Amir Lev's Most Recent Posts

Amir Lev's picture
Amir Lev

Security Levity

10 ways spam is like vuvuzelas (the World Cup horns)

If you've been glued to the World Cup, you'll know that there's more to the matches than soccer (football for our international audience). I'm talking about those incessant horns -- the vuvuzelas. They're really catching people's attention, for all the wrong reasons. It got me thinking... In this week's Security Levity, how is a vuvuzela just like spam? Vuvuzelas and spam? Have I gone mad? Never fear, dear reader, let me count the ways...

...Read more

read more

Is it illegal to bypass spam filters? Vonage hopes not.

"You Could Save up to 50% on Your Phone Bill!" screamed an email from Vonage. Naturally, users complained this unsolicited, bulk email was spam. But some spam filters weren't having it -- a surprising number of these messages reached user inboxes. Vonage's marketing agent sent the email from a list of "nonsense" domain names, including the unpronounceable urgrtquirkz.com. Surely that's illegal? Let's find out, in this week's Security Levity...

...Read more

read more

AT&T iPad privacy breach: Goatse email "theft" thoughts

In this week's Security Levity, I want to talk about the recent AT&T Apple iPad privacy breach, as discovered by Goatse Security. I also want to talk more generally about how companies often leak their customers' email addresses.

...Read more

Outbound spam: hard data illustrates real risks

In today's Security Levity, I've got more on the outbound spam problem. Back in April, I argued that it's critical for networks to block outbound spam, to protect your reputation and the deliverability of your email. I also said that outbound spam can be a symptom of far more damaging problems, specifically malware that could damage your business. Today, I want to talk about an independent study that sheds more light -- and hard data -- on these issues...

...Read more

read more

Tabnapping: don't be scared of new phishing trick

In this week's Security Levity, I want to address the fears raised about a new phishing trick. Dubbed tabnapping, it was recently dreamed up by Mozilla's Aza Raskin. Commentators around the web are worrying about its potential. But is the sky falling? No! Let's see why...

...Read more

Ask Amir #5: How to deal with gray reputation?

In this week's Security Levity: a reply to a couple of reader questions about spam filtering techniques. Specifically, the types of techniques that can be used when the sender's reputation is 'gray'.

...Read more

Real-world DLP: people are a problem

In this week's Security Levity, the second part of my interview with Abhilash V. Sonwane, vice president of product management at Cyberoam. Abhilash has extensive experience building data-loss-prevention solutions that help organizations keep their sensitive data confidential. I'm sure you'll agree that he brings some thoughtful insights into real-world data loss prevention (DLP).

...Read more

Spammer tricks: unnatural acts with spam filters

This week's Security Levity is a follow-on from last week's. I want to talk about one more spammer trick: how they misuse spam filters, to try to get delivered to the inbox. I have first-hand intelligence confirming what many spam fighters have long-suspected...

...Read more

read more

Spammer tricks: link shenanigans

In the next two weeks' Security Levity, I want to cover some more tricks that spammers employ to avoid spam filters. This time: messing around with the embedded web links in their messages.

...Read more

read more

Real-world email defense in depth: keep it simple, stupid

In this week's Security Levity, I'm interviewing Cameron Brown, the VP of engineering at Sendio. Cameron has been architecting email protection systems for many years; he has an interesting perspective on balancing simplicity with "defense-in-depth".

...Read more

Latest spam zombie research data

In this week's Security Levity, I want to talk more about zombies and botnets, sharing the results of some research we've been doing into this problem. I'll also pass on some encouraging recent news that hasn't gotten the attention it deserves.

...Read more

read more

Why is spam filtering such a challenge?

This week in Security Levity, I'm digging further into the topic of spam filtering technology. Today, I want to talk about why spam filtering seems to be such a continual challenge for filter vendors. I mean, we've been filtering spam automatically since the mid-80s -- how come we haven't fully mastered it yet?

...Read more

read more

Outbound spam: the canary in the coalmine

Earlier in Security Levity, I argued that you should block outbound spam, because otherwise your legitimate email may go unread. Here's another reason why you should control outbound spam. As I'll explain in this post, it isn't only a question of preventing spam or protecting your email reputation -- outbound spam can be a sign of far more damaging problems...

...Read more

read more

How good is your outbound spam protection?

This week on Security Levity, I want to talk about a recent trend in spamming and spam filtering, which has important implications for people who run email networks -- be they corporate or consumer. In summary: it's now critical for networks to block outbound spam. Read on to understand why...

...Read more

read more

Text message spam: is it a big problem?

In this week's Security Levity, I want to talk about spam again -- not email spam, but spam sent via SMS. Also known as text message spam. I want to get to the bottom of whether SMS spam is as a big a problem as email spam -- and if not, why not?

...Read more

read more