Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 15 Feb 2004 12:00:54 +0100
From:      "Simon L. Nielsen" <simon@FreeBSD.org>
To:        Murray Baker <murray_baker@ihug.com.au>
Cc:        bugbusters@FreeBSD.org
Subject:   Re: i386/62382: Web access to PRs enables harvest email addresses for spamming.
Message-ID:  <20040215110053.GB722@arthur.nitro.dk>
In-Reply-To: <3.0.3.32.20040215211107.009dde20@pop.ihug.com.au>
References:  <3.0.3.32.20040215211107.009dde20@pop.ihug.com.au>

next in thread | previous in thread | raw e-mail | index | archive | help

--ZoaI/ZTpAVc4A5k6
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On 2004.02.15 21:11:07 +1100, Murray Baker wrote:

> See PR ``i386/62382''.
>   http://www.freebsd.org/cgi/query-pr.cgi?pr=3D62382
>=20
> Within days of submitting the update to ''i386/62382'', which has been
> appended to the original PR with my unmodified email address exposed, I
> have my first ever spams to this email address. Is this a coincidence?

Probably not, but was it spam or the regular worm for the day virus
mail?  The worm mails are probably from windows users on the FreeBSD
mailing lists with worms infested computers.

> I know that this is a real pain, but I suggest that if email addresses
> are to be visible on web, they should be rendered into 'gif' or 'png'
> and the html then reference the bitmap. Bitmaps should use different
> fonts, colors, backgrounds to discourage ocr software.

As said several times before the GNATS database is mirrored around on
all FreeBSD mirrors and all the PR's sent to public mailing lists, so
hiding the email addresse on the web probably doesn't change much.  If
it's obscufated everywhere it will make it harder for the people who
need to contact a PR submitter (which very likely will mean people just
won't bother contacting a submitter if it's to much trouble).

> My only defense against spam is to change email addresses frequently.

Have you considered installing anti spam software like spamassasin? It
catches almost all my spam (and I probably get a few hundred spam mails
per day, and one or two a week get through the filters).

Yes spam sucks, but personally I don't belive hiding/obfuscating works.
I won't object if somebody changes the gnats webinterface to obfuscate
email address, but I'm not going to do it myself, since I just don't
belive it work.

--=20
Simon L. Nielsen
FreeBSD Documentation Team

--ZoaI/ZTpAVc4A5k6
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (FreeBSD)

iD8DBQFAL1Flh9pcDSc1mlERAuKHAKCUs7ewvIVJrxdPc7doZcEJgU8cRgCfS29v
HQQDBOzdwrGTTtzEs9ZOkZ0=
=8LnS
-----END PGP SIGNATURE-----

--ZoaI/ZTpAVc4A5k6--


Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040215110053.GB722>