Archive for February, 2008

Feb 28 2008

Web Spam, Not Just Bots Anymore

While email spam is battled with relentless focus, web spam becomes more powerful while we aren't watching. By "web spam" I am referring to the type of spam that is posted on blogs, comment sections or forums. Because we have been so barraged with unwanted messages from bots, many sophisticated plugins and scripts have been developed. The Akismet web service blocks nearly all of the common bot-posted spam (online casinos, pharmacy links) and does its job so well, you may be lucky enough to only receive one bogus comment or trackback every few months. Akismet can be implemented into many applications which receive submitted content such as forums, wikis, contact forms and blogs.

So we finally have adequate protection available for these kinds of annoyances. The new arising problem is the spammers are realizing their success rates are dropping. If the bots can't get into our forums and blogs, then who can? Only real human eyes. In the past few months I have witnessed a definite increase in the amount of spam being posted by real people behind their smeared monitors. Unless these posters are directly benefiting from the spam they spew, they must be "employed" by the head spammers. The good part of this is that spammers' pockets are now being emptied. While their bot-operation failure rate climbs as we build more walls, they are reluctantly spending their own money to recoup losses.

The new breed of web spammers aren't just posting about their regular reduced-price selection of watches and illegal software. Now they are even targeting web hosting. It's a bit scary to think that some seedy host start-ups out there are recruiting this underground advertising. Luckily most of the big forums or high traffic blogs are quick to catch their posts and remove them fast. Now that we're back to fighting the old fashioned way, hopefully we'll show them what we've got.

No responses yet

Feb 27 2008

Did You Mean Anti-Phishing or Anti-Tubing?

Senator Ted "Series of Tubes" Stevens (Alaska) along with Senator Olympia Snowe (Maine) introduced the Anti-Phishing Consumer Protection Act this week. The problem is they are honestly in need of phishing education.

The APCPA just doesn't make much sense. First, phishing is already illegal. Second, phishing is going to continue happening no matter how many laws there are. The root of the problem has to be addressed. Blanketing more laws over existing ones is not helping. Third, there is a section in this bill about domain name Whois privacy. This has nothing to do with stopping phishing either. From the pages of the act:

(9) Phishing operators utilize deceptive domain names for their schemes. They routinely register domain names that mimic the addresses of well-known online merchants, and then set up websites that can fool consumers into releasing personal and financial information.

That is hardly the most popular method of phishing. Phishing most often happens within "cracked" directories on existing websites owned by innocent people. If a phish is reported, the data center which hosts the website is notified. This is because IP addresses do not lie. The person who owns the domain name has nothing to do with the phish (at least in a direct way) and they have every right to keep their details private if they want. Phishers are not in a habit of registering "bankofamericaaccountlogin.com" and buying hosting every day, that opens them up to being found easily. So the idea of possibly disallowing private domain registration is a foolish and definitely unfair to domain owners. (Disclaimer: I do believe businesses should have their details listed, but private citizens should have a choice.)

With all of the phish attention lately, I am ready to start a website with the real story of how the series of tubes is really being compromised. 

No responses yet

Feb 27 2008

Selling your web host business — Act I

First we will start with an alert---because timing can be everything.

Marbles… One of the most important parts of any transaction is how many marbles you get to keep. If you are considering selling your company in 2008, 2009 or 2010 please run down (not just trott, put off til' tomorrow...I said RUN) to your tax accountant. If it would be a stock sale, which frankly you really don’t know today, you could be in trouble.

Why? The Bush tax reductions will soon start to evaporate, specifically the long term capital gain treatment which expires December 31, 2008 ---- yes a short 10 months away. In a stock transaction it could cost you another 5% in taxes.

Well it is only 5% some people may say. Yes but it takes almost 7% to make that up after paying taxes on the incremental amount you need to cover the poor timing.

So if you are considering selling in 2008 you should start earlier than later. And if you are considering 2009 ---- think again.

 ========== MORE ABOUT TOM ==========

New Commerce Communications

E-Mail Tom Direct

No responses yet

Feb 26 2008

USPS Goes Anti-Phish

I received what you might call unsolicited mail from the post office. It arrived addressed to Postal Customer and in bold was the title "Identity theft prevention tips."

