Rendered at 21:43:16 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
mrmattyboy 1 days ago [-]
The uceprotect Level 3 page clearly says using the list will cause collateral damage and should only use as an indicator as part of a spam score, not to act purely on it.
So, yes, if a service provider is known for having a lot of spam coming from it, it makes sense to be on there. They're not saying every IP is bad, they're literally stating the opposite (which seems fair).
So, if Orange are blocking purely based on it, not only are they using a spam filter as a DNS query/web filter (given uceprotect seems to flag based on mail spam traps based detections etc.) and ignoring their documentation (which says it shouldn't be used to block on it's own).
goldenmember 1 days ago [-]
Well, if it's just an indicator, why not delist automatically on request, as other blocklists do? It seems inappropriate to charge for this.
niels8472 1 days ago [-]
And not just charge. You need to get a subscription even!
portagescout 1 days ago [-]
[flagged]
nubinetwork 1 days ago [-]
Theoretically speaking, a person could get themselves blocked, request an unblocking, and keep on spamming, hoping they won't get blocked again.
john_strinlai 1 days ago [-]
right now, they can apparently just spend $108/year and keep on spamming.
AndrewKemendo 1 days ago [-]
This is what capitalist “regulation” looks like in practice
literalAardvark 1 days ago [-]
Because they don't want to. You can create one too and add whoever you like to it.
The problem is either with other things raising your scores (very likely) or with Orange dropping traffic based on the wrong list (unlikely)
JohnMakin 1 days ago [-]
DigitalOcean has been on their list for a while, they say something like “if you don’t want to be flagged as spam, dont host on a site that hosts spammers” which is pretty ridiculous given every cloud platform does
mmh0000 1 days ago [-]
It’s not ridiculous.
Hosting providers should be good citizens of the network and immediately terminate spammer accounts. This used to be standard practice until about 2015. When suddenly management decided it’s more profitable host spammers than not.
I think this is a great policy decision by uceprotect.
xp84 22 hours ago [-]
I’m not saying one shouldn’t endeavor to terminate spammers immediately, but I’m pretty sure that it doesn’t matter if you do, because as soon as you terminate the account, another one’s gonna be spun up immediately with another fake identity. The only thing that would change that would be the exact kind of heavy-handed identity-verification BS that most of us don’t really care for. And even then, it will only change it slightly. Spammers will be paying people in the third world $20 to use their passport to sign up for a cloud hosting account so they can spam for a few days.
JohnMakin 1 days ago [-]
Why DigitalOcean in particular though? Why not Cloudflare? A significant percentage of malicious and spam traffic is hosted on or routed through cloudflare services. Why not AWS? Same thing. It's a personal grudge, and they aren't quite big enough or have powerful enough lawyers to cause a widespread problem if put on a list, so, the big players are left alone.
All that aside, the website and their communication around this over the years is extraordinarily unprofessional and it's astounding to me they wield such power.
mmh0000 1 days ago [-]
I ran my own small-business/family mail server for a little over a decade. Spam is out of control.
UCEPROTECT and other RBLs are just lists of text files. They do not block anything. As the mail administrator, you can choose what you do with a UCEPROTECT listing.
When I ran my mail server, I had UCEPROTECT tied into SpamAssassin, so that a UCEPROTECT listing by itself wouldn't block email; it would just raise the "spam probability rating" up.
UCEPROTECT is not a huge professional thing; it's "some guy" who's been running it, effectively, for free since the very early 2000s. No one is obligated to use it. If someone is being blocked by it, they need to contact the mail admin. UCEPROTECT just lists problematic hosts.
On to WHY DO and no CF/AWS? I don't know.. I'm not the "some guy" running the thing. But if I had to guess, it's that DO doesn't respond to spam complaints[1]. Whereas CF/AWS, while they host spammers, will take action against reported spammers.
"This time, however, we have a premiere: A Woman. Actually, it reads more like a brat than a woman [...] If we were as emotional as you are and report you to our authorities, the handcuffs might click the next time you move your ass off the British Isles. [...] This means that they have heared that bullshit you spammed to them at times when you still slipped across the floor with your shit diaper. :-) [...]
