsolicited mail has become very high. In the year 2011, the estimated figure for spam messages is around seven trillion. The costs, such as lost productivity and fraud, are borne by the public and by Internet service providers, which have been forced to add extra capacity to cope with the deluge. Spamming has been the subject of legislation in many jurisdictions.[2]
A person who creates electronic spam is called a spammer.[3]
Etymology
The term spam is derived from the 1970 Spam sketch of the BBC television comedy series Monty Python's Flying Circus.[4] The sketch is set in a cafe where nearly every item on the menu includes Spam canned luncheon meat. As the waiter recites the Spam-filled menu, a chorus of Viking patrons drowns out all conversations with a song repeating "Spam, Spam, Spam, Spam… lovely Spam! wonderful Spam!", hence "Spamming" the dialogue.[5] The excessive amount of Spam mentioned in the sketch is a reference to the preponderance of imported canned meat products in the United Kingdom, particularly a brand of tinned pork and ham (SPAM) from the USA, in the years after World War II, as the country struggled to rebuild its agricultural base. Spam captured a large slice of the British market within lower economic classes and became a byword among British children of the 1960s for low-grade fodder due to its commonality, monotonous taste and cheap price — hence the humour of the Python sketch.
In the 1980s the term was adopted to describe certain abusive users who frequented BBSs and MUDs, who would repeat "Spam" a huge number of times to scroll other users' text off the screen.[6] In early chat rooms services like PeopleLink and the early days of Online America (later known as America Online or AOL), they actually flooded the screen with quotes from the Monty Python Spam sketch. With internet connections over phone lines, typically running at 1200 or even 300 bit/s, it could take an enormous amount of time for a spammy logo, drawn in ASCII art to scroll to completion on a viewer's terminal. Sending an irritating, large, meaningless block of text in this way was called spamming. This was used as a tactic by insiders of a group that wanted to drive newcomers out of the room so the usual conversation could continue. It was also used to prevent members of rival groups from chatting—for instance, Star Wars fans often invaded Star Trek chat rooms, filling the space with blocks of text until the Star Trek fans left.[7] This act, previously called flooding or trashing, came to be known as spamming.[8] The term was soon applied to a large amount of text broadcast by many users.
It later came to be used on Usenet to mean excessive multiple posting—the repeated posting of the same message. The unwanted message would appear in many, if not all newsgroups, just as Spam appeared in nearly all the menu items in the Monty Python sketch. The first usage of this sense was by Joel Furr[9] in the aftermath of the ARMM incident of March 31, 1993, in which a piece of experimental software released dozens of recursive messages onto the news.admin.policy newsgroup.[10] This use had also become established—to spam Usenet was flooding newsgroups with junk messages. The word was also attributed to the flood of "Make Money Fast" messages that clogged many newsgroups during the 1990s. In 1998, the New Oxford Dictionary of English, which had previously only defined "spam" in relation to the trademarked food product, added a second definition to its entry for "spam": "Irrelevant or inappropriate messages sent on the Internet to a large number of newsgroups or users."
There was also an effort to differentiate between types of newsgroup spam. Messages that were crossposted to too many newsgroups at once – as opposed to those that were posted too frequently – were called velveeta (after a cheese product). But this term didn't persist.[11]
History
Pre-Internet
In the late 19th Century Western Union allowed telegraphic messages on its network to be sent to multiple destinations. The first recorded instance of a mass unsolicited commercial telegram is from May 1864, when some British politicians received an unsolicited telegram advertising a dentistry shop.[12]
History
Earliest documented spam (although the term had not yet been coined[13]) was a message advertising the availability of a new model of Digital Equipment Corporation computers sent by Gary Thuerk to 393 recipients on ARPANET in 1978.[9] Rather than send a separate message to each person, which was the standard practice at the time, he had an assistant, Carl Gartley, write a single mass email. Reaction from the net community was fiercely negative, but the spam did generate some sales.[14][15]
Spamming had been practiced as a prank by participants in multi-user dungeon games, to fill their rivals' accounts with unwanted electronic junk.[15] The first known electronic chain letter, titled Make Money Fast, was released in 1988.
The first major commercial spam incident started on March 5, 1994, when a husband and wife team of lawyers, Laurence Canter and Martha Siegel, began using bulk Usenet posting to advertise immigration law services. The incident was commonly termed the "Green Card spam", after the subject line of the postings. Defiant in the face of widespread condemnation, the attorneys claimed their detractors were hypocrites or "zealouts", claimed they had a free speech right to send unwanted commercial messages, and labeled their opponents "anti-commerce radicals." The couple wrote a controversial book entitled How to Make a Fortune on the Information Superhighway.[15]
Within a few years, the focus of spamming (and anti-spam efforts) moved chiefly to email, where it remains today.[6] Arguably, the aggressive email spamming by a number of high-profile spammers such as Sanford Wallace of Cyber Promotions in the mid-to-late 1990s contributed to making spam predominantly an email phenomenon in the public mind. By 2009, the majority of spam sent around the World was in the English language; spammers began using automatic translation services to send spam in other languages.[16] In 2014, the Swiss artist M.M. Keupp reproduced original spam letters in his artist's book spam, sex, & random thoughts, interpreting them as readymades."."