If the majority of receivers do open these letters, this project will have very good results. Educating the public about phishing and identity theft online is hard enough so any outside help is really a good idea. The letter inside reads:

 "Enclosed is a brochure that provides you with helpful tips, phone numbers, websites, and steps you can take to deter, detect and defend yourself against identity theft. Please take the time to read through it and follow the advice. Sincerely, John E. Potter, Postmaster General."

The brochure itself is produced by the FTC and is actually the best brochure I've read yet. Most organizations are definitely becoming more savvy about these issues so explanations and solutions are more detailed than ever.

The problem with phishing is still rampant but ever since we implemented our anti-phishing redirect page a lot of other companies are following with the same. Our page had 4,083 visits in January alone due to the scams we have had to disable, mainly on dedicated servers. This is a huge improvement since my last post about the redirection page. I think this is because I continue to believe that the key to solving phishing really lies in educating dedicated server customers. The freedom we allow them should really be considered a danger and treated as such. Dedicated server hosts can still give customers the control they seek but they have to give them guidelines with it.

No responses yet

Feb 25 2008

All or Nothing?

Today I want to go on about web design in general, and also talk about my web site's home page.

The General Rant

It is said that the 'well rounded scientist' concept is dead, replaced by two groups - people who know everything about nothing (specialists), and people who know nothing about everything (generalists). Technically, there is no difference between the two (something times nothing is nothing), but from experience, the specialists get paid much, much, better - at least when they have a job.

It seems to me that home pages tend to follow the same trend. They either do one thing well, or they try to do everything at once - one stop shopping for all information and entertainment needs. My personal preference is utilitarianism. I want to get in and out quickly, preferably with what I was looking for. Unless, of course, what I want is a leisurely, meandering, tour of content (such as reading the newspapers, or looking for everything for sale on a web site).

For example, let's look at some leading web sites. We all hear about the web search wars between Google, Yahoo! and Microsoft (MSN). When one is at the Google web site, there is a text box, a couple of choices, and a search button. When one is at MSN or Yahoo!, he may think he is reading the supermarket special offers handout - there are boxes with text, pictures, weather info, stock market updates, regular links, bold links. Oh, and somewhere in there is also a search box. Does anyone wonder why Google is winning the search war? Ask.com is similar to Google, and I know other sites emulate the same sparse design as well, and I am sure they are much more attractive to searchers than the busy web pages of portals that also do search.

Let's take a look at some social networking sites. We have Bebo, MySpace, which look like portals with text ads, pictures, links, videos, etc. and rather busy interface. In contrast, Facebook, LinkedIn and Orkut have a functional interface, essentially a box with login/password fields and some additional information. The real sprawling mess is hidden behind that one simple door, which suits me fine. If I want to search for video clips, I would go to YouTube, Revver, or one of their equivalents. When I visit a social network site, I want to get in, do my thing, and get out. Nothing more, nothing less.

Which brings me to my web site and my design preferences.

My Web Site (www.words2u.net)

According to a comment, my site '...contains almost nothing at all, just a little text... Your blog link is a big empty space.. "Technical" is not a live link...', which does show how much one can observe by just looking. I have already apologized about the blog (WordPress died prematurely after I applied a package update), but let's take a minute to review the rest of the comment.

I subscribe to the school of thought that 'if something is worth doing, it is worth doing badly' - in other words, it is better to get something started and improve later, than wait till it is perfect, probably never. So when I decided to go on with the web page, I borrowed a table from another site, slapped on my basic content, added a php line for the dynamic date, and took it live.

I wanted a home page that lists and link to the three other site components, and have a second page with a general description. I am not sure if the design I selected is not in itself over-designed. I will see about the front end in the coming week (sorry, other commitments), and in the meantime, if you have suggestions how further simplify the page, please let me know. If I have enough time and suggestions, I will create several pages based on your comments, and let you choose the best one. Then I will use another one, of course, just to show character.

No responses yet

Next »