<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Internet ghost-towns: the blocked IPs where the bad guys used to&#160;live</title>
	<atom:link href="http://boingboing.net/2009/11/13/internet-ghost-towns.html/feed" rel="self" type="application/rss+xml" />
	<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html</link>
	<description>Brain candy for Happy Mutants</description>
	<lastBuildDate>Mon, 20 May 2013 21:47:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: hancocks</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-635921</link>
		<dc:creator>hancocks</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-635921</guid>
		<description>They should block those IP addresses, then unblock them, then block them again, then unblock them... pretty much at random.

  That way, they&#039;ll be providing about the same level of service as my local ISP...sigh...</description>
		<content:encoded><![CDATA[<p>They should block those IP addresses, then unblock them, then block them again, then unblock them&#8230; pretty much at random.</p>
<p>  That way, they&#8217;ll be providing about the same level of service as my local ISP&#8230;sigh&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pelrun</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-635670</link>
		<dc:creator>pelrun</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-635670</guid>
		<description>Sounds like the perfect method to motivate people to transition across to IPv6 :D</description>
		<content:encoded><![CDATA[<p>Sounds like the perfect method to motivate people to transition across to IPv6 :D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Halloween Jack</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-635703</link>
		<dc:creator>Halloween Jack</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-635703</guid>
		<description>Ironically, it seems like block lists are propagated, and persist, not unlike spam lists. </description>
		<content:encoded><![CDATA[<p>Ironically, it seems like block lists are propagated, and persist, not unlike spam lists. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Agies</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-635705</link>
		<dc:creator>Agies</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-635705</guid>
		<description>Not really. IPv6 doesn&#039;t provide any sort of real solution for this.</description>
		<content:encoded><![CDATA[<p>Not really. IPv6 doesn&#8217;t provide any sort of real solution for this.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Antinous / Moderator</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-635964</link>
		<dc:creator>Antinous / Moderator</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-635964</guid>
		<description>Yeah, I&#039;m looking at you, IPs that start with 58 or 59.</description>
		<content:encoded><![CDATA[<p>Yeah, I&#8217;m looking at you, IPs that start with 58 or 59.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: dculberson</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-635771</link>
		<dc:creator>dculberson</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-635771</guid>
		<description>Just quantity. Yeah, eventually you&#039;d run into the same problem - but it&#039;ll be the next generation&#039;s problem. ;-)</description>
		<content:encoded><![CDATA[<p>Just quantity. Yeah, eventually you&#8217;d run into the same problem &#8211; but it&#8217;ll be the next generation&#8217;s problem. ;-)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: manicbassman</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-635783</link>
		<dc:creator>manicbassman</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-635783</guid>
		<description>shouldn&#039;t be blocking IP addresses anyway... they should be blocking domain names and do a DNS lookup every day to get the latest IP for the domain...

simple really... when you get an active spammer, then reverse DNS to get the domain, then add that domain to the blocklist... then everyday, repopulate a temporary IP list using DNS lookups of the blocked domains...

