{"id":69,"date":"2004-02-01T19:40:54","date_gmt":"2004-02-01T19:40:54","guid":{"rendered":""},"modified":"2004-02-01T19:40:54","modified_gmt":"2004-02-01T19:40:54","slug":"","status":"publish","type":"post","link":"https:\/\/www.sungate.co.uk\/?p=69","title":{"rendered":"Annoyed by other people&#8217;s anti-virus software"},"content":{"rendered":"<p>This is a rant.<\/p>\n<p>The recent <a href=\"http:\/\/www.sophos.com\/virusinfo\/articles\/maindoom.html\">MyDoom<\/a> viruses have been causing me annoyance.  Not because my system can be infected by them, because it can&#8217;t &#8211; it&#8217;s not Windows.  Not even because I have received a large number of emails containing these viruses from infected individuals &#8211; I haven&#8217;t; as far as I can tell, I haven&#8217;t actually received even <i>one<\/i> infected message in this way.  (Actually, that might not be true, they could all have been caught in my spam trap &#8230; but I haven&#8217;t noticed any.)<\/p>\n<p>So what am I complaining about?<\/p>\n<p>Well, it&#8217;s the continual stream of &#8220;The message you sent to bob@place.com was infected with a virus &#8211; please check your system!&#8221;  I have had <i>loads<\/i> of these.<\/p>\n<p>This is how it works:<\/p>\n<ul>\n<li>Clueless individual receives a virus-infected email and opens the attachment;<\/li>\n<li>The virus code starts to run &#8211; it begins generating new email messages to propogate itself.  To do this, it chooses two email addresses at random from the infected user&#8217;s address book &#8211; one of these addresses will become the &#8220;From:&#8221; address for the message, the other will be the &#8220;To:&#8221; address;<\/li>\n<li>In many cases, the infected person has <i>me<\/i> in their address book, so my address goes out as the &#8220;From:&#8221; address, even though I&#8217;ve had nothing to do with the message;<\/li>\n<li>For some recipients (the &#8220;To:&#8221; users), their corporate anti-virus software returns what it assumes to be a helpful message saying that I have sent their poor user a virus-infected message.<\/li>\n<\/ul>\n<p>So, you see the problem.  The corporate anti-virus system is replying to the supposed-sender of a message which they <i>know has been generated by a virus that fakes the sender<\/i>.  Not even remotely helpful and probably doing more harm than good since it generates lots of unnecessary email messages.  In fact, some of these &#8220;you have sent us a virus&#8221; messages are more than just a simple notification &#8211; they are bordering on full-page advertisements for the anti-virus software in question.  Given that this message is commercial and is, by definition, going to someone who has no previous relationship to the company, I expect this meets most people&#8217;s definition of <i>spam<\/i>.<\/p>\n<p>I have now decided to write to postmaster@wherever.com whenever I receive one of these notifications.  I am asking them to configure their system so that these notifications are not sent.  It is an option on every setup that I am aware of, but often defaults to &#8216;on&#8217; simply because the anti-virus companies realise that this is good advertising.  (&#8220;Hey, Bob, this FooSoft Anti-Virus seems to be detecting loads of viruses &#8211; why don&#8217;t <i>we<\/i> use that??&#8221;)  If the notification is particularly &#8216;spammy&#8217;, I am copying my messages to the anti-virus company too.<\/p>\n<p>OK, rant over &#8230; but if you&#8217;ve got me in your address-book &#8211; make sure your system is clean!<\/p>\n<p><b>Updated Monday 02.02.2004 19:24<\/b>: The article Martin refers to in his comment is <a href=\"http:\/\/www.attrition.org\/security\/rant\/av-spammers.html\">this one<\/a> and it&#8217;s discussed on Slashdot <a href=\"http:\/\/slashdot.org\/article.pl?sid=04\/01\/29\/1847211&#038;mode=nested&#038;tid=111&#038;tid=126&#038;tid=172\">here<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is a rant. The recent MyDoom viruses have been causing me annoyance. Not because my system can be infected by them, because it can&#8217;t &#8211; it&#8217;s not Windows. Not even because I have received a large number of emails containing these viruses from infected individuals &#8211; I haven&#8217;t; as far as I can tell,&#8230;&nbsp;(<a href=\"https:\/\/www.sungate.co.uk\/?p=69\">read more<\/a>)<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-69","post","type-post","status-publish","format-standard","hentry"],"_links":{"self":[{"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/69","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=69"}],"version-history":[{"count":0,"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=\/wp\/v2\/posts\/69\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=69"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=69"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sungate.co.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=69"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}