{"id":31,"date":"2005-04-15T00:11:12","date_gmt":"2005-04-14T23:11:12","guid":{"rendered":"http:\/\/pgregg.com\/wp\/2005\/04\/the-bondedsender-program-bsp-con\/"},"modified":"2005-04-15T00:11:12","modified_gmt":"2005-04-14T23:11:12","slug":"the-bondedsender-program-bsp-con","status":"publish","type":"post","link":"https:\/\/blog.pgregg.com\/blog\/2005\/04\/the-bondedsender-program-bsp-con\/","title":{"rendered":"The BondedSender Program (BSP) con."},"content":{"rendered":"<p>I don&#8217;t know how this happened, but for some reason the antispam community seem to have walked right into quicksand. Why?&nbsp; &nbsp;Well, consider this: If you existed to come up with ways to stop spam, you would think that implementing a way to establish trust relationships with sender would guarantee* that they wouldn&#8217;t send you spam.<\/p>\n<p>* &#8211; No there are no guarantees.<\/p>\n<p>Well recently a configuration option within <a href=\"http:\/\/spamassassin.apache.org\/\" rel=\"nofollow\" target=\"_blank\">SpamAssassin<\/a> caused me alarm since it was occurring more frequently in spams that were getting through to me. Looking into the RCVD_IN_BSP_TRUSTED score I found that spamassassin gave it a -4.3 weighting which unless the email is particularly spammy, it means the net score for that email will result it it being classified as non-spam.&nbsp; Trouble is &#8211; this is spam, so why is spamassassin being so nice to it?<\/p>\n<p>Looking it up, I ended up at The <a href=\"http:\/\/www.bondedsender.org\/\" rel=\"nofollow\" target=\"_blank\">Bonded Sender Program .org<\/a> (this is the Internet friendly face) which &quot;turns the spam problem upside down by identifying legitimate email traffic&quot;.&nbsp; Oh?&nbsp; Further reading shows that the BSP has a <a href=\"http:\/\/www.bondedsender.com\" rel=\"nofollow\" target=\"_blank\">corporate side<\/a> that companies pay the BSP (read: IronPort, who also happen to own and run SpamCop) so their emails get positively flagged as non-spam.<\/p>\n<p>Am I the only one spotting the delicious conflict of interest?<br \/>1. Spamassassin catches spam<br \/>2. Users report spam to SpamCop<br \/>3. SpamCop blocks spammer.<br \/>4. Spammer has less success because their servers are blacklisted<\/p>\n<p>Now SpamCop, aka IronPort, aka BSP goes to spammer &quot;Pay us a wodge of cash and we can make sure a) you don&#8217;t get flagged as spam, and b) your servers can&#8217;t get blacklisted&quot;. Sounds like a sweet deal.&nbsp; Why wouldn&#8217;t any spammer go for it?<\/p>\n<p>In any other industry this would be blackmail. e.g. Mafia: &quot;Pay us your insurance so you can be sure you or your shop doesn&#8217;t meet with an unfortunate accident&quot;.<\/p>\n<p>Now the BSP apparently takes abuse of their system very seriously.&nbsp; I beg to differ.&nbsp; &nbsp;I reported an instance of abuse, to which the initial reply sounded positive, but that same customer is still spamming away.&nbsp; I shall post some example spams that BSP claim isn&#8217;t spam as comments.<\/p>\n<p>So, anyone reading this.&nbsp; If you use Spamassassin, add this to your user_prefs:<br \/>score RCVD_IN_BSP_OTHER 0<br \/>score RCVD_IN_BSP_TRUSTED 0<\/p>\n<p>Companies or Email senders &#8211; if you hit this page whilst researching about using the BSP, then please don&#8217;t.&nbsp; It is a dirty way to get your message across &#8211; if anything it will make people like myself even more vehemently outspoken against you and your products.<\/p>\n<p>BSP\/SpamCop\/IronPort &#8211; if you want to regain some credibility, perhaps you will take your abuse reports seriously and actually kill off those customers who do use you as a ticket to get spam through.<\/p>\n<p>This is my personal opinion based on my experience of spam emails I have received via the Bonded Sender Program.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I don&#8217;t know how this happened, but for some reason the antispam community seem to have walked right into quicksand. Why?&nbsp; &nbsp;Well, consider this: If you existed to come up with ways to stop spam, you would think that implementing a way to establish trust relationships with sender would guarantee* that they wouldn&#8217;t send you &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/blog.pgregg.com\/blog\/2005\/04\/the-bondedsender-program-bsp-con\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;The BondedSender Program (BSP) con.&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"1","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[4],"tags":[],"class_list":["post-31","post","type-post","status-publish","format-standard","hentry","category-general"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pbQOUu-v","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.pgregg.com\/blog\/wp-json\/wp\/v2\/posts\/31","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.pgregg.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.pgregg.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.pgregg.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.pgregg.com\/blog\/wp-json\/wp\/v2\/comments?post=31"}],"version-history":[{"count":0,"href":"https:\/\/blog.pgregg.com\/blog\/wp-json\/wp\/v2\/posts\/31\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.pgregg.com\/blog\/wp-json\/wp\/v2\/media?parent=31"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.pgregg.com\/blog\/wp-json\/wp\/v2\/categories?post=31"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.pgregg.com\/blog\/wp-json\/wp\/v2\/tags?post=31"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}