<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Kommentare zu: How to secure your email address correctly on the web</title>
	<atom:link href="http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/</link>
	<description>From the land of wobbly windows</description>
	<lastBuildDate>Thu, 11 Mar 2010 00:58:18 +0100</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Von: Martin</title>
		<link>http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/comment-page-1/#comment-6215</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Wed, 07 Oct 2009 19:20:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/#comment-6215</guid>
		<description>@Goo: if you don&#039;t need digitized books: fine. I need them and I want that they get digitzed and if that can be done in an outomated process even better. And btw. reCAPTCHA did not start as a Google service, that is a very recent development.</description>
		<content:encoded><![CDATA[<p>@Goo: if you don&#8217;t need digitized books: fine. I need them and I want that they get digitzed and if that can be done in an outomated process even better. And btw. reCAPTCHA did not start as a Google service, that is a very recent development.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Goo</title>
		<link>http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/comment-page-1/#comment-6214</link>
		<dc:creator>Goo</dc:creator>
		<pubDate>Wed, 07 Oct 2009 19:13:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/#comment-6214</guid>
		<description>I&#039;m sorry but your response in regard to Google is nonsense. By solving the reCaptcha you provide Google with free labor (aka unpaid work). This labor directly contributes to Google&#039;s value e.g. as it makes their offering of scanned books better than that of any competitors. Google is extremely good at making people work for them for free. And this is the reason why you shouldn&#039;t touch any of their products.</description>
		<content:encoded><![CDATA[<p>I&#8217;m sorry but your response in regard to Google is nonsense. By solving the reCaptcha you provide Google with free labor (aka unpaid work). This labor directly contributes to Google&#8217;s value e.g. as it makes their offering of scanned books better than that of any competitors. Google is extremely good at making people work for them for free. And this is the reason why you shouldn&#8217;t touch any of their products.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Michael "I am not a bad guy" Howell</title>
		<link>http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/comment-page-1/#comment-6209</link>
		<dc:creator>Michael "I am not a bad guy" Howell</dc:creator>
		<pubDate>Wed, 07 Oct 2009 15:26:50 +0000</pubDate>
		<guid isPermaLink="false">http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/#comment-6209</guid>
		<description>@Sebastián Benítez: &quot;I think the only way to stop spam is counterattacking with DDOS.&quot;

DDOS is worse than SPAM. By definition, it eats lots of bandwidth. Besides of which, it&#039;s illegal.</description>
		<content:encoded><![CDATA[<p>@Sebastián Benítez: &#8220;I think the only way to stop spam is counterattacking with DDOS.&#8221;</p>
<p>DDOS is worse than SPAM. By definition, it eats lots of bandwidth. Besides of which, it&#8217;s illegal.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Sebastián Benítez</title>
		<link>http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/comment-page-1/#comment-6207</link>
		<dc:creator>Sebastián Benítez</dc:creator>
		<pubDate>Wed, 07 Oct 2009 14:55:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/#comment-6207</guid>
		<description>Stop being so paranoid. If your mail is harvested so what? You&#039;ll get more spam in your spam folder, that&#039;s all. I think the only way to stop spam is counterattacking with DDOS. Then the ISP of those machines acting as zombies for massive nets are going to take note and do something.</description>
		<content:encoded><![CDATA[<p>Stop being so paranoid. If your mail is harvested so what? You&#8217;ll get more spam in your spam folder, that&#8217;s all. I think the only way to stop spam is counterattacking with DDOS. Then the ISP of those machines acting as zombies for massive nets are going to take note and do something.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: André</title>
		<link>http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/comment-page-1/#comment-6206</link>
		<dc:creator>André</dc:creator>
		<pubDate>Wed, 07 Oct 2009 14:47:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/#comment-6206</guid>
		<description>In Germany we have some problems with law which requires you to lay open your contact information on your web site. Of course it should the contact information should also be barrier-free...

The purpose of &quot;obfuscaption protection&quot; is just to reduce a likelihood of email harvesting. Of course you can quickly write an attack script that grabs an email address. Otherwise you simply hand out the mail address to spammers.</description>
		<content:encoded><![CDATA[<p>In Germany we have some problems with law which requires you to lay open your contact information on your web site. Of course it should the contact information should also be barrier-free&#8230;</p>
<p>The purpose of &#8220;obfuscaption protection&#8221; is just to reduce a likelihood of email harvesting. Of course you can quickly write an attack script that grabs an email address. Otherwise you simply hand out the mail address to spammers.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: halo</title>
		<link>http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/comment-page-1/#comment-6199</link>
		<dc:creator>halo</dc:creator>
		<pubDate>Wed, 07 Oct 2009 12:24:29 +0000</pubDate>
		<guid isPermaLink="false">http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/#comment-6199</guid>
		<description>you just proved with your arguments that the captcha discussion is useless anyway, since there are already a information monopols by google and other huge crawlers/service providers and all you can do is *nothing* about your mail address getting caught by them.
you can only hope that you cannot be made responsible for your mails by the state, which is cooperating with google in all countries. and hope they won&#039;t do what they promise at the moment: share more information between different parties to improve crime detection.