In different media
Email spam, also known as unsolicited bulk email (UBE), junk mail, or unsolicited commercial email (UCE), is the practice of sending unwanted email messages, frequently with commercial content, in large quantities to an indiscriminate set of recipients. Spam in email started to become a problem when the Internet was opened up to the general public in the mid-1990s. It grew exponentially over the following years, and today composes some 80 to 85 percent of all the e-mail in the World, by a "conservative estimate".[17] Pressure to make email spam illegal has been successful in some jurisdictions, but less so in others. The efforts taken by governing bodies, security systems and email service providers seem to be helping to reduce the onslaught of email spam. According to "2014 Internet Security Threat Report, Volume 19" published by Symantec Corporation, spam volume dropped to 66% of all email traffic.[18] Spammers take advantage of this fact, and frequently outsource parts of their operations to countries where spamming will not get them into legal trouble.
Increasingly, e-mail spam today is sent via "zombie networks", networks of virus- or worm-infected personal computers in homes and offices around the globe. Many modern worms install a backdoor that allows the spammer to access the computer and use it for malicious purposes. This complicates attempts to control the spread of spam, as in many cases the spam does not obviously originate from the spammer. In November 2008 an ISP, McColo, which was providing service to botnet operators, was depeered and spam dropped 50 to 75 percent Internet-wide. At the same time, it is becoming clear that malware authors, spammers, and phishers are learning from each other, and possibly forming various kinds of partnerships.
An industry of email address harvesting is dedicated to collecting email addresses and selling compiled databases.[19] Some of these address-harvesting approaches rely on users not reading the fine print of agreements, resulting in their agreeing to send messages indiscriminately to their contacts. This is a common approach in social networking spam such as that generated by the social networking site Quechup.[20]
Instant messaging
Instant messaging spam makes use of instant messaging systems. Although less ubiquitous than its e-mail counterpart, according to a report from Ferris Research, 500 million spam IMs were sent in 2003, twice the level of 2002. As instant messaging tends to not be blocked by firewalls, it is an especially useful channel for spammers. This is very common on many instant messaging systems such as Skype.
Newsgroup and forum
Newsgroup spam is a type of spam where the targets are Usenet newsgroups. Spamming of Usenet newsgroups actually pre-dates e-mail spam. Usenet convention defines spamming as excessive multiple posting, that is, the repeated posting of a message (or substantially similar messages). The prevalence of Usenet spam led to the development of the Breidbart Index as an objective measure of a message's "spamminess".
Forum spam is the creation of advertising messages on Internet forums. It is generally done by automated spambots. Most forum spam consists of links to external sites, with the dual goals of increasing search engine visibility in highly competitive areas such as weight loss, pharmaceuticals, gambling, pornography, real estate or loans, and generating more traffic for these commercial websites. Some of these links contain code to track the spambot's identity; if a sale goes through, the spammer behind the spambot works on commission.
Mobile phone
Mobile phone spam is directed at the text messaging service of a mobile phone. This can be especially irritating to customers not only for the inconvenience, but also because of the fee they may be charged per text message received in some markets. The term "SpaSMS" was coined at the adnews website Adland in 2000 to describe spam SMS. To comply with CAN-SPAM regulations in the US, SMS messages now must provide options of HELP and STOP, the latter to end communication with the advertiser via SMS altogether.
Despite the high number of phone users, there has not been so much phone spam, because there is a charge for sending SMS, and installing trojans into other's phones that send spam (common for e-mail spam) is hard because applications normally must be downloaded from a central database.
Social networking spam
Facebook and Twitter are not immune to messages containing spam links. Most insidiously, spammers hack into accounts and send false links under the guise of a user's trusted contacts such as friends and family.[21] As for Twitter, spammers gain credibility by following verified accounts such as that of Lady Gaga; when that account owner follows the spammer back, it legitimizes the spammer and allows him or her to proliferate.[22] Twitter has studied what interest structures allow their users to receive interesting tweets and avoid spam, despite the site using the broadcast model, in which all tweets from a user are broadcast to all followers of the user.[23]
Social spam
Spreading beyond the centrally managed social networking platforms, user-generated content increasingly appears on business, government, and nonprofit websites worldwide. Fake accounts and comments planted by computers programmed to issue social spam can infiltrate these websites.[24] Well-meaning and malicious human users can break websites' policies by submitting profanity,[25] insults,[26] hate speech, and violent messages.
Online game messaging
Many online games allow players to contact each other via player-to-player messaging, chat rooms, or public discussion areas. What qualifies as spam varies from game to game, but usually this term applies to all forms of message flooding, violating the terms of service contract for the website. This is particularly common in MMORPGs where the spammers are trying to sell game-related "items" for real-world money, chiefly among them being in-game currency. In gameplay terms, spamming also refers to the repetitive use of the same combat skills as a cheap tactic (e.g. "to defeat the blue dragon, just spam fireballs").
Spam targeting search engines (spamdexing)
Spamdexing (a portmanteau of spamming and indexing) refers to a practice on the World Wide Web of modifying HTML pages to increase their chances of high placement on search engine relevancy lists. These sites use "black-hat" search engine optimization techniques to deliberately manipulate their rank in search engines. Many modern search engines modified their search algorithms to try to exclude web pages utilizing spamdexing tactics. For example, the search bots will detect repeated keywords as spamming by using a grammar analysis. If a website owner is found to have spammed the webpage to falsely increase its page rank, the website may be penalized by search engines.
