[#] Wed Jan 18 2017 05:48:51 EST from the_mgt

I have never found Spamassassin worth the hassle. I have applied Greylisting for years now, and while it delays the very first email you receive from a certain sender, it works fine.

But it does not help you against botnet'ed Desktops which send via legitimate but hijacked mail clients.


And yes, there were recently some rather nasty waves of spam. Some of them were borderlining on DOS attacks.

[#] Wed Jan 18 2017 13:51:08 EST from IGnatius T Foobar

Spammers haven't adapted to greylisting yet? I figured by now they'd all be either following the SMTP rules or sending mail through the big services.
Usually the phishers seem to come from gmail or yahoo.

This week I realized that I had at some point changed my DNS server to which made SURBL stop working. Fixing that helped a lot. I also installed Pyzor which seems to have made a dent also. Should I install Razor2 along with it? Is there a difference?

I'm open to greylisting but of course that means I'd have to write my own implementation of it. Sure, I could put a lot of off-the-shelf spam filters in front of Citadel but I use all of our incoming email as a nonstop test of Citadel's MTA.

What I *really* want is a Facebook blocker.

[#] Wed Jan 18 2017 22:38:10 EST from wizard of aahz

For thee first time in weeks I logged into UCG and didn't have 40 spam messages. Is a huge improvement.

[#] Mon Feb 06 2017 15:17:39 EST from zooer

Art, Did you close your G+ account?  I tried looking at it today and I received a 'The requested URL was not found on this server' error.

[#] Tue Feb 07 2017 10:42:19 EST from IGnatius T Foobar

I did. Once in a while I go around and clean up online presences that I'm not using anymore. Ever since that terrorist tried to get me fired from my job in 2010 I've been careful about what I leave lying around on the 'net.

I use an app to automatically delete anything I post to Twitter after one week.

I don't use fecesbook at all. (Although I do have an account with a fake name, just to get past the hitlerwall when someone posts a link that I want to read.)

When I see that I have an account that I'm no longer using, I close it. (Exception: my 4-digit Slashdot ID might come in handy someday.)

And then there's Disqus, which seems to be everywhere these days. Every now and then I abandon my account and start over with a new name.

[#] Tue Feb 07 2017 11:19:10 EST from zooer

At the time, for some odd reason, I thought you could only use Hangouts if you had Google Plus, so I joined.  I wanted to have video calls.  I think Google is in the process of getting rid of hangouts. in favor of their apps.


[#] Tue Feb 07 2017 13:57:38 EST from zooer

What about those "sign in with...." google features?  They show the g+ logo, is that Google plus or standard google?

[#] Tue Feb 07 2017 16:41:59 EST from IGnatius T Foobar

Seems to work with just an ordinary Google account.

[#] Mon Feb 13 2017 22:43:32 EST from zooer

You would think Google Location, once known as Google Latitude would be part of Google Maps.  This is not the case, you need G+ to share locations on a map.  
When traveling my family does use location services.

There are ways to text/SMS your location but that is only at the time the message is sent.  I wish Google would move location to maps...where it belongs.

[#] Thu Feb 16 2017 13:39:49 EST from fleeb

Well, if they drop Hangouts, there's some obscure-ish thing, called 'OpenMeetings', that might work, but ... it still uses Flash, and seems terrily kludgy in a lot of ways.

[#] Sat Feb 18 2017 05:02:16 EST from the_mgt

Btw, I added spam assassin with your recommendations, IG. It seems to help a lot, on the next install, I'll probably omit the postfix+greylisting setup.

[#] Thu Feb 23 2017 10:58:11 EST from IGnatius T Foobar

Snapchat? Anyone using it?

I still don't see any practical application for it other than sexting, which by itself probably can't carry the company.

Nevertheless, they are doing an IPO next week, with the company supposedly valued at $22 billion (USD). That seems excessive for a company with a very narrow user demographic and not a whole lot of revenue.

[#] Mon Feb 27 2017 10:02:57 EST from fleeb

Snapchat, as I understand it, is very popular with younger folks.

[#] Tue Feb 28 2017 14:49:01 EST from the_mgt

Snapchat is to make the chicks feel secure enough so they post nekid pics. And then you take a screenshot, or if you are old school, photograph your phone with another phone. Teens are stupid assholes. 

[#] Tue Feb 28 2017 14:52:41 EST from IGnatius T Foobar

Well well well. All hell is breaking loose right now. It's being reported in the news as an "Amazon outage" and I'm fine with Amazon's reputation taking a hit, but I think it might actually be impacting more than just them. But let's call it an Amazon outage because I like that. That'll teach people not to trust a bookstore to provide IT services.

[#] Wed Mar 01 2017 00:38:43 EST from kc5tja

More importantly, it'll drive home the point that cloud is no substitute for locally managed infrastructure. I have no beef with AWS, but I find the very concept of cloud itself every bit as annoying as it is useful. Too many people rely too heavily on it.

[#] Wed Mar 01 2017 10:30:45 EST from wizard of aahz

We really on AWS to be our backup / dr site.. We tell people we don't use tthem normally because our data center is much more dependable than AWS.

[#] Wed Mar 01 2017 13:49:00 EST from LoanShark

It's not as unreliable as all that, in particular if your team is not Very Good, they will somewhat inevitably do much worse than AWS's team in terms of keeping locally managed infrastructure reliably working.

So, what do you do?
* design a fault-tolerant application stack and distribute it across multiple AWS regions. Anybody who did that, and did it well, survived yesterday's outage without a hiccup. My workplace isn't nearly there, but we weren't disrupted too too badly because we don't rely on S3 for anything central.

Locally managed hardware will fail. Hardware will go kaput, and on any sufficiently large server farm this will happen with distressing regularity. The advantages of AWS are *tremendous* in terms of staff you don't have to employ and the ability to requisition new hardware (to scale up, to deploy new services, or to replace failed hardware) nearly instantaneously.

Nobody is forcing you to rely on S3 either, you could just use the core EC2 instances.

aahz, you might just be living in the stone age.

[#] Wed Mar 01 2017 19:55:38 EST from wizard of aahz

As I said. All our backups are applied at AWS and ready to go. If our DC has a problem we can very quickly go live with AWS. Is even tested.

But sometimes people like to audit the DC.. Is nice to show them a nice place that they can go and walk through.

[#] Thu Mar 02 2017 00:04:42 EST from LoanShark

But sometimes people like to audit the DC.. Is nice to show them a
nice place that they can go and walk through.

Look, this is also wrong. The auditors MUST adapt to changing times. THEY CAN'T ask you to physically walk through your datacenter if you don't fricking have one.

We don't have one. And it's worked quite well.

We are fully PCI compliant at the relevant tier for our traffic level and application profile. (We tokenize everything and don't store card numbers.) This involves AUDITING.

