Date: Sun, 15 Feb 2004 12:00:54 +0100 From: "Simon L. Nielsen" <simon@FreeBSD.org> To: Murray Baker <murray_baker@ihug.com.au> Cc: bugbusters@FreeBSD.org Subject: Re: i386/62382: Web access to PRs enables harvest email addresses for spamming. Message-ID: <20040215110053.GB722@arthur.nitro.dk> In-Reply-To: <3.0.3.32.20040215211107.009dde20@pop.ihug.com.au> References: <3.0.3.32.20040215211107.009dde20@pop.ihug.com.au>
next in thread | previous in thread | raw e-mail | index | archive | help
--ZoaI/ZTpAVc4A5k6 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On 2004.02.15 21:11:07 +1100, Murray Baker wrote: > See PR ``i386/62382''. > http://www.freebsd.org/cgi/query-pr.cgi?pr=3D62382 >=20 > Within days of submitting the update to ''i386/62382'', which has been > appended to the original PR with my unmodified email address exposed, I > have my first ever spams to this email address. Is this a coincidence? Probably not, but was it spam or the regular worm for the day virus mail? The worm mails are probably from windows users on the FreeBSD mailing lists with worms infested computers. > I know that this is a real pain, but I suggest that if email addresses > are to be visible on web, they should be rendered into 'gif' or 'png' > and the html then reference the bitmap. Bitmaps should use different > fonts, colors, backgrounds to discourage ocr software. As said several times before the GNATS database is mirrored around on all FreeBSD mirrors and all the PR's sent to public mailing lists, so hiding the email addresse on the web probably doesn't change much. If it's obscufated everywhere it will make it harder for the people who need to contact a PR submitter (which very likely will mean people just won't bother contacting a submitter if it's to much trouble). > My only defense against spam is to change email addresses frequently. Have you considered installing anti spam software like spamassasin? It catches almost all my spam (and I probably get a few hundred spam mails per day, and one or two a week get through the filters). Yes spam sucks, but personally I don't belive hiding/obfuscating works. I won't object if somebody changes the gnats webinterface to obfuscate email address, but I'm not going to do it myself, since I just don't belive it work. --=20 Simon L. Nielsen FreeBSD Documentation Team --ZoaI/ZTpAVc4A5k6 Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.3 (FreeBSD) iD8DBQFAL1Flh9pcDSc1mlERAuKHAKCUs7ewvIVJrxdPc7doZcEJgU8cRgCfS29v HQQDBOzdwrGTTtzEs9ZOkZ0= =8LnS -----END PGP SIGNATURE----- --ZoaI/ZTpAVc4A5k6--
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040215110053.GB722>