Blog, wiki, and guestbook
Blog spam, or "blam" for short, is spamming on weblogs. In 2003, this type of spam took advantage of the open nature of comments in the blogging software Movable Type by repeatedly placing comments to various blog posts that provided nothing more than a link to the spammer's commercial web site.[27] Similar attacks are often performed against wikis and guestbooks, both of which accept user contributions. Another possible form of spam in blogs is the spamming of a certain tag on websites such as Tumblr.
Spam targeting video sharing sites
Video sharing sites, such as YouTube, are now frequently targeted by spammers. The most common technique involves spammers (or spambots) posting links to sites, most likely pornographic or dealing with online dating, on the comments section of random videos or user profiles. With the addition of a "thumbs up/thumbs down" feature, groups of spambots may constantly "thumbs up" a comment, getting it into the top comments section and making the message more visible. Another frequently used technique is using bots to post messages on random users' profiles to a spam account's channel page, along with enticing text and images, usually of a sexually suggestive nature. These pages may include their own or other users' videos, again often suggestive. The main purpose of these accounts is to draw people to the link in the home page section of their profile. YouTube has blocked the posting of such links. In addition, YouTube has implemented a CAPTCHA system that makes rapid posting of repeated comments much more difficult than before, because of abuse in the past by mass spammers who would flood individuals' profiles with thousands of repetitive comments.
Yet another kind is actual video spam, giving the uploaded movie a name and description with a popular figure or event that is likely to draw attention, or within the video has a certain image timed to come up as the video's thumbnail image to mislead the viewer, such as a still image from a feature film, purporting to be a part-by-part piece of a movie being pirated, e.g. Big Buck Bunny Full Movie Online - Part 1/10 HD, a link to a supposed keygen, trainer, ISO file for a video game, or something similar. The actual content of the video ends up being totally unrelated, a Rickroll, offensive, or simply on-screen text of a link to the site being promoted.[28] In some cases, the link in question may lead to an online survey site, a password-protected archive file with instructions leading to the aforementioned survey (though the survey, and the archive file itself, is worthless and doesn't contain the file in question at all), or in extreme cases, malware.[29] Others may upload videos presented in an infomercial-like format selling their product which feature actors and paid testimonials, though the promoted product or service is of dubious quality and would likely not pass the scrutiny of a standards and practices department at a television station or cable network.
SPIT
SPIT (SPam over Internet Telephony) is VoIP (Voice over Internet Protocol) spam, usually using SIP (Session Initiation Protocol). This is nearly identical to telemarketing calls over traditional phone lines. When the user chooses to receive the spam call, a pre-recorded spam message or advertisement is usually played back. This is generally easier for the spammer as VoIP services are cheap and easy to anonymize over the Internet, and there are many options for sending mass amounts of calls from a single location. Accounts or IP addresses being used for VoIP spam can usually be identified by a large number of outgoing calls, low call completion and short call length.
Academic search
Academic search engines enable researchers to find academic literature and are used to obtain citation data for calculating performance metrics such as the H-index and impact factor. Researchers from the University of California, Berkeley and OvGU demonstrated that most (web-based) academic search engines, especially Google Scholar, are not capable of identifying spam attacks.[30] The researchers manipulated the citation counts of articles, and managed to make Google Scholar index complete fake articles, some containing advertising.[30]
Noncommercial forms
E-mail and other forms of spamming have been used for purposes other than advertisements. Many early Usenet spams were religious or political. Serdar Argic, for instance, spammed Usenet with historical revisionist screeds. A number of evangelists have spammed Usenet and e-mail media with preaching messages. A growing number of criminals are also using spam to perpetrate various sorts of fraud.[31]
Geographical origins
A 2011 Cisco Systems report shows spam volume originating from countries worldwide.[32]
Rank | Country | Spam volume(%) |
---|---|---|
1 | India | 13.7 |
2 | Russia | 9.0 |
3 | Vietnam | 7.9 |
4 (tie) |
South Korea | 6.0 |
Indonesia | 6.0 | |
6 | China | 4.7 |
7 | Brazil | 4.5 |
8 | United States | 3.2 |
Trademark issues
Hormel Foods Corporation, the maker of SPAM luncheon meat, does not object to the Internet use of the term "spamming". However, they did ask that the capitalized word "Spam" be reserved to refer to their product and trademark.[33] By and large, this request is obeyed in forums that discuss spam. In Hormel Foods v. SpamArrest, Hormel attempted to assert its trademark rights against SpamArrest, a software company, from using the mark "spam", since Hormel owns the trademark. In a dilution claim, Hormel argued that SpamArrest's use of the term "spam" had endangered and damaged "substantial goodwill and good reputation" in connection with its trademarked lunch meat and related products. Hormel also asserted that SpamArrest's name so closely resembles its luncheon meat that the public might become confused, or might think that Hormel endorses SpamArrest's products.
