Google SearchMore ContentAds / SponsorsGoogle AdsSite RankMy FOSS Work |
Don't Trust Salesforce.com (Revised)Thursday, September 20. 2007Trackbacks
Trackback specific URI for this entry
No Trackbacks
Comments
Display comments as
(Linear | Threaded)
Alan,
I work for salesforce.com, and while I don't speak in official capacity, I regret that you did not get a response to your email. I took a look at the email address you provided on sign up and a possible explanation suggested itself to me. I get spammed a lot at my domain using targeted dictionary aliases. For example, admin@kingsley2.com gets the most web hosting junk. The traceable alias that you are using just happens to be the target of much web marketing related junk mail. That seems to me like a more plausible explanation than salesforce.com having a data leak. You have a good point. Since the dawn of dictionary attacks I have moved toward adding a random seed to my "trace" addresses to prevent this. However, to date every misuse of a trace address has been clearly linked to the original source -- typically the subject matter is closely related to the site, instead of the generalized noise common in indiscriminate spam.
As you can see from the revision I added near the beginning of this post, the misuse was due to a third party with legitimate access to the data, not a dictionary based attack. I think that deliberately trying to find addresses using my old trace technique would offer too little payback for the spam harvesters. Probably the only target that they would be successful with is people like you and I who manage our own domains and have some technical wherewithal. The "admin@" and "sales@' class of spam is based on both addresses recommended in the Internet RFC, and simply guessing at likely hits, such as "accounts@" or "webmaster@". Salesforce.com should be implementing two-factor authentication system, like Salesboom.com and NEtsuite does.
|
CategoriesRecent EntriesAbout this Blog
Our Legacy: Environmental Barbarians Simplifying Joomla Template Layouts How the Liberals Should Elect a Leader TD Bank Tries an End Run Around Site Tracking Blockers Liberal Hopeful Bob Rae Expects Three Years of Recession? The Anatomy of a Security Breach Paris Hilton Gives Republicans a Lesson in Internet 101 RIP, SUV: Gas Prices Are "Getting There" Malware Injection: More Fun With Skype The Single Best Way to Bust a Telephone Scam Earth Hour: Little More than a Message I'm Boycotting the Olympics Viral Marketing from a Venture Capital Company? Online Shopping versus Traditional Shopping Geek BlogOn the Enforcability of the GPL
More Controversy: the Joomla Extensions Directory (JED) and the GPL Simplifying Joomla Template Layouts How to: Ubuntu PHP Remove Suhosin Joomla 1.5.8 is... is what?? "IBM May Quit Technology Standards Bodies" WSJ Screams In Search of an Application Framework: PHP GTK Python XULRunner Why I Love Open Source Web 2.0 and the One Page Web Site Microsoft Security Fix Clobbers Two Million Password Stealers LinksTop Exitswww.extensionprofessionals.com (21)
www.ambitonline.com (16) www.theglobeandmail.com (11) www.joomla.org (10) www.abivia.net (8) www.google.com (7) www.softwarefreedom.org (7) www.funnyordie.com (6) www.techcebu.net (6) community.joomla.org (5) Administration |