Re: Administrivia: Good mailing list social graces.

From: Leif Ericksen (leife_at_dls.net)
Date: 03/18/05

  • Next message: Dante Mercurio: "RE: Netscreen 5XT SSH Traffic"
    To: Daniel Hanson <dhanson@securityfocus.com>
    Date: Fri, 18 Mar 2005 12:59:14 -0600
    
    

    Clap, Clap, Clap...

    I see two main issues with the auto responders letting people know that
    the recipient is away on vacation or out at a conference while
    subscribed to the list. This can be used as a form of social
    engineering, or worse. As stated, it can give alternate contacts or
    points of access into your company.

    Yes the flood of emails is bothersome and I just delete them. However,
    when I get some that are written in a language other than English I have
    to look at it carefully and decide if it is spam or not.

    Another point to consider is how good is the security system at your
    home? Yes I said your home. If you name is in a phone directory or
    some other directory what is the likely hood that you could be targeted
    for a burglary? I will admit that saying somebody might use the list to
    determine whose home to go and burglarize, but being security concise
    requires a certain level of paranoia.

    Bottom line it only takes a few moments to un-subscribe/subscribe to the
    list so if your auto responder does not allow you to ignore the list,
    you should remove yourself from the list.

    That is just my thoughts on the matter.

    Now where are my burglary and lets see how my auto responses I get that
    are close enough to make it worth while! J/K but I hope that it makes
    a point.

    --
    Leif Ericksen
    On Thu, 2005-03-17 at 10:06 -0700, Daniel Hanson wrote:
    > I've posted some guidelines like this before, apparently I have to do it
    > again.
    > 
    > Leaving auto-responders on mailing list messages is not good social
    > behaviour. One or two auto-responses may not seem to be a huge problem,
    > but when a contributor to the list receives a mass of auto-response
    > messages, it dissuades the person from posting in the future.
    > 
    > We have over 10,000 subscribers, if 1% of them have auto-responders, that
    > is 100 messages, Do you like receiving 100 unsolicited messages in a 10
    > minute period in the middle of your work day?
    > 
    > Perhaps someone seeking assistance or advice won't be dissuaded by this
    > flood of email, but the people who reply and try to help (we have some
    > frequent contributors that do this an awful lot, thank you to all of you),
    > are a lot less motivated to put up with this.
    > 
    > Yet again, someone forwarded me an auto-reply that resulted because some
    > lazy site administrator decided to send all security mailing list traffic
    > to a a customer care email address that auto-replies to EVERY POST ALL THE
    > TIME.
    > 
    > As I have done before, and will continue to do, I will unsubscribe
    > addresses that do this. People on this list should be interested in making
    > the Internet a safer and more useable place, auto-replies because you are
    > too lazy to turn them off for mailing lists is not the way to do this.
    > 
    > As an aside, for all you corporate security administrators who seem to use
    > your vacation messages when you go away to conferences... If I were
    > interested to find the lazy administrators, and target the most lucrative
    > companies. I would pick a conference like blackhat or CanSecWest, send an
    > email to the list, and see who's away at the conference, and who
    > "concerns" should be addressed to while that person is away.
    > 
    > D
    -- 
    Leif Ericksen <leife@dls.net>
    

  • Next message: Dante Mercurio: "RE: Netscreen 5XT SSH Traffic"

    Relevant Pages

    • ANN: SciPy04 -- Last day for abstracts and early registration!
      ... The 1st annual *SciPy Conference* will be held this year at Caltech, ... Presenters ... we really haven't had much of a call for coding sprints for ... sprints will be determined via the mailing lists as well, ...
      (comp.lang.python)
    • Re: [Full-disclosure] EUSecWest CFP Closes April 14th (conf May 21/22 2008)
      ... Some of us find these conference ... is getting beyond a joke now all this unlawful commercial spam. ... I've seen this same message multiple times from various mailing lists ... These people are making big money and they shouldn't be allowed free ...
      (Full-Disclosure)
    • ANN: SciPy 2004 Conference - Python for Scientific Computing
      ... The 1st annual *SciPy Conference* will be held this year at Caltech, ... Jim Hugunin has answered the call and will be speaking to ... We're also planning three days of informal "Coding Sprints" prior to the ... determined via the mailing lists as well, ...
      (comp.lang.python)
    • ANN: Reminder -- SciPy 04 is coming up
      ... The 1st annual *SciPy Conference* will be held this year at Caltech, ... we really haven't had much of a call for coding sprints for ... sprints will be determined via the mailing lists as well, ...
      (comp.lang.python)
    • Re: [opensuse] undeleting files [OT]
      ... James Knott wrote: ... It is on the other lists I subscribe to. ... There are two reasons: ... Most auto-responders are smart enough not to reply to mail flagged as ...
      (SuSE)