Click here to close now.

Welcome!

Linux Authors: Elizabeth White, Carmen Gonzalez, Pat Romanski, Liz McMillan, Roger Strukhoff

Related Topics: Linux

Linux: Article

Spam and the Linux Desktop

Dealing with unsolicited commercial e-mail as a Linux desktop user

It's a fact of life for most of us: we all receive e-mail solicitations to "Make Money Fast" or for a "Mail Order Drugstore" or offensive or adult content that makes us blush, especially when a colleague is looking over our shoulder. Spam, a slang term for Unsolicited Commercial E-mail (UCE), has reached epidemic proportions. It clogs our inboxes and saps our productivity. I have a long history with spam - in a former career I was a "net abuse cop" for a large ISP.

In those days spammers (the accepted slang term for bulk mailers sending UCE) spent their time harvesting message headers from Usenet newsgroups and sending solicitations to those who had posted on topics ranging from computers to religion. Soon enough the spammers improved or, more accurately, became more insidious in their tactics to get their unwelcome messages into your inbox. That's why this month's installment of Dr. Migration is dedicated to spam and the Linux desktop.

SPAM Prevention Strategies

Dealing with spam is not only a Linux problem, it affects users of Macs, Windows, and Unix workstations as well as cell phone users who utilize e-mail to SMS (short messaging service) text messaging. Everyday spammers are scheming to fill our e-mail boxes with various solicitations for a cadre of products. That's why you should take as many precautions as you can to prevent junk e-mail. Many of these precautions are platform independent and are ways to improve your life on the Internet.

Protect Your E-mail Address

It may sound like an obvious precaution but many people don't guard their e-mail address with the same vigilance they protect their phone number or their address. Once you share your e-mail address, you trust that the person or organization will only utilize it for the prescribed use. Be sure to read the fine print in their offers or you may unknowingly agree to be on a mailing list.

My point is, when giving out your e-mail, you should verify that it won't be shared or find out what exactly the prescribed use is. My strategy is that when I do share my address with a source that I know little about, I use my secondary e-mail address. This is a second e-mail address that has little value to me if it becomes overwhelmed since I simply change it. I then check this e-mail address only when I feel I might be receiving information that I requested regarding a product or service. Then my daily work and personal e-mail boxes aren't subject to the abuse that this address often receives. I think many of us do this already, but those who don't and suffer from an inordinate amount of junk mail may want to start the practice.

HTML E-Mail: Don't Download Images from the Server

When you receive an HTML e-mail, besides the obvious message, bulk e-mailers often use a register bit that is usually a small transparent image that, when you view the message, loads and then alerts them that you have read that e-mail. This helps them understand which of their messages successfully reaches an end user and qualifies that e-mail address as a target for further advertisements. One way to prevent this is to not download images from the server. Three popular e-mail clients for the Linux desktop - Kmail, Thunderbird, and Evolution - enable you to turn off the accessing of Internet resources from the body of the e-mail, defeating this information-gathering campaign.

E-Mail Attachments: Be Aware of Worms and Viruses

One of the things that we are all very cognizant of (or should be) from the perspective of a Windows desktop is the risk of viruses. It's not uncommon to see news stories describing the damage caused by the latest Windows virus, and these viruses cause millions of dollars of damage. However, just because you are running a Linux desktop doesn't mean you should be lax in your approach to e-mail attachments and their hidden payloads. The fact is that a Linux virus doesn't get near the bang for the buck as a Windows virus because the Linux desktop user is in the minority. Authors of these malicious programs receive less notoriety by propagating their viruses on the Linux desktop simply because their target is substantially smaller. Also, if you are running a Linux desktop, you may just be an unwitting carrier of viruses. Since you'd be impervious to a virus that exploits VB script or ActiveX you may simply be passing it on to a colleague who reads mail on a Windows PC. So do take precautions when forwarding on the latest joke, or any document for that matter.

Alternative Office Advantage: Word Versus OpenOffice

In earlier versions of Microsoft Word, viruses prevailed by exploiting the macro language (WordBasic) and then causing global changes to the desktop. Later versions of Word ask if you would like to enable macros or not. However, being quick on the draw and clicking through these warnings as many people still do may cause problems.

If you are still using a Windows desktop, consider using OpenOffice on Windows as your primary word processor. The reason is that when you receive an attachment that you think might be suspect, you could open it in a program that is less likely to be exploited. OpenOffice has a macro language but it differs from the one that Word uses. This difference would insulate you from that type of attack. The problem is that over time the increased popularity of these alternative office suites will probably result in targeted attacks from unscrupulous programmers. In the near term, reading the Microsoft Office documents that you receive from unfamiliar sources or even those that you know in OpenOffice may be a good preventative measure.