Grow up and also try to grow a brain before you make a fool out of yourself, again next time.
their main page has an iamverybadass quote, too: "WARNING: Do not play around here. You have no idea who we really are, and what will happen to you!"
ciupicri 1 days ago [-]
If Orange relies on them I would say they're pretty bad ass.
goldenmember 1 days ago [-]
srv12039172893: Many ISPs across EU use Cisco's Talos Intelligence and similar solutions that automatically feed themselves of random blacklists like Uceprotect. [1]
I hope all the people who think that the Internet is hostile now understand…
the Internet used to be almost entirely composed of this guy.
Like in 1996 if you wanted to do something on the Internet you had to deal with some version of him. I worked for the top car electronics installer in Houston in the 90s, who ran a few websites as a hobby and he was 100% like this.
Literally sat and typed out Monty Python dialogue so he could just have it hosted on his page, and would make .WAVs of annoying customers to put on the site
Gracana 1 days ago [-]
> Literally sat and typed out Monty Python dialogue
Dear god.
AndrewKemendo 1 days ago [-]
Right, you know exactly the person I’m describing
ozim 1 days ago [-]
Sounds like this should go via Orange they have means to slap UCEPROTECT on the wrist. It also looks like it would be in Orange business to have proper spam lists not ones like that.
goldenmember 1 days ago [-]
While I absolutely agree that Orange is acting irresponsibly here, I also understand that they're not the only ones who rely on UCEPROTECT.
literalAardvark 1 days ago [-]
Mail server operators have known about uceprotect L3 for a long time.
I've had a successful mail sender on that list for almost two decades.
Your problem is most likely something else, and if it's not something else then Orange are being completely ridiculous.
tagyro 1 days ago [-]
Playing the devil’s advocate, my domains get constantly scanned from DO ips. I know it’s not feasible but some basic kyc on DO’s side would probably help.
Polizeiposaune 1 days ago [-]
Do you have any direct evidence that the Orange block is due to the listing in UCEPROTECT?
Digital Ocean is not a great neighborhood.
After seeing periodic bursts of login attempts from there, I now block all inbound ssh from AS14061 (among several such bad neighborhoods) as no authorized clients are hosted there and there is a constant level of attempted attacks from there.
petecooper 1 days ago [-]
UCEPROTECT Extortion Service: All Your Mails Are Belong To Us! (2009)
I personally found Meteor in Ireland (previously owned by Orange) to be far more liberal with blocks on an unregistered mobile internet connection than other providers.
Also, Orange UK have a much stricter block list to enforce than, for example, Orange FR.
swores 1 days ago [-]
Do you mean EE, or are you speaking from memories that are from a while ago?
Orange UK disappeared over a decade ago (merged with T-Mobile to become EE in 2010, then they stopped using the Orange brand in the UK in 2015).
rithdmc 1 days ago [-]
Meteor Ireland also shut down about a decade ago.
goldenmember 1 days ago [-]
Orange FR.
throwaway67743 1 days ago [-]
This is not new, "UCEPROTECT" has been a garbage RBL doing this for decades (even listing blocks preemptively, so that when they're assigned they're unusable), nobody worth emailing actually uses it.
pelagicAustral 1 days ago [-]
I think what's happening is obviously not fair, and should be corrected, but I also what to say that I've had pretty bad experiences when working with DO. I think maybe what happens is that they take too long to weed out problematic accounts. Not going to mention any other provider so it's not assumed that shilling for someone else, but there are quite a few that are no in the AWS, GCP, or Azure tier and work just fine, so, shouldnt be too hard to find a replacement.
cendyne 1 days ago [-]
UCEPROTECT is why I stopped self hosting my own email :(
someonebaggy 1 days ago [-]
I use my least reputable domains to send emails that are most important for the recipient and least important for me. If they don't receive it now it's their problem not mine.
SoftTalker 1 days ago [-]
That's the thing a lot of people don't understand about email. Delivery is not guaranteed. And neither is notification about failed delivery. Bits can just fall on the floor somewhere and you'll never know.
account42 1 days ago [-]
That is technically true for any communication method. In practice, email is extremely reliably except for deliberate decisions to drop mail. You can literally shut down your mail server for days and some time after you boot it back up you'll get all the mail people have been sending during that time. What other protocol gives you that reliability without complex failover infrastructure.
edoceo 1 days ago [-]
I know of one regulator in USA (WSLCB) that sends critical and time sensitive notifications via email only. Has had delivery problems for at least five years and cannot see the flaw in their system.
someonebaggy 1 days ago [-]
Is the flaw on their side or your side?
edoceo 1 days ago [-]
Varies. Some times their system doesn't get the message to their outgoing gateway, sometimes their gateway doesn't deliver (and it's a different agency that runs that, so support is hardly available), sometimes our provider (G) filters the messages. It's a mess all round.
The core flaw is depending on email for this. In fact it used to be a real-time API and the agency regressed to this. And their own system doesn't recognize invalid or undeliverable messages so it can get lost easy.
nottorp 1 days ago [-]
Apparently in this uceprotect thing my home ip (business connection, fixed IP) has a "dns problem" because there's a PTR record at my ISP but not an A record.
Seriously?
The rest of the list is as credible as that?
literalAardvark 1 days ago [-]
Yes.
Source: managed a high volume (by layperson standards, it's not very high volume) commercial mail server for more than a decade.
1 days ago [-]
ButlerianJihad 1 days ago [-]
For a long time, the Internet has been replete with blocklists and reputation scores cultivated by admins who had the means to track such things. And ad-blocking software/DNS often gives users the chance to tap into those bad reputations and protect themselves.
However, there is nothing preventing function/scope creep of these blocklists into things they should not be. Political bias, censorship, morality policing will trickle into blocklists. Furthermore these false positives are quite onerous for legit businesses and customers who sincerely want to connect. I've connected again to an ad-blocking DNS service, and many people may subscribe to filtering services, or simply be involuntarily subscribed, in the hopes that their Internet would stay usable, and scam-free.
I suppose this is the price to pay in low-trust society (wild and wooly Internet). I wonder if the Great Firewall of China obviates the need for their citizens to throw up such protective measures.
garaetjjte 1 days ago [-]
Why do you think Orange is using Uceprotect? It seems unlikely that big corp would use some weird unknown list.
srv12039172893 1 days ago [-]
Many ISPs across EU use Cisco's Talos Intelligence and similar solutions that automatically feed themselves of random blacklists like Uceprotect.
Polizeiposaune 1 days ago [-]
or, perhaps, Talos Intelligence observes the same behaviors observed by the operators of uceprotect and independently identifies the subnet as a source of threats.
diamondDrill 1 days ago [-]
its like we are in the grifted age
virrdhiman 17 hours ago [-]
[flagged]
someonebaggy 1 days ago [-]
All of the spam blocklists are like this.
At one time quite recently, Cloudflare was on Spamhaus's "Don't Route Or Peer" list. Imagine where the world would be if anyone cared about that list.
But if an entire ISP is blocking you based on UCEPROTECT, which is designed for email spam filters - are you sure? An ISP that blocked all of DO would get so many complaints and be open to so much legal liability. Usually these are only used for email filtering.
john_strinlai 1 days ago [-]
>At one time quite recently, Cloudflare was on Spamhaus's "Don't Route Or Peer" list.
it was only 2 /23's (only 1024 IPs, ASN14061 is 3,140,680 IPs), and was resolved without a monthly subscription in ~24 hours after being posted to the NANOG mailing list
the scale of the issue is significantly different and the resolution is significantly different (both in time and in money). that's important when comparing the situations.
highlighting those differences does not mean i think either situation is "good". one of them is "less bad" though.
goldenmember 1 days ago [-]
I disagree. Normally you can reach out to request delisting, and it's free.
As I explained, Orange's security filter seems to automatically block requests at the DNS level if your website's domain resolves to an IP listed on UCEPROTECT Level 3. In this case, that appears to be the entire DigitalOcean ASN.
someonebaggy 1 days ago [-]
You probably have standing to sue Orange for damages if they're blocking your customers from you based on bullshit criteria.
I am not a lawyer, so consult one.
ttul 1 days ago [-]
Spamhaus does not offer the ability to pay for removal. UCEPROTECT is uniquely evil in insisting on payment. It's a good thing that their lists are not widely used, so, in practice, it doesn't matter if your IPs are listed by them. Their revenue comes from unwitting victims who don't know any better.
JohnMakin 1 days ago [-]
Their lists are definitely used, which is the only way I knew about them - some years ago one major email provider was not receiving email from my DO hosted site at all, completely blackholed. I knew enough of what I was doing to know this was practically impossible, spent over a week running every kind of configuration scan and test I could think of, and finally narrowed it down to this organization in particular blacklisting all of DO IP space. Needless to say I was shocked and annoyed at such an unprofessional looking and sounding website wielding such control over the operation of my site (which, lest it needs to be said, was a completely legitimate site).
seebeen 1 days ago [-]
[dead]
tcdent 1 days ago [-]
Forgive the snark, but I find it incredibly surprising that in your 20-year career you haven't arrived at the conclusion that self-hosting your own outbound email is not worth it, especially if you don't own and/or manage the reputation of your IPv4 block.
goldenmember 1 days ago [-]
> _website_ was being blocked
mercurialuser 1 days ago [-]
I was reviewing uceprotect policies a couple of hours ago and what you say is really strange.
Uce level 3 should never be used alone to block general tcp traffic.
Are you saying that Orange is using uce level 3 to block email sent from your DO vm? Are you really sure that Orange blocks for this list only?
Is it possible that your ip is on another RBL?
If Orange is really blocking smtp based only on uce level 3 they are doing wrong: their system may be mis-configured or they have not read correctly hiw level 3 is populated.
Or - probably - they did on pourpose!
Today I checked september smtp traffic: almost 99% of traffic coming from uce level 1 (single ips) was spam. Traffic hitting level 2 but not present in level 1 (subnets, one I checked was /15!!) was also 99% spam.
Of the 5000k messages received, very few arrived into the mailboxes. A lot of messages were blocked by following spam checks and the few remaining were flagged as spam.
I feel your pain. If you host on DO and you send email, you should look for a email provider that will funnel your emails.
Ps: i repeat, email shoild not be bloocked only by uce level 3
So, yes, if a service provider is known for having a lot of spam coming from it, it makes sense to be on there. They're not saying every IP is bad, they're literally stating the opposite (which seems fair).
So, if Orange are blocking purely based on it, not only are they using a spam filter as a DNS query/web filter (given uceprotect seems to flag based on mail spam traps based detections etc.) and ignoring their documentation (which says it shouldn't be used to block on it's own).
The problem is either with other things raising your scores (very likely) or with Orange dropping traffic based on the wrong list (unlikely)
Hosting providers should be good citizens of the network and immediately terminate spammer accounts. This used to be standard practice until about 2015. When suddenly management decided it’s more profitable host spammers than not.
I think this is a great policy decision by uceprotect.
All that aside, the website and their communication around this over the years is extraordinarily unprofessional and it's astounding to me they wield such power.
UCEPROTECT and other RBLs are just lists of text files. They do not block anything. As the mail administrator, you can choose what you do with a UCEPROTECT listing.
When I ran my mail server, I had UCEPROTECT tied into SpamAssassin, so that a UCEPROTECT listing by itself wouldn't block email; it would just raise the "spam probability rating" up.
UCEPROTECT is not a huge professional thing; it's "some guy" who's been running it, effectively, for free since the very early 2000s. No one is obligated to use it. If someone is being blocked by it, they need to contact the mail admin. UCEPROTECT just lists problematic hosts.
On to WHY DO and no CF/AWS? I don't know.. I'm not the "some guy" running the thing. But if I had to guess, it's that DO doesn't respond to spam complaints[1]. Whereas CF/AWS, while they host spammers, will take action against reported spammers.
[1] https://www.reddit.com/r/sysadmin/comments/1cwilrc/does_digi...
for example: "People with a brain would simply fix their systems after getting listed for abuse. Stupid losers are different." http://www.uceprotect.org/cart00neys/index.html
or
"This time, however, we have a premiere: A Woman. Actually, it reads more like a brat than a woman [...] If we were as emotional as you are and report you to our authorities, the handcuffs might click the next time you move your ass off the British Isles. [...] This means that they have heared that bullshit you spammed to them at times when you still slipped across the floor with your shit diaper. :-) [...]
Grow up and also try to grow a brain before you make a fool out of yourself, again next time.