I&#039;m convinced some admins are just to lazy to write a simple script to run every day...</description>
		<content:encoded><![CDATA[<p>shouldn&#8217;t be blocking IP addresses anyway&#8230; they should be blocking domain names and do a DNS lookup every day to get the latest IP for the domain&#8230;</p>
<p>simple really&#8230; when you get an active spammer, then reverse DNS to get the domain, then add that domain to the blocklist&#8230; then everyday, repopulate a temporary IP list using DNS lookups of the blocked domains&#8230;</p>
<p>I&#8217;m convinced some admins are just to lazy to write a simple script to run every day&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Todd Knarr</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-635799</link>
		<dc:creator>Todd Knarr</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-635799</guid>
		<description>#5: the problem is that DNS lookups are per-address or per-host, not per-domain. Certainly I can go from the address of the spamming host to it&#039;s DNS name, and I can probably trim that to get just the domain, but from that there&#039;s no way to reliably translate that into an IP address block. There&#039;s in principle a way, if the spammer&#039;s set up some special records correctly and accurately, but they probably didn&#039;t. And it&#039;s fairly easy for them to make the domain name resolve to an address that&#039;s got nothing to do with the IP range they&#039;re really coming from. So the only thing I&#039;ve really got that I can use is the IP block containing the IP address of the host they used.</description>
		<content:encoded><![CDATA[<p>#5: the problem is that DNS lookups are per-address or per-host, not per-domain. Certainly I can go from the address of the spamming host to it&#8217;s DNS name, and I can probably trim that to get just the domain, but from that there&#8217;s no way to reliably translate that into an IP address block. There&#8217;s in principle a way, if the spammer&#8217;s set up some special records correctly and accurately, but they probably didn&#8217;t. And it&#8217;s fairly easy for them to make the domain name resolve to an address that&#8217;s got nothing to do with the IP range they&#8217;re really coming from. So the only thing I&#8217;ve really got that I can use is the IP block containing the IP address of the host they used.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-636090</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-636090</guid>
		<description>I ran into this when I went with a low cost colo provider. It took a year to get my IP unblacklisted. and Many many attempts. Its like anti virus, the companys that run blacklists have better credence if there databases are larger. So they have little motivation to de-list an IP once they have it.</description>
		<content:encoded><![CDATA[<p>I ran into this when I went with a low cost colo provider. It took a year to get my IP unblacklisted. and Many many attempts. Its like anti virus, the companys that run blacklists have better credence if there databases are larger. So they have little motivation to de-list an IP once they have it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-635838</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-635838</guid>
		<description>With services like Ring Central and Google Voice, the same thing will happen with phone numbers. I&#039;ve blocked a number of telemarketing phone numbers -- years from now, when someone legit has the number, they will not be able to call me.</description>
		<content:encoded><![CDATA[<p>With services like Ring Central and Google Voice, the same thing will happen with phone numbers. I&#8217;ve blocked a number of telemarketing phone numbers &#8212; years from now, when someone legit has the number, they will not be able to call me.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: mdh</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-635865</link>
		<dc:creator>mdh</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-635865</guid>
		<description>They should ask urban planners for advice. Seriously. </description>
		<content:encoded><![CDATA[<p>They should ask urban planners for advice. Seriously. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Antinous / Moderator</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-636899</link>
		<dc:creator>Antinous / Moderator</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-636899</guid>
		<description>I&#039;ve been gray-listed within the last two years, as have Xeni and David. And probably more of us that I don&#039;t know about. I think that anyone who does a fair amount of online business will be accidentally (or vengefully) tagged enough times to have the occasional problem.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve been gray-listed within the last two years, as have Xeni and David. And probably more of us that I don&#8217;t know about. I think that anyone who does a fair amount of online business will be accidentally (or vengefully) tagged enough times to have the occasional problem.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-636644</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-636644</guid>
		<description>Spam blacklists fail in one very specific way, and thats that spam scores need to reflect the user population density of a netblock. As there is no way of telling how many physical discrete people use a specific netblock to send email, there is no way of coming up with accurite spam scores and metrics.

This is why webhosts, esp. ones with large mail clusters, get very very badly dinged as far as mail delivery. A webhost with 10,000 customers using it&#039;s mail servers is most likely going to have worse of a spam score than a spam producing business with it&#039;s own netblock (spam producing business != buisness of producing spam).</description>
		<content:encoded><![CDATA[<p>Spam blacklists fail in one very specific way, and thats that spam scores need to reflect the user population density of a netblock. As there is no way of telling how many physical discrete people use a specific netblock to send email, there is no way of coming up with accurite spam scores and metrics.</p>
<p>This is why webhosts, esp. ones with large mail clusters, get very very badly dinged as far as mail delivery. A webhost with 10,000 customers using it&#8217;s mail servers is most likely going to have worse of a spam score than a spam producing business with it&#8217;s own netblock (spam producing business != buisness of producing spam).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: octopod</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-635878</link>
		<dc:creator>octopod</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-635878</guid>
		<description>not Argleton in lancashire then, meh.</description>
		<content:encoded><![CDATA[<p>not Argleton in lancashire then, meh.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: codeman38</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-635880</link>
		<dc:creator>codeman38</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-635880</guid>
		<description>I&#039;ve even seen this happen on a more short-term basis: A hosting company has several clients who try running spambots. Within a day, the spammers&#039; accounts have already been cancelled by the host. But by that time, the IP block has already been added to several blacklists. It&#039;s particularly bad when you&#039;re dealing with a single SMTP server that&#039;s shared between several web sites, as some hosting companies tend to do.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve even seen this happen on a more short-term basis: A hosting company has several clients who try running spambots. Within a day, the spammers&#8217; accounts have already been cancelled by the host. But by that time, the IP block has already been added to several blacklists. It&#8217;s particularly bad when you&#8217;re dealing with a single SMTP server that&#8217;s shared between several web sites, as some hosting companies tend to do.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Anonymous</title>
		<link>http://boingboing.net/2009/11/13/internet-ghost-towns.html#comment-635903</link>
		<dc:creator>Anonymous</dc:creator>
		<pubDate>Wed, 30 Nov -0001 00:00:00 +0000</pubDate>
		<guid isPermaLink="false">#comment-635903</guid>
		<description>@manicbassman: ... and what happens when there is no reverse DNS?  Nobody is under any obligation to set up an IP to name mapping.</description>
		<content:encoded><![CDATA[<p>@manicbassman: &#8230; and what happens when there is no reverse DNS?  Nobody is under any obligation to set up an IP to name mapping.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
