Comcast Admits Their Zombie Problem

from the biggest-spammers-on-the-net dept

People have been talking about the problems of zombie machines spewing spam for a while. One of the biggest issues is how to get the broadband providers to do something about it, and to help stop the flow of spam from the computers of users who have no idea they're sending out spam. One of the biggest targets in this discussion is Comcast - who, by their sheer size in the market, appears to have the most subscribers with compromised machines. In fact, last week, they admitted that they were, technically, "the biggest spammer on the internet." They say that Comcast users send out 800 million messages a day - and 700 million of them are spam from zombie machines. Many have complained that Comcast hasn't taken the situation seriously, but that seems to have changed lately. Over the last few months they've been a lot more proactive in letting subscribers know that their machines have been taken over - but it still takes a while, and end-users who end up getting cut off are often not savvy enough to understand what's happening or how to fix it. One potential solution is to block port 25 - something that many other ISPs do - but Comcast has rejected that plan, knowing that the complaint and support costs would be overwhelming. Instead, it sounds like they've come up with a fairly creative method of dealing with the problem. They're going to monitor overall usage, and if they become aware of a problem, they will remotely adjust only that user's modem to block port 25. While this may still cause an occasional headache for some users, the overall impact should be much lower, and the non-tech-savvy zombie-fied customer will have the problem they didn't know about solved without them knowing about it as well.
Hide this

Thank you for reading this Techdirt post. With so many things competing for everyone’s attention these days, we really appreciate you giving us your time. We work hard every day to put quality content out there for our community.

Techdirt is one of the few remaining truly independent media outlets. We do not have a giant corporation behind us, and we rely heavily on our community to support us, in an age when advertisers are increasingly uninterested in sponsoring small, independent sites — especially a site like ours that is unwilling to pull punches in its reporting and analysis.

While other websites have resorted to paywalls, registration requirements, and increasingly annoying/intrusive advertising, we have always kept Techdirt open and available to anyone. But in order to continue doing so, we need your support. We offer a variety of ways for our readers to support us, from direct donations to special subscriptions and cool merchandise — and every little bit helps. Thank you.

–The Techdirt Team


Reader Comments

Subscribe: RSS

View by: Time | Thread


  1. identicon
    Anonymous Coward, 24 May 2004 @ 12:58pm

    Creative Solution Doublespeak

    Instead of blocking port 25 they've decided to block port 25 instead.

    link to this | view in thread ]

  2. icon
    Mike (profile), 24 May 2004 @ 1:24pm

    Re: Creative Solution Doublespeak

    uh... blocking all port 25s is quite different than just blocking those that are causing problems.

    link to this | view in thread ]

  3. identicon
    data64, 24 May 2004 @ 4:08pm

    Re: Creative Solution Doublespeak

    Its the where they are blocking that is different not the what they are blocking.

    link to this | view in thread ]

  4. identicon
    Nonesuch, 24 May 2004 @ 9:54pm

    Intercept SMTP traffic

    Just as many ISPs transparently intercept outbound TCP/80 traffic and force all browser clients to use a caching proxy unless the user opts-out, Comcast could intercept all outbound TCP/25 traffic from the average dynamic IP customer pools, force connections through a dedicated pool of "customer" SMTP relay servers.

    This would allow automated detection and selective blocking of zombies, along with virus scanning, rate limiting, and other controls.

    Customers who want to run their own mail servers would be upset, as would users who want to send email through authenticating SMTP servers at their employer or email provider. (For the latter, the smart customers will use SSL encrypted SMTP on TCP/465.)

    link to this | view in thread ]

  5. identicon
    Phibian, 25 May 2004 @ 5:32am

    Re: Creative Solution Doublespeak

    It's actually the "who" not the what :)

    link to this | view in thread ]


Follow Techdirt
Essential Reading
Techdirt Deals
Report this ad  |  Hide Techdirt ads
Techdirt Insider Discord

The latest chatter on the Techdirt Insider Discord channel...

Loading...
Recent Stories

This site, like most other sites on the web, uses cookies. For more information, see our privacy policy. Got it
Close

Email This

This feature is only available to registered users. Register or sign in to use it.