Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Data breaches are so common now that your eyes may tend to gloss over the news of yet-another public exposure of personally identifiable information (PII) and customer records. . Even in such a world, however, sometimes a case which tops many others still enters the public domain -- such as the discovery of a database which has been described as "perhaps the biggest and most comprehensive email database I have ever reported" by the researcher who uncovered the breach. According to Bob Diachenko, alongside security researcher Vinny Troia, the 150GB MongoDB instance in question contained four separate collections of data. The link for this article located at ZDNet is no longer available. . Even in such a world, however, sometimes a case which tops many others still enters the public domai. breaches, common, gloss, yet-another, public. . LinuxSecurity.com Team
More and more customers are receiving e-mails warning them of Friday's database hack at Epsilon, which handles e-mail marketing for thousands of companies. The breach exposed personal information like names and e-mail addresses.. Dallas-based Epsilon works with more than 2,500 clients and sends more than 40 billion e-mails annually, so the magnitude of the breach may not be seen until the investigation is complete. So far, the following companies have confirmed a security breach: Kroger,TiVo, US Bank, JPMorgan Chase, Capital One, Citi, Home Shopping Network, Ameriprise Financial, LL Bean Visa Card, McKinsey & Company, Ritz-Carlton Rewards, Marriott Rewards, New York & Company, Brookstone, Walgreens. The College Board, Disney Destinations, and Best Buy. The link for this article located at CNET is no longer available. . Dallas-based Epsilon works with more than 2,500 clients and sends more than 40 billion e-mails annua. customers, receiving, e-mails, warning, friday's, database, epsilon. . LinuxSecurity.com Team
Chartered engineer Nigel Roberts became the first person to win a court judgment over a company's breach of the UK's anti-spam law late last year. His success received widespread media coverage – and now he's encouraging others to do the same. Roberts sued Media Logistics (UK) Ltd, a marketing firm based in Falkirk, Scotland, for sending him unsolicited emails about contract car hire and fax broadcasting businesses. . The judge's ruling is unlikely to influence future courts: it was an undefended Small Claims action – the simplest procedure in the English court system, which can be used by anyone without legal representation. The link for this article located at TheRegister.co.uk is no longer available. . The judge's ruling is unlikely to influence future courts: it was an undefended Small Claims action . chartered, engineer, nigel, roberts, became, first, person, court, judgment, company's. . LinuxSecurity.com Team
A Virginia judge sentenced a spammer to nine years in prison Friday in the nation's first felony prosecution for sending junk e-mail, though the sentence was postponed while the case is appealed. . Loudoun County Circuit Judge Thomas Horne said that because the law targeting bulk e-mail distribution is new and raises constitutional questions, it was appropriate to defer the prison time until appeals courts rule. A jury had recommended the nine-year prison term after convicting Jeremy Jaynes of pumping out at least 10 million e-mails a day with the help of 16 high-speed lines, the kind of Internet capacity a 1,000-employee company would need. Jaynes, of Raleigh, N.C., told the judge that regardless of how the appeal turns out, "I can guarantee the court I will not be involved in the e-mail marketing business again.". A Virginia judge sentences a spammer to nine years for the first felony case of its kind, awaiting appeals decision on the law.. Spam Case, Email Marketing, Legal Precedence, Justice System. . Brittany Day
E-mail accreditation isn't taken all that seriously as a method of spam control. I'm baffled as to why. It appears to be an effective means of helping ensure that spam filters don't accidently block e-mail that the recipient actually wants to get. . . .. E-mail accreditation isn't taken all that seriously as a method of spam control. I'm baffled as to why. It appears to be an effective means of helping ensure that spam filters don't accidently block e-mail that the recipient actually wants to get. These legitimate messages wrongly blocked by spam and virus filters are known as "false positives," and they're as big a problem as spam itself. E-mail marketers and bulk mailers - like us here at Security Pipeline - are putting up the loudest squawk about the problem. I've seen estimates that 10-15 percent of legitimate bulk mail fails to reach its recipients, because messages are blocked by overzealous spam and virus filters. That includes the very newsletter you're reading now; industry statistics tell me that one subscriber in seven or eight will simply not receive this message. (Let me know if you're not reading this. Ha ha. I make ze joke, yes?) We e-mail publishers are looking to improve the delivery rate, and e-mail accreditation has emerged as one technique. The idea is this: Companies like Bonded Sender and Habeas, Inc., sign up bulk e-mailers to agree to terms of service designed to keep e-mailers from sending spam. (Some anti-spam advocates say the terms of service aren't strict enough, but at least the accreditation programs are trying to put SOME controls in place.) The e-mail publishers pay to use the service. (This is a bit down the page, but worth reading) The link for this article located at securitypipeline.com is no longer available. . Email accreditation initiatives aim to boost sender credibility and reduce spam but often struggle due to their complexity and fragmented implementation processes. Spam Control Solutions, Email Delivery Challenges, Accreditations in Email Marketing. .LinuxSecurity.com Team