bad luck, preventing porn ads in your mail account should be your least problem actually.

p.s. you can create a lot of free public e-mail accounts of course, but this won&#039;t safe you from their intensive scanning either. now set up your mail server and create accounts as you wish, but hey they know your domain and still will track you easily... maybe speek l33t?, no it is easy to do regexp transformations on strings today... so do it in tor or minion... now c&#039;mon you paranoids, this is a political issue, which logically cannot be solved technically, but only politically. fight against surveillance or rest in quietness forever.</description>
		<content:encoded><![CDATA[<p>you just proved with your arguments that the captcha discussion is useless anyway, since there are already a information monopols by google and other huge crawlers/service providers and all you can do is *nothing* about your mail address getting caught by them.<br />
you can only hope that you cannot be made responsible for your mails by the state, which is cooperating with google in all countries. and hope they won&#8217;t do what they promise at the moment: share more information between different parties to improve crime detection.</p>
<p>bad luck, preventing porn ads in your mail account should be your least problem actually.</p>
<p>p.s. you can create a lot of free public e-mail accounts of course, but this won&#8217;t safe you from their intensive scanning either. now set up your mail server and create accounts as you wish, but hey they know your domain and still will track you easily&#8230; maybe speek l33t?, no it is easy to do regexp transformations on strings today&#8230; so do it in tor or minion&#8230; now c&#8217;mon you paranoids, this is a political issue, which logically cannot be solved technically, but only politically. fight against surveillance or rest in quietness forever.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Andre</title>
		<link>http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/comment-page-1/#comment-6198</link>
		<dc:creator>Andre</dc:creator>
		<pubDate>Wed, 07 Oct 2009 12:15:23 +0000</pubDate>
		<guid isPermaLink="false">http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/#comment-6198</guid>
		<description>Obfuscation is no Captcha. Obfuscations/Crypting and CAPTCHAs both belong to the family of Challenge-Response Tests. I still don&#039;t understand the point here, though. I have places where it&#039;s perfectly fine to use obfuscation (which definitely does work) and where it would be quite out of place to use captchas. On the other hand I use reCAPTCHA frequently (on all comment forms, registrations, contact formulars, etc. pp.).</description>
		<content:encoded><![CDATA[<p>Obfuscation is no Captcha. Obfuscations/Crypting and CAPTCHAs both belong to the family of Challenge-Response Tests. I still don&#8217;t understand the point here, though. I have places where it&#8217;s perfectly fine to use obfuscation (which definitely does work) and where it would be quite out of place to use captchas. On the other hand I use reCAPTCHA frequently (on all comment forms, registrations, contact formulars, etc. pp.).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Von: Steve</title>
		<link>http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/comment-page-1/#comment-6195</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Wed, 07 Oct 2009 11:39:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.martin-graesslin.com/blog/2009/10/how-to-secure-your-email-address-correctly-on-the-web/#comment-6195</guid>
		<description>Hi Martin!

I think your point is correct, but is worth it to take the time to change what we already have?

&gt; Obfuscation is broken and it is only a matter of time till harvesters start to harvest the email addresses

It it, but how long is that?  I made the point last time about low hanging fruit, and I submit that it is enough for me that my fruit hangs higher.  In my case, I fully realise that spammers could at any moment start executing JavaScript and evaluating the results.  How long is it until they do?  I like my solution, as the end user gets an un-obfuscated clickable &#039;mailto&#039; link, whereas a (non-JS) bot doesn&#039;t get anything that even remotely resembles an email address.

For anyone still using &quot;foo at bar dot com&quot; style obfuscation, I would say it is worth the time to change what you have for the following reason: /(\w+)\s+at\s+((\w+)(\s+dot\s+(\w+))+)/ -- and that&#039;s only a very simple one off the top of my head.  Your fruit hangs low!  :-)

Steve</description>
		<content:encoded><![CDATA[<p>Hi Martin!</p>
<p>I think your point is correct, but is worth it to take the time to change what we already have?</p>
<p>&gt; Obfuscation is broken and it is only a matter of time till harvesters start to harvest the email addresses</p>
<p>It it, but how long is that?  I made the point last time about low hanging fruit, and I submit that it is enough for me that my fruit hangs higher.  In my case, I fully realise that spammers could at any moment start executing JavaScript and evaluating the results.  How long is it until they do?  I like my solution, as the end user gets an un-obfuscated clickable &#8216;mailto&#8217; link, whereas a (non-JS) bot doesn&#8217;t get anything that even remotely resembles an email address.</p>
<p>For anyone still using &#8220;foo at bar dot com&#8221; style obfuscation, I would say it is worth the time to change what you have for the following reason: /(\w+)\s+at\s+((\w+)(\s+dot\s+(\w+))+)/ &#8212; and that&#8217;s only a very simple one off the top of my head.  Your fruit hangs low!  <img src='http://blog.martin-graesslin.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Steve</p>
]]></content:encoded>
	</item>
</channel>
</rss>