Hormel did not prevail. Attorney Derek Newman responded on behalf of SpamArrest: "Spam has become ubiquitous throughout the [w]orld to describe unsolicited commercial email. No company can claim trademark rights on a generic term." Hormel stated on its website: "Ultimately, we are trying to avoid the day when the consuming public asks, 'Why would Hormel Foods name its product after junk email?'".[34]
Hormel also made two attempts that were dismissed in 2005 to revoke the marks "SPAMBUSTER"[35] and Spam Cube.[36] Hormel's corporate attorney Melanie J. Neumann also sent SpamCop's Julian Haight a letter on August 27, 1999 requesting that he delete an objectionable image (a can of Hormel's Spam luncheon meat product in a trash can), change references to UCE spam to all lower case letters, and confirm his agreement to do so.[37]
Cost-benefit analyses
The European Union's Internal Market Commission estimated in 2001 that "junk email" cost Internet users €10 billion per year worldwide.[38] The California legislature found that spam cost United States organizations alone more than $13 billion in 2007, including lost productivity and the additional equipment, software, and manpower needed to combat the problem.[39] Spam's direct effects include the consumption of computer and network resources, and the cost in human time and attention of dismissing unwanted messages.[40] Large companies who are frequent spam targets utilize numerous techniques to detect and prevent spam.[41]
In addition, spam has costs stemming from the kinds of spam messages sent, from the ways spammers send them, and from the arms race between spammers and those who try to stop or control spam. In addition, there are the opportunity cost of those who forgo the use of spam-afflicted systems. There are the direct costs, as well as the indirect costs borne by the victims—both those related to the spamming itself, and to other crimes that usually accompany it, such as financial theft, identity theft, data and intellectual property theft, virus and other malware infection, child pornography, fraud, and deceptive marketing.
The cost to providers of search engines is not insignificant: "The secondary consequence of spamming is that search engine indexes are inundated with useless pages, increasing the cost of each processed query".[3] The methods of spammers are likewise costly. Because spamming contravenes the vast majority of ISPs' acceptable-use policies, most spammers have for many years gone to some trouble to conceal the origins of their spam. Email, Usenet, and instant-message spam are often sent through insecure proxy servers belonging to unwilling third parties. Spammers frequently use false names, addresses, phone numbers, and other contact information to set up "disposable" accounts at various Internet service providers. In some cases, they have used falsified or stolen credit card numbers to pay for these accounts. This allows them to quickly move from one account to the next as each one is discovered and shut down by the host ISPs.
The costs of spam also include the collateral costs of the struggle between spammers and the administrators and users of the media threatened by spamming.[42] Many users are bothered by spam because it impinges upon the amount of time they spend reading their email. Many also find the content of spam frequently offensive, in that pornography is one of the most frequently advertised products. Spammers send their spam largely indiscriminately, so pornographic ads may show up in a work place email inbox—or a child's, the latter of which is illegal in many jurisdictions. Recently, there has been a noticeable increase in spam advertising websites that contain child pornography.
Some spammers argue that most of these costs could potentially be alleviated by having spammers reimburse ISPs and persons for their material. There are three problems with this logic: first, the rate of reimbursement they could credibly budget is not nearly high enough to pay the direct costs , second, the human cost (lost mail, lost time, and lost opportunities) is basically unrecoverable, and third, spammers often use stolen bank accounts and credit cards to finance their operations, and would conceivably do so to pay off any fines imposed.
Email spam exemplifies a tragedy of the commons: spammers use resources (both physical and human), without bearing the entire cost of those resources. In fact, spammers commonly do not bear the cost at all. This raises the costs for everyone. In some ways spam is even a potential threat to the entire email system, as operated in the past. Since email is so cheap to send, a tiny number of spammers can saturate the Internet with junk mail. Although only a tiny percentage of their targets are motivated to purchase their products (or fall victim to their scams), the low cost may provide a sufficient conversion rate to keep the spamming alive. Furthermore, even though spam appears not to be economically viable as a way for a reputable company to do business, it suffices for professional spammers to convince a tiny proportion of gullible advertisers that it is viable for those spammers to stay in business. Finally, new spammers go into business every day, and the low costs allow a single spammer to do a lot of harm before finally realizing that the business is not profitable.
Some companies and groups "rank" spammers; spammers who make the news are sometimes referred to by these rankings.[43][44] The secretive nature of spamming operations makes it difficult to determine how prolific an individual spammer is, thus making the spammer hard to track, block or avoid. Also, spammers may target different networks to different extents, depending on how successful they are at attacking the target. Thus considerable resources are employed to actually measure the amount of spam generated by a single person or group. For example, victims that use common anti-spam hardware, software or services provide opportunities for such tracking. Nevertheless, such rankings should be taken with a grain of salt.
General costs
In all cases listed above, including both commercial and non-commercial, "spam happens" because of a positive cost-benefit analysis result; if the cost to recipients is excluded as an externality the spammer can avoid paying.
Cost is the combination of
- Overhead: The costs and overhead of electronic spamming include bandwidth, developing or acquiring an email/wiki/blog spam tool, taking over or acquiring a host/zombie, etc.
- Transaction cost: The incremental cost of contacting each additional recipient once a method of spamming is constructed, multiplied by the number of recipients (see CAPTCHA as a method of increasing transaction costs).
- Risks: Chance and severity of legal and/or public reactions, including damages and punitive damages.
- Damage: Impact on the community and/or communication channels being spammed (see Newsgroup spam).
Benefit is the total expected profit from spam, which may include any combination of the commercial and non-commercial reasons listed above. It is normally linear, based on the incremental benefit of reaching each additional spam recipient, combined with the conversion rate. The conversion rate for botnet-generated spam has recently been measured to be around one in 12,000,000 for pharmaceutical spam and one in 200,000 for infection sites as used by the Storm botnet.[45] The authors of the study calculating those conversion rates noted, "After 26 days, and almost 350 million e-mail messages, only 28 sales resulted."
In crime
Spam can be used to spread computer viruses, trojan horses or other malicious software. The objective may be identity theft, or worse (e.g., advance fee fraud). Some spam attempts to capitalize on human greed, while some attempts to take advantage of the victims' inexperience with computer technology to trick them (e.g., phishing). On May 31, 2007, one of the world's most prolific spammers, Robert Alan Soloway, was arrested by US authorities.[46] Described as one of the top ten spammers in the world, Soloway was charged with 35 criminal counts, including mail fraud, wire fraud, e-mail fraud, aggravated identity theft, and money laundering.[46] Prosecutors allege that Soloway used millions of "zombie" computers to distribute spam during 2003.[47] This is the first case in which US prosecutors used identity theft laws to prosecute a spammer for taking over someone else's Internet domain name.
In an attempt to assess potential legal and technical strategies for stopping illegal spam, a study from the University of California, San Diego, and the University of California, Berkeley, "Click Trajectories: End-to-End Analysis of the Spam Value Chain", cataloged three months of online spam data and researched website naming and hosting infrastructures. The study concluded that: 1) half of all spam programs have their domains and servers distributed over just eight percent or fewer of the total available hosting registrars and autonomous systems, with 80 percent of spam programs overall being distributed over just 20 percent of all registrars and autonomous systems; 2) of the 76 purchases for which the researchers received transaction information, there were only 13 distinct banks acting as credit card acquirers and only three banks provided the payment servicing for 95 percent of the spam-advertised goods in the study; and, 3) a "financial blacklist" of banking entities that do business with spammers would dramatically reduce monetization of unwanted e-mails. Moreover, this blacklist could be updated far more rapidly than spammers could acquire new banking resources, an asymmetry favoring anti-spam efforts.[48]
Political issues
Spamming remains a hot discussion topic. In 2004, the seized Porsche of an indicted spammer was advertised on the Internet;[49] this revealed the extent of the financial rewards available to those who are willing to commit duplicitous acts online. However, some of the possible means used to stop spamming may lead to other side effects, such as increased government control over the Internet, loss of privacy, barriers to free expression, and the commercialization of e-mail.
One of the chief values favored by many long-time Internet users and experts, as well as by many members of the public, is the free exchange of ideas. Many have valued the relative anarchy of the Internet, and bridle at the idea of restrictions placed upon it. A common refrain from spam-fighters is that spamming itself abridges the historical freedom of the Internet, by attempting to force users to carry the costs of material that they would not choose.
An ongoing concern expressed by parties such as the Electronic Frontier Foundation and the American Civil Liberties Union has to do with so-called "stealth blocking", a term for ISPs employing aggressive spam blocking without their users' knowledge. These groups' concern is that ISPs or technicians seeking to reduce spam-related costs may select tools that (either through error or design) also block non-spam e-mail from sites seen as "spam-friendly". Spam Prevention Early Warning System (SPEWS) is a common target of these criticisms. Few object to the existence of these tools; it is their use in filtering the mail of users who are not informed of their use that draws fire.
Some see spam-blocking tools as a threat to free expression—and laws against spamming as an untoward precedent for regulation or taxation of e-mail and the Internet at large. Even though it is possible in some jurisdictions to treat some spam as unlawful merely by applying existing laws against trespass and conversion, some laws specifically targeting spam have been proposed. In 2004, United States passed the CAN-SPAM Act of 2003 that provided ISPs with tools to combat spam. This act allowed Yahoo! to successfully sue Eric Head, reportedly one of the biggest spammers in the World, who settled the lawsuit for several thousand U.S. dollars in June 2004. But the law is criticized by many for not being effective enough. Indeed, the law was supported by some spammers and organizations that support spamming, and opposed by many in the anti-spam community. Examples of effective anti-abuse laws that respect free speech rights include those in the U.S. against unsolicited faxes and phone calls, and those in Australia and a few U.S. states against spam.
In November 2004, Lycos Europe released a screen saver called make LOVE not SPAM that made Distributed Denial of Service attacks on the spammers themselves. It met with a large amount of controversy and the initiative ended in December 2004.[50][51][52]
Anti-spam policies may also be a form of disguised censorship, a way to ban access or reference to questioning alternative forums or blogs by an institution. This form of occult censorship is mainly used by private companies when they cannot muzzle criticism by legal ways.[53]
Court cases
United States
Sanford Wallace and Cyber Promotions were the target of a string of lawsuits, many of which were settled out of court, up through a 1998 Earthlink settlement that put Cyber Promotions out of business. Attorney Laurence Canter was disbarred by the Tennessee Supreme Court in 1997 for sending prodigious amounts of spam advertising his immigration law practice. In 2005, Jason Smathers, a former America Online employee, pled guilty to charges of violating the CAN-SPAM Act. In 2003, he sold a list of approximately 93 million AOL subscriber e-mail addresses to Sean Dunaway who, in turn, sold the list to spammers.[54][55]
In 2007, Robert Soloway lost a case in a federal court against the operator of a small Oklahoma-based Internet service provider who accused him of spamming. U.S. Judge Ralph G. Thompson granted a motion by plaintiff Robert Braver for a default judgment and permanent injunction against him. The judgment includes a statutory damages award of $10,075,000 under Oklahoma law.[56]
In June 2007, two men were convicted of eight counts stemming from sending millions of e-mail spam messages that included hardcore pornographic images. Jeffrey A. Kilbride, 41, of Venice, California was sentenced to six years in prison, and James R. Schaffer, 41, of Paradise Valley, Arizona, was sentenced to 63 months. In addition, the two were fined $100,000, ordered to pay $77,500 in restitution to AOL, and ordered to forfeit more than $1.1 million, the amount of illegal proceeds from their spamming operation.[57] The charges included conspiracy, fraud, money laundering, and transportation of obscene materials. The trial, which began on June 5, was the first to include charges under the CAN-SPAM Act of 2003, according to a release from the Department of Justice. The specific law that prosecutors used under the CAN-Spam Act was designed to crack down on the transmission of pornography in spam.[58]
In 2005, Scott J. Filary and Donald E. Townsend of Tampa, Florida were sued by Florida Attorney General Charlie Crist for violating the Florida Electronic Mail Communications Act.[59] The two spammers were required to pay $50,000 USD to cover the costs of investigation by the state of Florida, and a $1.1 million penalty if spamming were to continue, the $50,000 was not paid, or the financial statements provided were found to be inaccurate. The spamming operation was successfully shut down.[60]
Edna Fiedler, 44, of Olympia, Washington, on June 25, 2008, pleaded guilty in a Tacoma court and was sentenced to 2 years imprisonment and 5 years of supervised release or probation in an Internet $1 million "Nigerian check scam." She conspired to commit bank, wire and mail fraud, against US citizens, specifically using Internet by having had an accomplice who shipped counterfeit checks and money orders to her from Lagos, Nigeria, last November. Fiedler shipped out $609,000 fake check and money orders when arrested and prepared to send additional $1.1 million counterfeit materials. Also, the U.S. Postal Service recently intercepted counterfeit checks, lottery tickets and eBay overpayment schemes with a face value of $2.1 billion.[61][62]
In a 2009 opinion, Gordon v. Virtumundo, Inc., 575 F.3d 1040, the Ninth Circuit assessed the standing requirements necessary for a private plaintiff to bring a civil cause of action against spam senders under the CAN-SPAM Act of 2003, as well as the scope of the CAN-SPAM Act's federal preemption clause.[63]
United Kingdom
In the first successful case of its kind, Nigel Roberts from the Channel Islands won £270 against Media Logistics UK who sent junk e-mails to his personal account.[64]
In January 2007, a Sheriff Court in Scotland awarded Mr. Gordon Dick £750 (the then maximum sum that could be awarded in a Small Claim action) plus expenses of £618.66, a total of £1368.66 against Transcom Internet Services Ltd.[65] for breaching anti-spam laws.[66] Transcom had been legally represented at earlier hearings, but were not represented at the proof, so Gordon Dick got his decree by default. It is the largest amount awarded in compensation in the United Kingdom since Roberts v Media Logistics case in 2005.
Despite the statutory tort that is created by the Regulations implementing the EC Directive, few other people have followed their example. As the Courts engage in active case management, such cases would probably now be expected to be settled by mediation and payment of nominal damages.
New Zealand
In October 2008, a vast international internet spam operation run from New Zealand was cited by American authorities as one of the world’s largest, and for a time responsible for up to a third of all unwanted e-mails. In a statement the US Federal Trade Commission (FTC) named Christchurch’s Lance Atkinson as one of the principals of the operation. New Zealand’s Internal Affairs announced it had lodged a $200,000 claim in the High Court against Atkinson and his brother Shane Atkinson and courier Roland Smits, after raids in Christchurch. This marked the first prosecution since the Unsolicited Electronic Messages Act (UEMA) was passed in September 2007. The FTC said it had received more than three million complaints about spam messages connected to this operation, and estimated that it may be responsible for sending billions of illegal spam messages. The US District Court froze the defendants’ assets to preserve them for consumer redress pending trial.[67] U.S. co-defendant Jody Smith forfeited more than $800,000 and faces up to five years in prison for charges to which he pled guilty.[68]
Bulgaria
While most countries either outlaw or at least ignore spam, Bulgaria is the first and until now only one to legalize it. According to the Bulgarian E-Commerce act[69] (Чл.5,6) anyone can send spam to mailboxes published as owned by a company or organization, as long as there is a "clear and straight indication that the message is unsolicited commercial e-mail" ("да осигури ясното и недвусмислено разпознаване на търговското съобщение като непоискано") in the message body.
This made lawsuits against Bulgarian ISP's and public e-mail providers with antispam policy possible, as they are obstructing legal commerce activity and thus violate Bulgarian antitrust acts. While there are no such lawsuits until now, several cases of spam obstruction are currently awaiting decision in the Bulgarian Antitrust Commission (Комисия за защита на конкуренцията) and can end with serious fines for the ISP's in question.
The law contains other dubious provisions — for example, the creation of a nationwide public electronic register of e-mail addresses that do not want to receive spam.[70] It is usually abused as the perfect source for e-mail address harvesting, because publishing invalid or incorrect information in such a register is a criminal offense in Bulgaria.
Newsgroups
Psyhology
Approach and avoidance, psychologists describe as reasons why people click on most spams.[71]
See also
|
References
Notes
- ↑ "Spam". Merriam-Webster Dictionary (definition & more). 2012-08-31. Retrieved 2013-07-05.
- ↑ "The Definition of Spam". The Spamhaus Project. Retrieved 2013-09-03.
- 1 2 Gyöngyi, Zoltan; Garcia-Molina, Hector (2005). "Web spam taxonomy" (PDF). Proceedings of the First International Workshop on Adversarial Information Retrieval on the Web (AIRWeb), 2005 in The 14th International World Wide Web Conference (WWW 2005) May 10, (Tue) – 14 (Sat), 2005, Nippon Convention Center (Makuhari Messe), Chiba, Japan (PDF) . New York, NY: ACM Press. ISBN 1-59593-046-9.
- ↑ "RFC 2635 - DON\x27T SPEW A Set of Guidelines for Mass Unsolicited Mailings and Postings (spam*):". Retrieved 2010-09-29.
- ↑ "The Origin of the word 'Spam':". Retrieved 2010-09-20.
- 1 2 "Origin of the term "spam" to mean net abuse". Templetons.com. Retrieved 2013-09-03.
- ↑ Goldberg, Myshele. "The Origins of Spam". Retrieved 2014-07-15.
- ↑ Spamming? (rec.games.mud) - Google Groups USENET archive, 1990-09-26
- 1 2 Thuerk, Gary; Furr, Joel, At 30, Spam Going Nowhere Soon (interviews), NPR.
- ↑ Darren Waters (31 March 2008). "Spam blights e-mail 15 years on". news.bbc.co.uk. Retrieved 26 August 2010.
- ↑ "velveeta", The Jargon File (4.4.7 ed.), CatB.
- ↑ "Getting the message, at last". The Economist. 2007-12-14.
- ↑ Zeller, Tom (1 June 2003). "Ideas & Trends; Spamology". The New York Times.
- ↑ "Reaction to the DEC Spam of 1978". Templetons. Retrieved 2013-09-03.
- 1 2 3 Abate, Tom (May 3, 2008). "A very unhappy birthday to spam, age 30". San Francisco Chronicle.
- ↑ Danchev, Dancho. "Spammers go multilingual, use automatic translation services." ZDNet. July 28, 2009. Retrieved on August 31, 2009.
- ↑ "Email Metrics Report" (PDF). MAAWG.
- ↑ "2014 Internet Security Threat Report, Volume 19" (PDF). Symantec Corporation. Retrieved 7 May 2014.
- ↑ "FileOn List Builder-Extract URL, MetaTags, Email, Phone, Fax from www-Optimized Webcrawler". List DNA. Retrieved 2013-09-03.
- ↑ Hansell, Saul (September 13, 2007), "Social network launches worldwide spam campaign", The New York Times.
- ↑ "Marketers need to build trust as spam hits social networks", Grace Bello, Direct Marketing News, June 1, 2012
- ↑ Understanding and Combating Link Farming in the Twitter Social Network, Max Planck Centre for Computer Science
- ↑ On the Precision of Social and Information Networks
- ↑ Dan Tynan (3 April 2012). "Social spam is taking over the Internet". ITworld.
- ↑
- ↑ "Professor: Social media can fuel spread of racial slurs, hate speech". sentinelandenterprise.com.
- ↑ The (Evil) Genius of Comment Spammers - Wired Magazine, March 2004
- ↑ Fabrício Benevenuto, Tiago Rodrigues, Virgílio Almeida, Jussara Almeida and Marcos Gonçalves. Detecting Spammers and Content Promoters in Online Video Social Networks. In ACM SIGIR Conference, Boston, MA, USA, July 2009.
- ↑ "Toy Story 3 movie scam warning". Web User magazine. Retrieved 23 January 2012.
- 1 2 Joeran Beel and Bela Gipp. Academic search engine spam and google scholar’s resilience against it. Journal of Electronic Publishing, 13(3), December 2010. PDF
- ↑ See: Advance fee fraud
- ↑ Cisco 2011 Annual Security Report (PDF)
- ↑ "Hormel Foods Corp. v. Jim Henson Prods". Harvard University. 73 F.3d 497 (2d Cir. 1996). Retrieved 2015-02-12.
- ↑ "Hormel Foods v SpamArrest, Motion for Summary Judgment, Redacted Version" (PDF). Spam arrest. Retrieved 2013-09-03.
- ↑ "Richard Arnold sitting as a deputy high court Judge". Vision Systems. Court cases. January 24, 2005.
- ↑ "Hormel Foods Corporation v. Spam Cube, Inc". United States Patent and Trademark Office. Retrieved 2008-02-12.
- ↑ "Letter from Hormel's Corporate Attorney Melanie J. Neumann to SpamCop's Julian Haight" (GIF). Spam cop. Retrieved 2013-09-03.
- ↑ "Data protection: "Junk" email costs internet users 10 billion a year worldwide – Commission study". Europa. Retrieved 2013-09-03.
- ↑ "California business and professions code". Spamlaws. Retrieved 2013-09-03.
- ↑ "Spam Cost Calculator: Calculate enterprise spam cost?". Commtouch. Retrieved 2013-09-03.
- ↑ Ghosemajumder, Shuman (18 March 2008). "Using data to help prevent fraud". Google Blog. Retrieved 12 August 2011.
- ↑ Thank the Spammers - William R. James 2003-03-10
- ↑ Spamhaus' "TOP 10 spam service ISPs"
- ↑ "The 10 Worst ROKSO Spammers". Spamhaus. Retrieved 2013-09-03.
- ↑ Kanich, C.; C. Kreibich; K. Levchenko; B. Enright; G. Voelker; V. Paxson; S. Savage (2008-10-28). "Spamalytics: An Empirical Analysis of Spam Marketing Conversion" (PDF). Proceedings of Conference on Computer and Communications Security (CCS). Alexandria, VA, USA. Retrieved 2008-11-05.