Server-Side Spam Filtering

E-mail servers are often thought of as electronic post offices that simply route mail to individual users, no questions asked. However, e-mail servers can also incorporate other protective measures like virus scanning and spam filtering to protect you, the end user, from malicious or time-sapping e-mail that you never care to see. Applying a preventative measure at the server saves users from having to deal with spam and viruses on an individual basis. You may want to work with your mail administrator to incorporate some simple rules to remove some of your junk e-mail. One tactic is to verify that the mail server sending you e-mail has a valid DNS entry. Much of today's UCE comes from illegitimate sources, not from a credible mail server that ISPs or businesses use. Most system administrators will have some additional ideas on what the common tactics are for avoiding this mail.

My best advice for dealing with spam is that if the e-mail never gets to your inbox, it can't sap your time dealing with it. Also, qualifying the mail as potentially suspect upon arrival to your e-mail box can be helpful as well. One of the most effective measures I have taken is to flag potential spam and then filter that out of my inbox for further review. I accomplish the server-side filtering through SpamAssassin, a popular open source project.

SpamAssassin

(http://spamassassin.apache.org/)

Probably the most popular open source application for server-side spam filtering is SpamAssassin. It allows you to filter e-mail and make decisions on the server or as a mail agent running locally that qualifies e-mail before it reaches your inbox. SpamAssassin uses a number of tactics to identify spam. These tactics include:

  • Header analysis: Tries to identify the mail headers of a message for information that might indicate the e-mail message is suspect.
  • Text analysis: Works much the same way as header analysis. SpamAssassin identifies patterns that may indicate a message is spam.
  • Blacklists: Many community organizations provide lists of known spammers and e-mail domains that have been known to send spam. These blacklists can be used by SpamAssassin to filter UCE offenders qualified by a volunteer network.
  • "Learning" rules: SpamAssassin also has the ability to "learn" what might be spam and to use the probability of what might be spam to classify it as such.
I use SpamAssassin for my corporate e-mail server. Based on some training it sends e-mail to me with the designa-tion of "[Spam]" in the subject line preceding the original subject so I can filter those messages to a local folder and scan to make sure they are all junk mail and not important. The reason I do this rather than just deleting [Spam]-labeled subjects is to avoid what is known as a "false positive," which means based on my criteria it seems that the e-mail is spam but in fact it's a legitimate e-mail. I very seldom find an error in the logic but, as in most automated systems, there is some fallibility, especially if you try to be overly aggressive in your filtering.

Challenge Base Response

As anyone who has ever sent an e-mail to my LinuxWorld address knows, you'll receive a polite but pointed message that asks you to explain why you want to contact me. This service is provided by my ISP (Earthlink's Spamblocker); all e-mail sent to me is first filtered by Brightmail (www.brightmail.com), a spam-filtering service that forwards all suspected spam to my server-side spam folder. Then anything that it's unsure of goes into my suspect queue and waits for my intervention before it's downloaded. Those who send e-mails that arrive in my "suspect queue" receive a request for more information. While initially this prospect horrified me as being incredibly unfriendly, I have rarely if ever received a complaint. It's an unfortunate necessity of using e-mail these days. It also is another way you can keep junk mail from reaching your desktop.

Linux E-Mail Clients

One of the must-have features in e-mail clients these days is the ability at some level to have a spam filter or at least the ability to add filters to handle spam in a more efficient fashion. The most common e-mail clients for the Linux desktop are all able to filter and in some cases include anti-spam facilities. The following round up is a short primer on how to deal with spam with three common Linux e-mail clients.

Thunderbird

(www.mozilla.org/products/thunderbird/)

Thunderbird is an extension of the Mozilla project (www.mozilla.org) offering a robust e-mail client packed with features and capabilities that rival any commercial application. Also, Thunderbird is available for Windows, Mac OS X, and Linux, so if you are still considering the move to Linux you can try out Thunderbird today on your non-Linux desktop, and then still be able to use the same client when you move to Linux.

Thunderbird is probably the most advanced of any Linux e-mail client in its spam-filtering abilities. Thunderbird has junk mail controls that are very effective in detecting and acting on unsolicited e-mail. Spam can then be detected and deleted or stored in a folder for later review in the event of a false positive. Also, Thunderbird has a way to "whitelist" e-mail so you can be assured that e-mails from a certain address never get "wrongly imprisoned" by your spam filters. One innovative feature in Thunderbird is the option to use adaptive filters that can analyze incoming messages and flag those likely to be junk e-mail (see Figure 1).

