Indeed, I was going to say that. I already knew it, not because I've ever used that company, but because trigger-happy antivirus email generators the world over have sent me messages with the bizarre title "Panda Perimeter Scan".
Oh, thankyou, excellent. Still leaves the question as to why they relayed something they knew was an attempt at fraud rather than just dropping it, but that's a more widespread form of idiocy...
The general thinking (he says, having once had to do spam filtering for a company) is that one doesn't know for certain it's a phishing attack, so one lets it through with a warning attached so the recieving user can make the final decision.
What I personally feel is broken is checking outbound e-mail:
If you add a message saying something's benign when it isn't you might get sued.
If you add a message saying you know something is malicious but send it anyway you might get sued.
The recipient shouldn't trust such notices from anywhere but their local system anyway (indeed, malicious messages often include fake no-virus-found footers).
As you've just discovered, the message may not be in the right language for the recipient.
Checking outbound mail makes sense for consumer ISPs if they drop the bad mail (i.e. if they are confident enough in the checking, or uncaring enough of their users), as a way of reducing the amount of spam sent out, thus keeping themselves out of blacklists, reducing their bandwidth bills, etc. (For inbound mail obviously it's a matter of local policy what you do with the suspected-bad mail.)
(no subject)
Date: 2007-07-10 11:00 pm (UTC)(no subject)
Date: 2007-07-10 11:13 pm (UTC)(no subject)
Date: 2007-07-11 12:11 am (UTC)(no subject)
Date: 2007-07-11 07:57 am (UTC)(no subject)
Date: 2007-07-11 09:14 am (UTC)"Panda: in a bamboo thicket, no-one can hear you scream"
(no subject)
Date: 2007-07-11 09:51 am (UTC)stringpanda?(no subject)
Date: 2007-07-11 10:52 am (UTC)(no subject)
Date: 2007-07-11 08:41 am (UTC)(no subject)
Date: 2007-07-11 08:52 am (UTC)(no subject)
Date: 2007-07-11 09:17 am (UTC)(no subject)
Date: 2007-07-11 12:58 pm (UTC)What I personally feel is broken is checking outbound e-mail:
- If you add a message saying something's benign when it isn't you might get sued.
- If you add a message saying you know something is malicious but send it anyway you might get sued.
- The recipient shouldn't trust such notices from anywhere but their local system anyway (indeed, malicious messages often include fake no-virus-found footers).
- As you've just discovered, the message may not be in the right language for the recipient.
*sigh*(no subject)
Date: 2007-07-11 01:19 pm (UTC)(no subject)
Date: 2007-07-11 09:01 am (UTC)(no subject)
Date: 2007-07-11 09:54 am (UTC)(no subject)
Date: 2007-07-11 01:34 pm (UTC)(no subject)
Date: 2007-07-11 08:29 pm (UTC)Knowing them, it wouldn't surprise me if it was actually real...