Prediction: MSN and Hotmail will lose ground to Yahoo, AOL, and possibly even Juno. This will occur if any sizable number of businesses take Microsoft up on this idea. The open question is: when will legislators and certain technology providers realize that required 'opt-in' is the only way to even hope to reduce the level of unsolicited email? Why must 'legitamite' marketers to whom we have never expressed an interest in relationship get even one free crack at our inboxes? . . .. Microsoft said yesterday it had introduced a white list scheme to allow well-behaved email marketing firms to reach its customers without falling foul of its spam filters. Marketing firms who post a cash bond of up to $20,000 through IronPort's "Bonded Sender Programme" will get guarantees that their message will be delivered to the estimated 170 million regular users of Microsoft's Hotmail and MSN e-mail services, providing they follow a strict set of guidelines. Firms who flout the guidelines - standards that exceed those defined in the CAN-SPAM Act - risk losing their money. The approach rewards marketeers who agree to be held accountable for the messages they send. Microsoft has been working on the programme with IronPort for five months but the arrangement was only made public yesterday. The link for this article located at TheRegister is no longer available. . Microsoft said yesterday it had introduced a white list scheme to allow well-behaved email marketing. prediction, hotmail, ground, yahoo, possibly, occur. . LinuxSecurity.com Team
Susan Getgood, SurfControl's vice president of marketing, said the total volume of spam the company is tracking has not changed since the beginning of January. Francois Lavaste, vice president of marketing at e-mail-filtering company Brightmail, said his company's statistics showed similar results and, if anything, a slight increase in spam volume since the beginning of the year. . . .. No sooner did the U.S. Can-Spam antispam law go into effect than spammers got to work exploiting its loopholes and gray areas, an e-mail-filtering company said Tuesday. Representatives of United Kingdom-based SurfControl said that while 19 out of 20 spammers are ignoring the law completely, SurfControl researchers have observed some spammers adjusting their tactics to give at least the impression of compliance. The spammers' methods, however, often violate either the letter or the spirit of the law. The Can-Spam Act (full name: Controlling the Assault of Non-Solicited Pornography and Marketing Act), which took effect Jan. 1, requires commercial e-mail to include the advertiser's postal address, a "clear and conspicuous" commercial notice and a way for recipients to opt out of future mailings. "Unfortunately, many spammers aren't really doing anything different than they did before the Can-Spam Act was passed -- they're just creating the illusion they are complying with the law and using it to market or commit fraud," said Susan Larson, SurfControl's vice president of global content. The link for this article located at Wired.com is no longer available. . Scammers find ways around the GDPR regulations as soon as they are enacted, tweaking their methods to seem legitimate.. Spam Compliance, Email Marketing, Digital Fraud, Anti-Spam, Marketing Tactics. . Anthony Pell
Its only fair that we publish a different, more hopeful point of view on the CAN-SPAM issue. Larry Seltzer at eWeek writes that this law, while certainly not the silver bullet to end all spam, is still a welcome start.. . .. Its only fair that we publish a different, more hopeful point of view on the CAN-SPAM issue. Larry Seltzer at eWeek writes that this law, while certainly not the silver bullet to end all spam, is still a welcome start. We appear to be on the verge of having a national law on the problem of spam. The CAN-SPAM act would preempt the numerous attempts that have been made by various states to regulate the issue. (Here's a PDF file of the latest version of the bill.) There's a lot of common sense in the bill and it's both good for the covered spamming practices to be made illegal and important that this become a national law. But the CAN-SPAM act won't make a substantial difference in the actual amount of spam you receive. CAN-SPAM is actually an acronym for the full name of the bill: "Controlling the Assault of Non-Solicited Pornography and Marketing Act of 2003." The version I linked to above is the one most recently passed by the Senate. The final version will be very close to it and President Bush is expected to sign it. The link for this article located at eWeek is no longer available. . Its only fair that we publish a different, more hopeful point of view on the CAN-SPAM issue. Larry S. publish, different, hopeful, point, can-spam, larry. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.