Evolution

(www.novell.com/products/evolution/)

Novell's Evolution e-mail client is one of the most popular e-mail and PIMs (Personal Information Managers) for Linux. While there are no specific filters in Evolution there are many ways to prevent spam from clogging your Evolution inbox. Most definitely you should choose not to allow the loading of images from the network as referenced earlier. In Evolution, under the Evolution Settings -> Mail Preferences -> HTML Mail you should check "never load images off the Net" or "load images if sender is in address book" (see Figure 2).

Just because Evolution doesn't include a spam filtering system doesn't mean you're out of luck. Actually Evolution has a powerful filtering system that can access spam filters outside the program. Many Linux users have been successful in allowing Ximian to access bogofilter (www.bogofilter.sourceforge.net) via a wrapper script and then using bogofilter for a statistical process known as the Bayesian technique to make decisions on what is and is not spam. Also, the same SpamAssassin that I highlighted for server use could be used on your Linux desktop in conjunction with Evolution and the mail filters in Evolution.

KMail

(http://kmail.kde.org)

KMail, which is part of the KDE desktop, is also a popular Linux e-mail client and while there is no anti-spam features included in the current release, the next version of KMail will add an "Antispam Wizard," which if you have the capability now I'm sure your e-mail will never be without it again (see Figure 3).

Web-Based E-Mail Clients

Since you may be migrating to Linux gradually, you may still be working between two operating systems. So downloading and storing mail in one system versus another may not be in your best interest while you're in transition, or maybe you've decided to store your e-mail on a server that has scheduled backups. This approach is very advantageous because you can access your e-mail from almost any Web browser on numerous platforms. Also, it's a step in the direction of centrally managed applications and data that, I believe, improves the potential success of desktop PC users on most any platform. Also, by keeping data on the server rather than on disparate desktop PCs, you can have it managed consistently across an organization, applying spam filtering and virus checking on the server rather than at each individual user's desk. This approach is usually more efficient than each user doing it on an individual basis.

That's why solutions that offer server-side management and storage like IMAP (Internet Message Access Protocol) are valuable, because they allow you to access messages as if they were local but require a network connection to do so. There are a number of solutions for doing this. If you have a POP or IMAP server you can use a number of popular "free" Web interfaces including Squirrel Mail (www.squirrelmail.org/), Neomail (http://sourceforge.net/projects/neomail/), or the full-featured Horde Project (www.horde.org). The bottom line is that reducing the complexity of the PC desktop makes it easier to choose which platform you want to use, avoids vendor lock-in, and improves your ability to choose how you will accomplish your desktop computing goals.

Summary

No matter what your platform or your e-mail client preference, spam is a fact of life. Hopefully you're already using some of my prescribed methods to reduce your spam burden. If not, you might have something to think about when you finish this article. My best advice for dealing with spam: prevent it from entering your inbox in the first place. Deal with it at the server level, where you can provide an enterprise-wide blanket of protection from spam and viruses, then be vigilant on your desktop to keep malicious programs out of your workspace.

Additional Resources

  • http://spam.abuse.net
  • http://spamcop.net
  • www.cauce.org

    SIDEBAR

    SCALIX: Server-Based E-Mail and Calendaring

    Scalix, an enterprise messaging company, headquartered in San Mateo, CA, believes that Linux is the ideal platform to build messaging solutions based on the openness and security of the platform. However, they also recognize that users migrating from Windows to Linux are going to encounter differences between the two platforms; their solution is to provide a robust Web-based interface. They also provide a Web client, Scalix Web Access, that is more robust than many Web-based e-mail clients and allows you to work in the three-pane type of environment your current mail solution uses rather than in a single Web page.

    This next-generation Web interface including calendaring is a viable alternative to traditional e-mail clients. In addition, Scalix includes hooks for easy integration of third-party spam filtering additions.

  • More Stories By Mark R. Hinkle

    Mark Hinkle is the Senior Director, Open Soure Solutions at Citrix. He also is along-time open source expert and advocate. He is a co-founder of both the Open Source Management Consortium and the Desktop Linux Consortium. He has served as Editor-in-Chief for both LinuxWorld Magazine and Enterprise Open Source Magazine. Hinkle is also the author of the book, "Windows to Linux Business Desktop Migration" (Thomson, 2006). His blog on open source, technology, and new media can be found at http://www.socializedsoftware.com.