Claus von Wolfhausen
Technical Director
" http://www.uceprotect.org/cart00neys/2021-001.htmltheir main page has an iamverybadass quote, too: "WARNING: Do not play around here. You have no idea who we really are, and what will happen to you!"
https://news.ycombinator.com/item?id=49966613
Check this...
the Internet used to be almost entirely composed of this guy.
Like in 1996 if you wanted to do something on the Internet you had to deal with some version of him. I worked for the top car electronics installer in Houston in the 90s, who ran a few websites as a hobby and he was 100% like this.
Literally sat and typed out Monty Python dialogue so he could just have it hosted on his page, and would make .WAVs of annoying customers to put on the site
Dear god.
I've had a successful mail sender on that list for almost two decades.
Your problem is most likely something else, and if it's not something else then Orange are being completely ridiculous.
Digital Ocean is not a great neighborhood.
After seeing periodic bursts of login attempts from there, I now block all inbound ssh from AS14061 (among several such bad neighborhoods) as no authorized clients are hosted there and there is a constant level of attempted attacks from there.
https://www.aaroncake.net/misc/showthought.asp?thought=57
I personally found Meteor in Ireland (previously owned by Orange) to be far more liberal with blocks on an unregistered mobile internet connection than other providers.
Also, Orange UK have a much stricter block list to enforce than, for example, Orange FR.
Orange UK disappeared over a decade ago (merged with T-Mobile to become EE in 2010, then they stopped using the Orange brand in the UK in 2015).
The core flaw is depending on email for this. In fact it used to be a real-time API and the agency regressed to this. And their own system doesn't recognize invalid or undeliverable messages so it can get lost easy.
Seriously?
The rest of the list is as credible as that?
Source: managed a high volume (by layperson standards, it's not very high volume) commercial mail server for more than a decade.
However, there is nothing preventing function/scope creep of these blocklists into things they should not be. Political bias, censorship, morality policing will trickle into blocklists. Furthermore these false positives are quite onerous for legit businesses and customers who sincerely want to connect. I've connected again to an ad-blocking DNS service, and many people may subscribe to filtering services, or simply be involuntarily subscribed, in the hopes that their Internet would stay usable, and scam-free.
I suppose this is the price to pay in low-trust society (wild and wooly Internet). I wonder if the Great Firewall of China obviates the need for their citizens to throw up such protective measures.
At one time quite recently, Cloudflare was on Spamhaus's "Don't Route Or Peer" list. Imagine where the world would be if anyone cared about that list.
But if an entire ISP is blocking you based on UCEPROTECT, which is designed for email spam filters - are you sure? An ISP that blocked all of DO would get so many complaints and be open to so much legal liability. Usually these are only used for email filtering.
it was only 2 /23's (only 1024 IPs, ASN14061 is 3,140,680 IPs), and was resolved without a monthly subscription in ~24 hours after being posted to the NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/...
the scale of the issue is significantly different and the resolution is significantly different (both in time and in money). that's important when comparing the situations.
highlighting those differences does not mean i think either situation is "good". one of them is "less bad" though.
As I explained, Orange's security filter seems to automatically block requests at the DNS level if your website's domain resolves to an IP listed on UCEPROTECT Level 3. In this case, that appears to be the entire DigitalOcean ASN.
I am not a lawyer, so consult one.
Uce level 3 should never be used alone to block general tcp traffic.
Are you saying that Orange is using uce level 3 to block email sent from your DO vm? Are you really sure that Orange blocks for this list only? Is it possible that your ip is on another RBL?
If Orange is really blocking smtp based only on uce level 3 they are doing wrong: their system may be mis-configured or they have not read correctly hiw level 3 is populated.
Or - probably - they did on pourpose!
Today I checked september smtp traffic: almost 99% of traffic coming from uce level 1 (single ips) was spam. Traffic hitting level 2 but not present in level 1 (subnets, one I checked was /15!!) was also 99% spam.
Of the 5000k messages received, very few arrived into the mailboxes. A lot of messages were blocked by following spam checks and the few remaining were flagged as spam.
I feel your pain. If you host on DO and you send email, you should look for a email provider that will funnel your emails.
Ps: i repeat, email shoild not be bloocked only by uce level 3