Remix.run Logo
▲ mmh0000 2 days ago

It’s not ridiculous.

Hosting providers should be good citizens of the network and immediately terminate spammer accounts. This used to be standard practice until about 2015. When suddenly management decided it’s more profitable host spammers than not.

I think this is a great policy decision by uceprotect.

▲xp84 2 days ago | parent | next [-]

I’m not saying one shouldn’t endeavor to terminate spammers immediately, but I’m pretty sure that it doesn’t matter if you do, because as soon as you terminate the account, another one’s gonna be spun up immediately with another fake identity. The only thing that would change that would be the exact kind of heavy-handed identity-verification BS that most of us don’t really care for. And even then, it will only change it slightly. Spammers will be paying people in the third world $20 to use their passport to sign up for a cloud hosting account so they can spam for a few days.

▲JohnMakin 2 days ago | parent | prev | next [-]

Why DigitalOcean in particular though? Why not Cloudflare? A significant percentage of malicious and spam traffic is hosted on or routed through cloudflare services. Why not AWS? Same thing. It's a personal grudge, and they aren't quite big enough or have powerful enough lawyers to cause a widespread problem if put on a list, so, the big players are left alone.

All that aside, the website and their communication around this over the years is extraordinarily unprofessional and it's astounding to me they wield such power.

▲mmh0000 2 days ago | parent [-]

I ran my own small-business/family mail server for a little over a decade. Spam is out of control.

UCEPROTECT and other RBLs are just lists of text files. They do not block anything. As the mail administrator, you can choose what you do with a UCEPROTECT listing.

When I ran my mail server, I had UCEPROTECT tied into SpamAssassin, so that a UCEPROTECT listing by itself wouldn't block email; it would just raise the "spam probability rating" up.

UCEPROTECT is not a huge professional thing; it's "some guy" who's been running it, effectively, for free since the very early 2000s. No one is obligated to use it. If someone is being blocked by it, they need to contact the mail admin. UCEPROTECT just lists problematic hosts.

On to WHY DO and no CF/AWS? I don't know.. I'm not the "some guy" running the thing. But if I had to guess, it's that DO doesn't respond to spam complaints[1]. Whereas CF/AWS, while they host spammers, will take action against reported spammers.

[1] https://www.reddit.com/r/sysadmin/comments/1cwilrc/does_digi...

▲goldenmember 2 days ago | parent | prev [-]

Following your logic, we'd need to block the entire US, since that's where DigitalOcean's ASN is registered.