    Comments (1) View Comments

    Share your thoughts on this story.

    Add your comment
    You must be signed in to add a comment. Sign-in | Register

    In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


    Most Recent Comments
    Dan Jacobson 10/19/04 03:36:18 PM EDT

    Well, who's going to send you email if they have to pass a quiz or you keep changing your address.
    http://jidanni.org/comp/spam/index_en.html

    @ThingsExpo Stories
    SYS-CON Events announced today that ActiveState, the leading independent Cloud Foundry and Docker-based PaaS provider, has been named “Silver Sponsor” of SYS-CON's DevOps Summit New York, which will take place June 9-11, 2015, at the Javits Center in New York City, NY. ActiveState believes that enterprises gain a competitive advantage when they are able to quickly create, deploy and efficiently manage software solutions that immediately create business value, but they face many challenges that prevent them from doing so. The Company is uniquely positioned to help address these challenges thro...
    SYS-CON Events announced today that Vitria Technology, Inc. will exhibit at SYS-CON’s @ThingsExpo, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Vitria will showcase the company’s new IoT Analytics Platform through live demonstrations at booth #330. Vitria’s IoT Analytics Platform, fully integrated and powered by an operational intelligence engine, enables customers to rapidly build and operationalize advanced analytics to deliver timely business outcomes for use cases across the industrial, enterprise, and consumer segments.
    SYS-CON Events announced today that Alert Logic, the leading provider of Security-as-a-Service solutions for the cloud, has been named “Bronze Sponsor” of SYS-CON's 16th International Cloud Expo® and DevOps Summit 2015 New York, which will take place June 9-11, 2015, at the Javits Center in New York City, NY, and the 17th International Cloud Expo® and DevOps Summit 2015 Silicon Valley, which will take place November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA.
    The WebRTC Summit 2015 New York, to be held June 9-11, 2015, at the Javits Center in New York, NY, announces that its Call for Papers is open. Topics include all aspects of improving IT delivery by eliminating waste through automated business models leveraging cloud technologies. WebRTC Summit is co-located with 16th International Cloud Expo, @ThingsExpo, Big Data Expo, and DevOps Summit.
    SYS-CON Events announced today that Akana, formerly SOA Software, has been named “Bronze Sponsor” of SYS-CON's 16th International Cloud Expo® New York, which will take place June 9-11, 2015, at the Javits Center in New York City, NY. Akana’s comprehensive suite of API Management, API Security, Integrated SOA Governance, and Cloud Integration solutions helps businesses accelerate digital transformation by securely extending their reach across multiple channels – mobile, cloud and Internet of Things. Akana enables enterprises to share data as APIs, connect and integrate applications, drive part...
    SYS-CON Events announced today that CommVault has been named “Bronze Sponsor” of SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY, and the 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. A singular vision – a belief in a better way to address current and future data management needs – guides CommVault in the development of Singular Information Management® solutions for high-performance data protection, universal availability and sim...
    SYS-CON Events announced today that SafeLogic has been named “Bag Sponsor” of SYS-CON's 16th International Cloud Expo® New York, which will take place June 9-11, 2015, at the Javits Center in New York City, NY. SafeLogic provides security products for applications in mobile and server/appliance environments. SafeLogic’s flagship product CryptoComply is a FIPS 140-2 validated cryptographic engine designed to secure data on servers, workstations, appliances, mobile devices, and in the Cloud.
    The best mobile applications are augmented by dedicated servers, the Internet and Cloud services. Mobile developers should focus on one thing: writing the next socially disruptive viral app. Thanks to the cloud, they can focus on the overall solution, not the underlying plumbing. From iOS to Android and Windows, developers can leverage cloud services to create a common cross-platform backend to persist user settings, app data, broadcast notifications, run jobs, etc. This session provides a high level technical overview of many cloud services available to mobile app developers, includi...
    BroadSoft on Tuesday announced that it is a recipient of the 2014 Frost & Sullivan Market Leadership Award in the Hosted/Cloud Internet Protocol (IP) Telephony market for Latin America. According to Frost & Sullivan market research, the Latin America (LATAM) hosted/cloud Internet Protocol (IP) telephony market, including integrated unified communications and collaboration (UC&C) applications, is currently experiencing a rapid growth trajectory and is expected to exhibit a tenfold rise in annual revenues in the 2013-2020 period. With more than 600 cloud deployments internationally, BroadSoft w...
