On TechRepublic: Windows 7: Slower to boot than Vista?
BNET Business Network:
BNET
TechRepublic
ZDNet

April 11th, 2006

Common sense and lawsuits don't mix

Posted by George Ou @ 11:27 am

Categories: Security

Tags:

In today’s litigious society, common sense is often out the door with some juries with the "stick it to the man" mentality are eager to give large awards even when no real faults are found.  In one of our more heated TechRepublic debates, member "sostermann" posts "Can porn spam be considered sexual harassment to employees?"  Sostermann tells of a new employee who has complained to upper management stating "This is now border line harassing!  It would be unreasonable to hold an employer liable for any vulgar message than an employee may come across. Some employees would consider this sexual harassment."  Having been in a similar position, I can see his dilemma and I feel his pain.

The company in this case is a small business with limited resources.  Email is outsourced to a cheap POP3 mail provider who filters "obvious" spam.  Although it wasn’t stated in the post, my guess is that the inexpensive ISP is probably using a free open source solution which may not have the best catch rate in order to minimize false positives.  Spam filtering is not an exact science and never will be because email by definition means that you’re willing to accept email from strangers.  The fact that domain-level authentication standards have not been widely deployed makes it even tougher because emails can fake their identities.  As a result, spam filtering usually boils down to the following:

  • Keyword filters 
  • Existence of a reverse lookup for the sender domain
  • Hash (digital fingerprint) of the message to see if it’s been sent to many other recipients throughout the world
  • Heuristics
  • Obvious blacklisted sender domains
  • Obvious blacklisted SMTP servers
  • SPF, SenderIDDomainKeys (all low penetration)

The problem is that even with all of the above; it takes a lot to fine tune an anti-spam solution.  The Internet is like living in a neighborhood where every hoodlum and vandal in the world is within 1 minute of your business or home and you have some nice white walls facing the street.  Even if you keep 99 vandals from spraying garbage on your walls, 1 will eventually get through.  In the spam business, even the best anti-spam solution misses 1% of spam if they wish to maintain an extremely low false positive rate.  Most people would rather not see spam at all but given the choice, they’re willing to see a few get through in order to avoid missing that critical letter they’ve been waiting for.  In a former company I worked for, one of our executives had one of his time-sensitive mortgage refinance letter caught in the spam filter as a false positive and he was obviously rather upset.  In another false positive case where an important email was lost, the message contained a reference to a product code "6xxx".  The key word filter caught the "xxx" portion and blocked it as spam.

Unfortunately, we had an HR head that wasn’t very sympathetic to the situation because she simply assumed that the spam problem was trivial and that it was easily fixed if only IT weren’t so incompetent.  We could get a more accurate spam solution would either cost $50,000 or we would have to go to an expensive email scrubbing outfit neither of which were easily approved and IT was caught in the middle and the perception was that we were idiots.  Since it’s a matter of reality that it is impossible to block all unsolicited messages, it would be unreasonable to hold an employer liable for any vulgar message than an employee may come across.

