Sophos: Spam won't be gone in two years

By Vivian Yeo, ZDNet Asia
Monday, May 22, 2006 12:13 PM

The world will not see the end of spam anytime soon, but a combination of legislation and antispam tools could help manage the problem, says a veteran in the security industry.

"In two years' time, we're definitely not going to see the end of spam," said Jan Hruska, co-founder of Sophos, in an interview with ZDNet Asia last week. The security vendor's former co-CEO was making a reference to Microsoft Chairman Bill Gates' prediction that spam would be eradicated in 2006.

Hruska pointed out that "every single tactic that has been tried so far [to stop the spam scourge] has had very limited success". Mail authentication for one, "hasn't helped" in practice, and will not have much impact--at least not in the short term, he said.

"People who have tools to authenticate an e-mail are in fact spammers," he noted. "They start sending out spam [to e-mail] that has been authenticated."

Other initiatives such as charging for e-mail and providing an e-mail registry, have also not been successful, according to Hruska. Fee-based e-mail has not taken off mainly because people "are not used to paying for e-mail", he said, adding that an e-mail registry is also not feasible as people who do not register are automatically considered spammers.

"Only two things really have worked--legislation followed by prosecution, which discourages spammers, and second, the use of antispam software," Hruska said, stressing that the laws must be complemented with "the willingness and capability of the judiciary to catch and prosecute [spammers]".

"Legislation is the enabler of the prosecution, but the effect is not going to be seen until there are a number of successful prosecutions," he said.

Prosecution, Hruska added, should be followed up fairly quickly after the legislation is passed. Cases should be publicized to give them a higher profile, he said.

One country that has vowed to put in place tougher legislation against spam is China, which is catching up with the United States in terms of spam contribution.

Hruska also highlighted partnership of some countries worldwide to fight spam, but cautioned that these initiatives are limited in their impact.

"We mustn't forget that the spam problem is very much an international problem--there might be legislation in some countries, but there are still going to be places around the world where there is going to be little or no legislation, and it is only natural that spammers will gravitate toward those jurisdictions," he explained.

"The government can put in place legislation to deter spam, and also prosecute spammers, but from the point of view of users and companies affected by spam, the best thing people can do is just use antispam software," he said.


WORTHWHILE?

0

0 votes
Blog

Talkback 1 comments

It will never be gone until the US scraps its "You CAN spam" joke, takes spamming seriously and treats spammers as the thieves of other people's resources, extortionists, thugs and con-men they are.
Seems to me that the fact that spammers rarely get what they deserve implies that some people in high places are on the spammers' payroll.
Spam Cop seems perfectly capable of identifying the origin of spam, so why do the law enforcement agencies seem to have so much trouble nailing these slime and taking them off the net?
Posted by A Spamee on Tuesday, May 23 2006 11:40 PM


Tech Jobs Now!

Search for your ideal tech job:

Export project data for future effort estimation

Tech Management

Learn to tweak your estimation matrix even further by analyzing the project data from your Microsoft Project schedule.


Read more »


 
Virtualize your way to cost savings
Build an infrastructure that is flexible, scalable, and economical, as you strive to become a truly agile business.

Red Hat Outlines Its Virtualization Strategy and Roadmap for 2009
» Watch the video




Are telcos new drivers of outsourcing industry?

Blog thumbnail

The recent TPI Index from TPI highlighted an interesting trend where a few very large telco-to-telco contracts--instances where one telecommunications carrier outsources its network operations requirements to another telecommunications service..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web