    SYS-CON Events announced today that StorPool Storage will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. StorPool is distributed storage software that allows service providers, enterprises and other cloud builders to run data storage on standard x86 servers, instead of using expensive and inefficient storage arrays (SAN).
    Temasys has announced senior management additions to its team. Joining are David Holloway as Vice President of Commercial and Nadine Yap as Vice President of Product. Over the past 12 months Temasys has doubled in size as it adds new customers and expands the development of its Skylink platform. Skylink leads the charge to move WebRTC, traditionally seen as a desktop, browser based technology, to become a ubiquitous web communications technology on web and mobile, as well as Internet of Things compatible devices.
    GENBAND has announced that SageNet is leveraging the Nuvia platform to deliver Unified Communications as a Service (UCaaS) to its large base of retail and enterprise customers. Nuvia’s cloud-based solution provides SageNet’s customers with a full suite of business communications and collaboration tools. Two large national SageNet retail customers have recently signed up to deploy the Nuvia platform and the company will continue to sell the service to new and existing customers. Nuvia’s capabilities include HD voice, video, multimedia messaging, mobility, conferencing, Web collaboration, deskt...
    VoxImplant has announced full WebRTC support in the newest versions of its Android SDK and iOS SDK. The updated SDKs, which enable audio and video calls on mobile devices, are now compatible with the WebRTC standard to allow any mobile app to communicate with WebRTC-enabled browsers, including Google Chrome, Mozilla Firefox, Opera, and, when available, Microsoft Spartan. The WebRTC-updated SDKs represent VoxImplant's continued leadership in simplifying the development of real-time communications (RTC) services for app developers. VoxImplant (built by Zingaya, the real-time communication servi...
    SYS-CON Events announced today that Site24x7, the cloud infrastructure monitoring service, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Site24x7 is a cloud infrastructure monitoring service that helps monitor the uptime and performance of websites, online applications, servers, mobile websites and custom APIs. The monitoring is done from 50+ locations across the world and from various wireless carriers, thus providing a global perspective of the end-user experience. Site24x7 supports monitoring H...
    SYS-CON Events announced today that Intelligent Systems Services will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Established in 1994, Intelligent Systems Services Inc. is located near Washington, DC, with representatives and partners nationwide. ISS’s well-established track record is based on the continuous pursuit of excellence in designing, implementing and supporting nationwide clients’ mission-critical systems. ISS has completed many successful projects in Healthcare, Commercial, Manufacturing, ...
    Sonus Networks introduced the Sonus WebRTC Services Solution, a virtualized Web Real-Time Communications (WebRTC) offer, purpose-built for the Cloud. The WebRTC Services Solution provides signaling from WebRTC-to-WebRTC applications and interworking from WebRTC-to-Session Initiation Protocol (SIP), delivering advanced real-time communications capabilities on mobile applications and on websites, which are accessible via a browser.
    SYS-CON Events announced today that B2Cloud, a provider of enterprise resource planning software, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. B2cloud develops the software you need. They have the ideal tools to help you work with your clients. B2Cloud’s main solutions include AGIS – ERP, CLOHC, AGIS – Invoice, and IZUM
    SYS-CON Events announced today that Tufin, the market-leading provider of Security Policy Orchestration Solutions, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. As the market leader of Security Policy Orchestration, Tufin automates and accelerates network configuration changes while maintaining security and compliance. Tufin's award-winning Orchestration Suite™ gives IT organizations the power and agility to enforce security policy across complex, multi-vendor enterprise networks. With more than 1...
    SYS-CON Events announced today that Cloudian, Inc., the leading provider of hybrid cloud storage solutions, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Cloudian, Inc., is a Foster City, California - based software company specializing in cloud storage software. The main product is Cloudian, an Amazon S3-compliant cloud object storage platform, the bedrock of cloud computing systems, that enables cloud service providers and enterprises to build reliable, affordable and scalable cloud storage solu...
    “With easy-to-use SDKs for Atmel’s platforms, IoT developers can now reap the benefits of realtime communication, and bypass the security pitfalls and configuration complexities that put IoT deployments at risk,” said Todd Greene, founder & CEO of PubNub. PubNub will team with Atmel at CES 2015 to launch full SDK support for Atmel’s MCU, MPU, and Wireless SoC platforms. Atmel developers now have access to PubNub’s secure Publish/Subscribe messaging with guaranteed ¼ second latencies across PubNub’s 14 global points-of-presence. PubNub delivers secure communication through firewalls, proxy ser...