- 1 2 Lombardi, Candace. "Alleged 'Seattle Spammer' arrested - CNET". News.com. Retrieved 2013-09-03.
- ↑ Claburn, Thomas. "'Spam King' Robert Alan Soloway Pleads Guilty". InformationWeek.com , 3/17/2008.
- ↑ Levchenko, Kirill; et. al. (2011). "Click Trajectories: End-to-End Analysis of the Spam Value Chain" (PDF). 2011 IEEE Symposium on Security and Privacy: 431–446. doi:10.1109/SP.2011.24.
- ↑ "timewarner.com". timewarner.com. Retrieved 2013-09-03.
- ↑ Screensaver tackles spam websites BBC News Online. 29 November 2004
- ↑ Anti-spam plan overwhelms sites BBC News Online. 2 December 2004
- ↑ Anti-spam screensaver scrapped BBC News Online. 6 December 2004
- ↑ See for instance the black list of the French Wikipedia encyclopedia
- ↑ U.S. v Jason Smathers and Sean Dunaway, amended complaint, US District Court for the Southern District of New York (2003). Retrieved 7 March 2007, from "Pair Nabbed In AOL Spam Scheme". thesmokinggun.com.
- ↑ Ex-AOL employee pleads guilty in spam case. (2005, February 4). CNN. Retrieved 7 March 2007, from "Ex-AOL employee pleads guilty in spam case". CNN.com. February 5, 2005. Retrieved 27 August 2010.
- ↑ Braver v. Newport Internet Marketing Corporation et al. -U.S. District Court - Western District of Oklahoma (Oklahoma City), 2005-02-22
- ↑ "Two Men Sentenced for Running International Pornographic Spamming Business". United States Department of Justice. October 12, 2007. Retrieved 2007-10-25.
- ↑ Gaudin, Sharon, Two Men Convicted Of Spamming Pornography InformationWeek, June 26, 2007
- ↑ "Crist Announces First Case Under Florida Anti-Spam Law". Office of the Florida Attorney General. Archived from the original on 15 January 2009. Retrieved 21 December 2014.
- ↑ "Crist: Judgment Ends Duo's Illegal Spam, Internet Operations". Office of the Florida Attorney General. Archived from the original on 15 January 2009. Retrieved 21 December 2014.
- ↑ "Woman gets prison for 'Nigerian' scam". upi.com.
- ↑ "Woman Gets Two Years for Aiding Nigerian Internet Check Scam (PC World)". PC World. Retrieved 2014-01-30.
- ↑ Gordon v. Virtumundo, Inc., 575 F.3d 1040 (9th Cir. 2009).
- ↑ "Businessman wins e-mail spam case". BBC News. 27 December 2005. Retrieved 13 November 2011.
- ↑ "Gordon Dick v Transcom Internet Service Ltd". Scotchspam.co.uk. Retrieved 2013-09-03.
- ↑ "Article 13-Unsolicited communications". Eur-lex.europa.eu. Retrieved 2013-09-03.
- ↑ "Kiwi spam network was 'World's biggest'". Stuff.co.nz. 16 October 2008. Retrieved 13 November 2011.
- ↑ "Court Orders Australia-based Leader of International Spam Network to Pay $15.15 Million". Ftc.gov. 2011-06-24. Retrieved 2013-09-03.
- ↑ "Закон За Електронната Търговия". Lex.bg. 2011-08-14. Retrieved 2013-09-03.
- ↑ "Регистър на юридическите лица, които не желаят да получават непоискани търговски съобщения". Kzp.bg. Retrieved 2013-09-03.
- ↑ Spam: The Money, Psychology and Business of Spam
Sources
- Specter, Michael (2007-08-06). "Damn Spam". The New Yorker. Retrieved 2007-08-02.
Further reading
- Brunton, Finn. Spam: A Shadow History of the Internet (MIT Press; 2013) 304 pages; $27.95). A cultural and technological history
- Sjouwerman, Stu; Posluns, Jeffrey, "Inside the spam cartel: trade secrets from the dark side", Elsevier/Syngress; 1st edition, November 27, 2004. ISBN 978-1-932266-86-3
- Brown, Bruce Cameron "How to stop e-mail spam, spyware, malware, computer viruses, and hackers from ruining your computer" Atlantic Publishing Group, 2011. ISBN 978-1-601383-03-7
- Dunne, Robert "Computers and the law: an introduction to basic legal principles and their application in cyberspace" Cambridge University Press, 2009. ISBN 978-0-521886-50-5
- The Spam Archive | Spamdex "Spam Archive list of spam from traceable sources", 2014-15 (including 2008-2013) over 35,000 spam emails listed
External links
Wikimedia Commons has media related to Electronic spam. |
- 1 December 2009: arrest of a major spammer
- Anti-Spam Consumer Resources and Information
- Cybertelecom:: Federal spam law and policy
- Federal Trade Commission page with spam reduction tips and reporting
- Malware City - The Spam Omelette BitDefender’s weekly report on spam trends and techniques.
- Reaction to the DEC Spam of 1978 Overview and text of the first known internet e-mail spam.
- Slamming Spamming Resource on Spam
- Spamtrackers SpamWiki: a peer-reviewed spam information and analysis resource.
- Why am I getting all this spam? CDT
|