In my college days as a waiter, I was routinely harassed by rowdy customers and sometimes even threatened with violence.  Sure it isn’t pleasant but that doesn’t mean I’m entitled to win a lawsuit against the restaurant because of a customer’s bad behavior so long as some effort was made to protect my safety and eject trouble makers.  Now I’m no lawyer and maybe I’m just a bit old fashioned, but there needs to be some sanity brought back in to the world.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 83 Talkback(s)
Others have already pointed out that the free solutions aren't as effective
... without a substantial amount of tuning. Others have also pointed out that the commercial solutions are indeed better out of the box. As for Microsoft, they don't really have a solution at the ga... (Read the rest)
Posted by: georgeou Posted on: 04/16/06 You are currently: a Guest | | Terms of Use
Lawsuit happy  Roger Ramjet | 04/11/06
Two steps  rjhenn_z | 04/12/06
This argument has been mentioned several times at my workplace.  nucrash | 04/11/06
'Misdirection', I like that!  george_ou | 04/11/06
I owed you one for "Paths" the other day  nucrash | 04/11/06
Agreed  george_ou | 04/11/06
Bad example  Yagotta B. Kidding | 04/11/06
No, he made a good choice  george_ou | 04/11/06
Hot cup.  Anton Philidor | 04/11/06
A foam cup?  george_ou | 04/11/06
It Wasn't The Cup  Edward Meyers | 04/11/06
Cancer eh?  george_ou | 04/12/06
RE: Hot Cup  Scott W | 04/12/06
They have paper drink holders  nucrash | 04/12/06
Not Familure With The Case  Edward Meyers | 04/12/06
And Yes- Cancer  Edward Meyers | 04/12/06
I don't know if the US is different  voska | 04/12/06
RE: Not Familiar with the Case  Scott W | 04/13/06
Re: Not Familar with the case.  maldain | 04/13/06
watch who you call stupid  big red one | 04/12/06
Coffee is served hot, this is common sense.  nucrash | 04/12/06
Hot not Boiling  Edward Meyers | 04/12/06
Water Boils at 212 Degrees F  nucrash | 04/12/06
It was held at 210 Degrees  Edward Meyers | 04/12/06
But I use boiling water for my baby formula as do most people  george_ou | 04/12/06
You Mix At That Temp But You Don't Hold It At That Temp  Edward Meyers | 04/12/06
YOU'RE NOT 5 YEARS OLD!  george_ou | 04/12/06
RE: Wath who you call stupid  Scott W | 04/13/06
I don't drink coffee but how about tea  voska | 04/13/06
frivolous? not a good example  big red one | 04/12/06
Yes, Coffee I make can possible couse 4th degree burns  vbp1 | 04/12/06
4th degree burns?  D-cat | 04/12/06
I know you kept this gender neutral...  ju1ce | 04/11/06
But that's the point  george_ou | 04/11/06
I agree...  ju1ce | 04/11/06
Good example, Here's another one.  nizuse | 04/11/06
I wish it were that simple  george_ou | 04/11/06
metrpolitan police did something similar  Scott W | 04/12/06
Oh fun, the race card.  nucrash | 04/12/06
Race Card? Here's what you can do with your race card  Shelendrea | 04/12/06
Paragraphs are a beautiful thing..  nucrash | 04/12/06
Farming  voska | 04/13/06
Laws of Supply and Demand  nucrash | 04/13/06
I've seen the same thing.  enduser_z | 04/11/06
There is a fine balance  george_ou | 04/11/06
So here is the problem...  Linux User 147560 | 04/12/06
Diversity Training  Erik1234 | 04/11/06
You're never obligated to be an '******'  george_ou | 04/11/06
It's a matter of perspective...  Erik1234 | 04/11/06
What ever happened to avoiding people.  nucrash | 04/13/06
IMHO  tombalablomba | 04/11/06
Great point  george_ou | 04/11/06
Try the experiment, George  Yagotta B. Kidding | 04/11/06
I think you both have points  george_ou | 04/11/06
"Using your e-mail freely"  Yagotta B. Kidding | 04/11/06
Blaming the victim  Yagotta B. Kidding | 04/11/06
Amen  Dave F_z | 04/11/06
Never use your work address, or any valid address...  ju1ce | 04/11/06
Your wrong  Been_Done_Before | 04/12/06
You are very dim  Dave F_z | 04/13/06
That's what you get...  Erik1234 | 04/11/06
No you directly, however....  nucrash | 04/12/06
Dictionary attacks etc.  tombalablomba | 04/12/06
Pathetic  Richard Flude | 04/11/06
Open source tools are effective too  george_ou | 04/11/06
Name them  Richard Flude | 04/11/06
No changes and no attacks  george_ou | 04/11/06
See, George...  rapson | 04/12/06
No kidding, even for things I didn't say  george_ou | 04/12/06
But George, it is what you say and how you say it.  Letophoro | 04/12/06
Others have already pointed out that the free solutions aren't as effective  georgeou | 04/16/06
I can name a few  voska | 04/12/06
To be honest  tombalablomba | 04/12/06
LOL, your funny.  Been_Done_Before | 04/12/06
Woops  Been_Done_Before | 04/12/06
Not so much the cost of free tools  nucrash | 04/12/06
Way to make up the news George.  Letophoro | 04/12/06
Raising the Mercury  D-cat | 04/12/06
good retort, Letophoro  JetJaguar | 04/12/06
Couple of thoughts  Linux User 147560 | 04/12/06
You know what?  Shelendrea | 04/12/06
Its not just common sense and lawsuits  Shelendrea | 04/12/06
Landlord vs Tenant, Rich vs Poor, Honest vs Dishonest  Erik1234 | 04/12/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads