Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Critical Eye on SpamAssassin

Posted by CmdrTaco on Tue Nov 25, 2003 08:52 AM
from the not-totally-surprising dept.
ErrorBase writes "In this Infoworld article, Logan G. Harbaugh makes a great deal about an ancient (2.44) version of SpamAssassin comparing it with newer comercial variants. Quote : You get what you pay for. [...] However, it took more than 10 times as long to install and configure SpamAssassin as it did any of the other products. " Why did he not ask Kevin Railsback who had the whole thing working some while ago?)"
This discussion has been archived. No new comments can be posted.
Critical Eye on SpamAssassin | Log In/Create an Account | Top | 324 comments (Spill at 50!) | Index Only | Search Discussion
Display Options Threshold:
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1) | 2
  • What is a good client-side spam filter for Outlook by Dancin_Santa (Score:1) Tuesday November 25 2003, @08:55AM
  • Nice to see... by PhilippeT (Score:1) Tuesday November 25 2003, @08:55AM
  • SpamAssassin (Score:5, Interesting)

    by hookedup (630460) on Tuesday November 25 2003, @08:57AM (#7557331)
    All my incomming mail comes through SpamAssassin (cant remember which version off the top of my head), and once in a blue moon a single piece of spam will manage to find it's way through. When it does, I guess i should just applaud the spammer for being so devious.

    TrollAssasin would be nice, imagine seeing posts subjects as *****TROLL***** heh
  • by ACK!! (10229) on Tuesday November 25 2003, @08:59AM (#7557357)
    (Last Journal: Friday June 23 2006, @12:04PM)
    Seems like this guy did not verbalize it but that was his problem. If you know what you are doing hacking a conf file from vi is easier than a gui for sure. However, his low performance and configuration woes would have probably been handled with a easy to use graphical interface.

    Aren't there tools that do this?
  • a problem with reviewers (Score:5, Insightful)

    by Taranis-BSD (699090) on Tuesday November 25 2003, @09:00AM (#7557363)
    (http://www.bsd-unix.net/~bruce)
    This was just a setup to make commercial software look better or just a incompetent reviewer. Next.
  • Coming soon at Infoworld... (Score:5, Insightful)

    "We compare a collection of recent operating systems: Windows XP Professional, Mac OS X Panther, Debian GNU/Linux 0.91".

    Seriously, InfoWorld, SpamAssassin 2.44 was released in February, all the other vendors you compared were constantly updating their products to cope with the ever changing nature of spam.

    John.
  • Logan You Better Run (Score:5, Informative)

    by Anonymous Coward on Tuesday November 25 2003, @09:01AM (#7557378)
    Great - compare generation or more older open source to fresh shrinkwrap. Who's zooming (or shilling) for who.

    My ISP (souther NH) runs SpamAssassin 2.6 - and I can tell you that at the default settings it catches 90-95% with .01% (yes Bucko, less than 1/1000) false positives. When they implemented it several versions ago it was just as good.

    I've got one client where the run NO filter - some folks (the names GOTTA be on the web site) get up to 100 spams a day. IT are basically monkeys with hands. I have no idea what the CEO thinks. They wouldn't even think OS as they're a total MS shop.
    • Re:Logan You Better Run by sirReal.83. (Score:1) Tuesday November 25 2003, @09:07AM
    • Re:Logan You Better Run (Score:4, Informative)

      by shis-ka-bob (595298) on Tuesday November 25 2003, @09:57AM (#7557938)
      From the home page of Spam Assassin:
      Razor: Vipul's Razor is a collaborative spam-tracking database, which works by taking a signature of spam messages. Since spam typically operates by sending an identical message to hundreds of people, Razor short-circuits this by allowing the first person to receive a spam to add it to the database -- at which point everyone else will automatically block it.

      From the review:
      All the products except Brightmail and SpamAssassin allow end-users to add senders to the domain whitelist themselves. Brightmail allows users to forward misidentified e-mails to the administrator, who can choose to add the sender to the whitelist. SpamAssassin allows only the administrator to add to the whitelist, with no direct access for users.

      Who is missing something here? Me or the reviewer? It looks like Razor does exactly what he wants to do and claims that SpamAssassin doesn' t do. It seems to me you are right ... selectively comparing old OS with newer commercial software so that he can make claims that are factually correct about SpamAssassin 2.44 but completely missleading about the current version.

      [ Parent ]
    • Re:Logan You Better Run by Refried Beans (Score:3) Tuesday November 25 2003, @10:47AM
    • Re:Logan You Better Run by PPGMD (Score:1) Tuesday November 25 2003, @10:57AM
    • *splutter* by magicianuk (Score:1) Tuesday November 25 2003, @11:46AM
    • Re:Logan You Better Run by HermanZA (Score:1) Tuesday November 25 2003, @02:43PM
      • walk dont run by Yorkshire (Score:1) Tuesday November 25 2003, @06:46PM
  • I don't understand why he's so critical of a free product. I upgraded to 2.60 and it's running near flawless, and since the program is so simple, you just upgrade it, no need to change configuration options if you don't need to, you just call it from procmail.

    Yeah all those GUI options look nice, but 90% of the time, why do I need to change my spamblocking settings? The Bayesian filter autoadjusts itself with little or no user intervention -- it's near transparent.

  • Works for me (Score:5, Informative)

    by perlionex (703104) <joseph&ganfamily,com> on Tuesday November 25 2003, @09:01AM (#7557382)
    (http://www.ganfamily.com/)
    I run a mail server at home on a Linux box, with Postfix and Spamassassin 2.60. I have it configured to label mail as spam once it hits 8 points, and to automatically chuck it into /dev/null once it hits 12 (using Postfix's header_checks).

    It works pretty well for me -- the mail server's only for my personal use so I don't really have to worry about irate subscribers sueing me for dropping them legit mail =p and the 8-12 point range in the spam marking gives me a chance to vet through those suspicious mails briefly before deleting them.

    I've never tried any other spam filters on the server-side, so I can't really compare. I guess I'm also a bit of a Linux hacker so I don't mind tweaking all those config files along the lines of the FAQ and other hints on forums to get it to work the way I want it to.
  • by Newt-dog (528340) <newt-dog@phantomcow . c om> on Tuesday November 25 2003, @09:03AM (#7557394)
    (http://www.lds-chat.com/)
    I use Eudora and I *tried* to set up a complex system of "filter words". I even it up so that all of the spam would go into a "spam filter" folder. Lotta good that did me . . . Now all of my spam goes directly into my In box, and the good email goes into the spam folder.

    Come to think of it, it seems to work out just fine.

    Newt-dog

  • Sales sales sales (Score:3, Insightful)

    by Anonymous Coward on Tuesday November 25 2003, @09:03AM (#7557398)
    This is likely funded by un-named virus vendors who has integrated SapmAssassin into their appliaces. Away on a vacation, I came back to find our people unaware SpamAssassin was open source. The vendor quietly forgot to mention that.

    In the end, any company is going to have to put people and tools together to get a spam solutution, or outsource it. But DIY needs people time.

    Don't pay vendors for SpamAssassin, it runs quite nicely on left over PCs reloaded with Linux.
    • 1 reply beneath your current threshold.
  • by damian (2473) on Tuesday November 25 2003, @09:04AM (#7557408)
    (http://krass.com/)
    He sent a long open letter to SAtalk. You can find it in the mailing list archive [sourceforge.net]

  • no wonder... (Score:5, Insightful)

    by theonlyholle (720311) on Tuesday November 25 2003, @09:05AM (#7557419)
    (http://www.only4christ.de/)
    well, on the first page the author already makes it pretty obvious why SpamAssassin had to come out at the bottom of the list. He is comparing version 2.44, which was included in RH9 and is thus at least 8 months old, to the latest antispam software that is regularly updated. How on earth is that an unbiased comparison? In a world where spam patters change every week, if not every day, 8 months is a generation... he even says so in his article. I'd be interested to see the results of a similar test, but with SpamAssassin 2.60 and of course with bayesian filtering and some of the other optional features enabled...
  • Because (Score:5, Interesting)

    by FreeLinux (555387) on Tuesday November 25 2003, @09:05AM (#7557425)
    Why did he not ask Kevin Railsback who had the whole thing working some while ago?)"

    He expected to get the results that he normally gets with most commercial software. Click Setup.exe, answer a question or two and it's done, up and running. Further configuration is not required though it may be desired.

    The commercial vendors of Spamassassin have not improved the core product in any way. What they have improved is the packaging, the installation, the default configuration and the interface to modify that configuration. The stock SpamAssassin does not offer that although, Spamassassin setup is far more simple than some other packages out there.
  • Taken from the two articles (Score:5, Interesting)

    by lpontiac (173839) on Tuesday November 25 2003, @09:07AM (#7557443)
    Kevin Railsback is Test Center operations manager at InfoWorld.

    versus

    IT consultant Logan Harbaugh is the author of two books on networking.

    The first found Spamassassin easy, the second found it hard. Hmmm.

    What really aggravates me is the typical "There are blacklists available that you can subscribe to, and some are updated regularly, but these are noncommercial lists with no guarantees." I'd like to see what guarantees the commercial lists come with.

  • Critical Eye on Tech Journalists (Score:5, Informative)

    by abulafia (7826) on Tuesday November 25 2003, @09:09AM (#7557458)
    In true form for throwaway articles like this, products are compared poorly:

    Each product was tested with a different stream of mail, so the number of messages received varied, but all received enough messages to assess their capabilities.

    Can you imagine someone writing "Oracle, Sybase and Postgres were compared. While the data and workloads were different, all products performed enough work to assess thier capabilities."

    All the products except Brightmail and SpamAssassin allow end-users to add senders to the domain whitelist themselves.

    I don't know anything about Brightmail. Spamassassin end user whitelists entries can be set up in a number of ways.

    And all the products but SpamAssassin use dynamic updates to keep up with the evolving technologies spammers use to circumvent less sophisticated filters.

    As aluded to in the summary, this is false with modern versions of Spamassassin, which uses Baysian filtering. (The author later says he couldn't get it working.

    However, it took more than 10 times as long to install and configure SpamAssassin as it did any of the other products. [...] But just because the software is installed does not mean it will work -- filtering criteria must be added manually, and until that's done nothing is filtered out. Getting the various configuration files edited properly so that the whole package worked was not simple. Documentation was difficult to find, and not always easy to follow.

    While it is true that one must be comfortable with a text editor to configure Spamassassin, thus perhaps putting it out of reach of point-and-click admins and technical journalists, I also wouldn't be prone to put my mail servers in the hands of either of those groups of people.

    It looks for keywords in the subject or body of e-mails, but is frustrated by words not in the dictionary, such as "V!agra," or words that contain invisible HTML characters.

    While I am not sure what tests appeared in which version, I'm pretty sure 2.44 handled off-by-one works such as V!agra. I have no idea what he's talking about when he says "invisible HTML characters", but it does seem to point to a certain technical incompetence, similar to the ostritch belief - "If I can't see you, then you can't see me."

    This is not to say Spamassassin is the easiest thing in the world to deal with. I happen to love it, because of the extreme flexibility.

    I just get sick of tech journos who decide that because a tool doesn't have a gui and they don't want to take the time to configure it, it sucks.

    • Re:Critical Eye on Tech Journalists (Score:5, Insightful)

      by dboyles (65512) on Tuesday November 25 2003, @09:28AM (#7557630)
      (http://sandbox.etree.org/)
      Can you imagine someone writing "Oracle, Sybase and Postgres were compared. While the data and workloads were different, all products performed enough work to assess thier capabilities."

      A very large sample of mail would negate almost all of the differences caused by using a different set of mail, but I get the feeling that each of these servers ran for about a day and the results were gleaned from that.

      I don't know anything about Brightmail. Spamassassin end user whitelists entries can be set up in a number of ways.

      ...and it ain't that hard.

      As aluded to in the summary, this is false with modern versions of Spamassassin, which uses Baysian filtering. (The author later says he couldn't get it working.)

      Maybe I'm missing something or taking things that I consider basic for granted, but Bayesian filtering with SA is about as straightforward as it gets, except that instead of clicking a few buttons, you run one short command.

      While it is true that one must be comfortable with a text editor to configure Spamassassin, thus perhaps putting it out of reach of point-and-click admins and technical journalists, I also wouldn't be prone to put my mail servers in the hands of either of those groups of people.

      I think we've all known these types, and unfortunately they're more widespread than we'd like to think. Many simple solutions such as SA are ruled out because the admin doesn't have the skill to implement them. Note to any managers reading this: hire people with a solid background in the field, not those who list single-platform applications on their resume as "skills." Software changes, but a good administrator has the ability to adapt.
      [ Parent ]
    • Re:Critical Eye on Tech Journalists by ceejayoz (Score:3) Tuesday November 25 2003, @09:46AM
    • Re:Critical Eye on Tech Journalists by JuggleGeek (Score:1) Wednesday November 26 2003, @05:41AM
    • 2 replies beneath your current threshold.
  • sixty-two percent? (Score:5, Interesting)

    by dboyles (65512) on Tuesday November 25 2003, @09:11AM (#7557477)
    (http://sandbox.etree.org/)
    [SpamAssassin] filtered only 62 percent of spam, whereas the other products produced great results, blocking 90 percent to 96 percent of all the spam they encountered with few, if any, legitimate messages blocked.

    To me, this statement is pretty telling. Harbaugh must get some completely different kinds of spam than me, because, even though I receive about 60 spam mails a day (directed to my "spam" folder, so I never see them until I scan the "From:" field and then delete them), maybe one per week makes it through the filter. And seeing as how I can't even remember the last time I got a false positive, that's a pretty damn good number.

    I can believe that if you receive a variety of mail and if you took no time to configure SpamAssassin other than cranking it up, maybe then it'll only catch 80% of the spam. But 62%? I'm not sure if Harbaugh is skewing the benchmarks or if he just doesn't know what he's doing.

    There are some legitimate issues with SpamAssassin that might not make it ready for the enterprise, but for a handful of users, I have been more than satisfied. And the price is right.
  • You think 2.44 is ancient? (Score:5, Informative)

    by ryanvm (247662) on Tuesday November 25 2003, @09:12AM (#7557490)
    You think 2.44 is ancient? Feh - Debian 'stable' is still stuck with 2.20.
  • Article lenght advertisement (Score:3, Insightful)

    by ericspinder (146776) on Tuesday November 25 2003, @09:15AM (#7557505)
    (Last Journal: Sunday January 08 2006, @04:07PM)
    In my testing, the performance of the newer products was more than acceptable in every case. Per-user, per-year pricing should not be an obstacle, even for the most expensive product.

    Sounds to me like Infoworld has an advertising contract with (at least) one of these companies. At the very least he should have checked the site for an update before he started his "tests". For a while there, I got every one of those "IT industry" hype mags (always free). While there was some good information here and there, you had to wade through a lot of advertising pretending to be articles.

    I love SpamAssassin and would not consider email hosting without it. It has made my email account useable again ! For the record, it seems to catch about 80-90% of my spam, and I have never seen a 'false positive' (I do check my 'spam' folder, but less and less)

  • Spamassassin by rk_nh (Score:1) Tuesday November 25 2003, @09:16AM
  • it's a matter of proper configuiration! by dummkopf (Score:2) Tuesday November 25 2003, @09:17AM
  • -1, Troll (Score:5, Funny)

    by Tom (822) on Tuesday November 25 2003, @09:18AM (#7557536)
    (http://web.lemuria.org/)
    Can we moderate the article at -1 Troll, please?

    It's just a bit too obvious that he was hoping for a severe slashdotting, driving his own numbers ("look, editor, how many people read my articles!") and the ad numbers of his paper up.

    Probably submitted the story himself, too. :)
    • Re:-1, Troll by Tin Foil Hat (Score:1) Tuesday November 25 2003, @12:50PM
  • by greppling (601175) on Tuesday November 25 2003, @09:18AM (#7557540)
    I am sure he was as disappointed as me that the installation didn't follow the ./configure && make && make install standard procedure, and that it defaulted to /usr instead of /usr/local as installation directory.

    Seriously:

    • The Spamassassin installation documentation could be better written IMHO.
    • Why doesn't RedHat's update service offer constand updates to the current version of SpamAssassin?
    • Why doesn't it (as mentioned in another post) have the most important configuratoin setups included in their overall configuration GUI?
    I really wish distributions would support SA better.
  • If he wants to pay by rf0 (Score:2) Tuesday November 25 2003, @09:19AM
  • Rule #1: user intelligence >= tool by Pointy_Hair (Score:2) Tuesday November 25 2003, @09:20AM
  • It's all about the UI (Score:4, Insightful)

    by The Subliminal Kid (647767) on Tuesday November 25 2003, @09:22AM (#7557577)

    The bias apparent in this article and the crappy comparison chart aside this review doesn't even begin to touch base as a throughly researched opinion ion piece and ends up look like an advert for Brightmail.

    However we do in the OS community face a UI problem. The missing rung on the ladder to mass acceptance is the absence of high quality UI that give users and indeed administrators of the point and drool variety a interface with the service they are seeking to use.

    Before the Highly polished phpmyadmin I met serious resistance from admins for MySQL over msSQL based mostly on interface. The same goes for CUPS which has a web interface that I think has come of age if not achieve adult hood. The Webmin's are OK as long as you don't tinker to much or do anything slightly non-standard. I dislike Swat and am now so used to editing smb.conf I haven't even checked it;s working. I think that a lot of these services, apache, Spamassassin and X11 for example, could bare providing embedded configuration UI's if they aim to capture wider markets. Mandrakes X11 confugulator is very good.

    I was going to mention the difficulty presented for admins with widely deployed Outlook when looking at these kind of solutions but then I though no only have sympathy where it is due. An I know that SpamAssassin could work seamlessly with Outlook but if users want a front end for white-listing then SpamAssassin isn't going to be your toy just yet.

    Though we love the text based config file you may have to put a lot of working into configuration UI's if you want to enter the area as far as that reviewer and many sysadmins are concerned.

  • Not Really (Score:4, Insightful)

    by tookish (126829) <tookeesh@nOSpaM.yahoo.com> on Tuesday November 25 2003, @09:27AM (#7557620)
    (http://www.tookish.org/)
    So his complaints are:
    1. SpamAssassin is hard to install
    2. it isn't very effective
    3. nothing is filtered until you manually set up your own filters
    4. it's hard to configure and poorly documented
    5. non-commercial blacklists come with no guarantees
    6. end users can't add to the whitelist
    7. Bayesian filtering isn't included by default, and he couldn't make it work anyway
    8. it doesn't catch words like Viagra and invisible HTML characters

    I knew nothing about filtering spam until I installed SpamAssassin 2.6 in a multi-user environment last week. Here are my responses:

    1. it took less than half an hour to install (from CPAN) and start
    2. effectiveness out of the box was about 95%, with no false positives -- after a few minor tweaks, I'm at about 98% with no false positives
    3. simply not true -- it runs right out of the box
    4. maybe it's hard to configure if you're used to a GUI -- if you're not afraid of editing a text file, it's very easy to set up; and there's no shortage of documentation at spamassassin.org [spamassassin.org] and elsewhere
    5. do commercial blacklists come with guarantees? I don't know
    6. with a very little bit of scripting, you could allow users to add to the whitelist
    7. I haven't tried the Bayesian filtering because it's apparently not well suited to a multi-user environment
    8. simply not true -- it flags this stuff out of the box

    I wouldn't recommend that my grandmother install SpamAssassin, but if you have any admin skills whatsoever, it's quite easy to use it to set up effective and useful filters. Furthermore, there are enough factual errors in the article that I'm tempted to dismiss it outright.

    Of course, it's possible that it got a lot better between 2.44 and 2.6, but that begs the question, why did he install 2.44?

    • Re:Not Really by daves (Score:2) Tuesday November 25 2003, @10:45AM
    • Re:Not Really by kalidasa (Score:2) Tuesday November 25 2003, @10:46AM
    • Re:Not Really by Mr Slushy (Score:1) Tuesday November 25 2003, @01:12PM
  • Paid opinions are worth what they cost by heironymouscoward (Score:2) Tuesday November 25 2003, @09:27AM
  • install took 10 times as long...? (Score:5, Insightful)

    by lone_marauder (642787) on Tuesday November 25 2003, @09:29AM (#7557639)
    I can install Spamassassin and six other applications via CPAN in the time it takes to get the syntax right for one license key.

    I also like the characterization of Spamassassin as "first generation" without any supporting evidence to the fact. First generation was adding spam senders to your e-mail client's blocklist. Bayesian filtering is well beyond first generation, but spammers have learned to defeat Bayesian filtering with poison data in non-eyeball space and text obfuscation. The next generation in spam detection is to detect the Bayesian evasion features - and guess what does that!? Spamassassin (2.60).
    • 1 reply beneath your current threshold.
  • SA+MailScanner works for me (Score:5, Informative)

    by cyways (225137) on Tuesday November 25 2003, @09:30AM (#7557652)

    I've found the easiest way to implement SpamAssassin is to invoke it through MailScanner [mailscanner.info]. MailScanner uses third-party virus scanners and can optionally invoke SpamAssassin as well. With the free ClamAV [elektrapro.com] antivirus product, you can build a powerful open source mail scanner. Even without a virus scanner, MailScanner detects and quarantines executable attachments and other dangerous content which represent the most common types of mail-borne viruses and worms.

    RedHat installs the daemonized version of SA as well as the SA Perl scripts. Using the daemon, the easiest implementation is to invoke SA in /etc/procmailrc on the mail delivery host; for mail gateways running sendmail, you need to use the milter interface. I've found the MailScanner+SpamAssassin approach much easier to configure than either of these methods, and you get virus scanning to boot!

    I suspect if the reviewer had compared SA 2.60+ to the commercial products, rather than the older 2.44 version used in the review, SA would have shown better results.

    I'd agree with the reviewer that one of the things SA lacks is an easy method for users to interact directly with the program. (Part of the issue has to do with security; SA runs as root. As I read the review, I wondered how the other products allow users to interact directly with the scanners without sacrificing security.) It's not easy to maintain per-user Bayesian filtering, for instance, but I generally recommend having the mail client, e.g., Mozilla [mozilla.org], handle these tasks.

    • 1 reply beneath your current threshold.
  • Thanks for the reminder!! (Score:3, Interesting)

    by Perl-Pusher (555592) on Tuesday November 25 2003, @09:31AM (#7557656)
    I was using version 2.44, I was able to compile and upgrade spamassassin before the number of posted replies hit 60! Can't be too hard!
  • Old, and on the list (Score:3, Informative)

    by satyap (670137) on Tuesday November 25 2003, @09:36AM (#7557701)
    Not only is this somewhat old news, it's been discussed on the spamassassin mailing list. Apparently, the article was edited so that it's more anti-spamassassin than the reviewer intended, but Mr. Harbaugh also defends his review of an older version of spamassassin as "it came with my Redhat 9" (NOT a direct a quote). He also claims it took nearly an hour to install and set up. (I counter that it took seconds to install and minutes to set up).

    The current version of spamassassin is 2.60.
  • Try the Custom Rule Emporium! (Score:4, Informative)

    by sillypixie (696077) on Tuesday November 25 2003, @09:37AM (#7557714)
    (Last Journal: Wednesday October 10, @03:59PM)
    I have SA 2.6 running as a plugin to the SunONE Messaging Server (v5.2), in BAREBONES mode (ie no RBL, no Bayesian, nothing but perl regex) and it filtered 591 spam from my bosses mailbox alone on the first weekend. 12 or 13 managed to sneak through.

    Since then, I've downloaded a bunch of rules from The SA Custom Rule Emporium [merchantsoverseas.com] and almost nothing gets through.

    If this guy had trouble, it is the fault of the documentation, not the product. Either that, or he was dumb enough not to upgrade to perl 5.8 or above, and spent forever installing modules.

    He says:
    SpamAssassin is the perfect example of first-generation techniques becoming outmoded by advances in spamming technology

    Funny how when you install an old version of the product, it seems outmoded, hmmm?

    Sheesh.

    Pixie
  • qmail + spamassasin by pkplex (Score:1) Tuesday November 25 2003, @09:40AM
  • Man could he be more wrong.... by i_want_you_to_throw_ (Score:2) Tuesday November 25 2003, @09:40AM
  • He was trying to make a point (Score:4, Interesting)

    by Zebra_X (13249) on Tuesday November 25 2003, @09:41AM (#7557756)
    While his review was perhaps not scientifically conducted. I think there was a point to be made with the SpamAssasin blurb.

    Notice that he deliberately took a standard install from RedHat 9, something some IT person (Not a tr00 g33k) might buy at CompUSA. He then tried to install the provided product. Clearly, a tr00 g33k would go and download the latest release, but keep in mind that not everyone is so comfortable with being on the bleeding edge - I believe that this was a point he tried to make. There is also the perception that the release provided with a "product" such as RedHat 9 will be up to the same standards as the OS.

    While it's true the latest version has default rules and whatnot - it's quite likely that his older, more out of date version does not. In fact, going briefly to the spamassin home page the links for the 2.5 and 2.4 release documentation are broken.

    The point to be made was: OSS needs to be more buttoned up. Notice that he said that he had no trouble installing redhat 9. That's becuase the installer is rather good.
  • Commercial Guarantees, eh? (Score:5, Insightful)

    by TheSpoom (715771) * on Tuesday November 25 2003, @09:41AM (#7557758)
    (http://www.uberm00.net/ | Last Journal: Monday January 19 2004, @09:27PM)
    Here's a nice example of a commercial guarantee. See if you can determine where it's from:

    11. LIMITED WARRANTY FOR PRODUCT ACQUIRED IN THE US AND CANADA.

    Microsoft warrants that the Product will perform substantially in accordance with the accompanying materials for a period of ninety days from the date of receipt.

    ...

    YOUR EXCLUSIVE REMEDY. Microsoft's and its suppliers' entire liability and your exclusive remedy shall be, at Microsoft's option from time to time exercised subject to applicable law, (a) return of the price paid (if any) for the Product, or (b) repair or replacement of the uct, that does not meet this Limited Warranty and that is returned to Microsoft with a copy of your receipt.


    Note that a) no updates or fixes are guaranteed, b) your only remedy is media replacement or a refund, and c) this choice of remedy is up to Microsoft.

    I love it when people claim that you're taking a huge risk with open source software without guarantees. Microsoft says their software will work, but isn't saying that if their software doesn't work, they have to fix it.
  • Who's your BOFH? by mvpll (Score:1) Tuesday November 25 2003, @09:41AM
  • Did anyone notice... by waferhead (Score:1) Tuesday November 25 2003, @09:44AM
  • Light weight alternative by Malc (Score:2) Tuesday November 25 2003, @09:47AM
  • if I can install spamassassin... by HighBit (Score:1) Tuesday November 25 2003, @09:49AM
  • modifying subjects and other content (Score:3, Interesting)

    by dan_bethe (134253) <`gro.alokcums' `ta' `todhsals'> on Tuesday November 25 2003, @10:03AM (#7557995)
    TrollAssasin would be nice, imagine seeing posts subjects as *****TROLL***** heh

    I know you're just joking, but to be serious for a minute, the reason not to do that is because you'd be transparently altering someone else's copyrighted property. Overzealous and/or overworked sysadmins misconfigure SA to globally analyze all incoming content and then to alter email subjects based on its opinion. This is an invasion of content, certainly prone to false positives because antispam scanning is an individually trained process, and breaks the trail of reply threads at least on a visual basis. There are always going to be tons of misconfigured or RFC ignorant smtp servers out there, and being compatible with them is what makes the Internet work. That would include corporate servers, legitimate opt-in bulk mail, and opt-in mailing lists run by Some Dude. There will be people on a mailing list whose personal content is always publicly marked by certain recipients as spam! It's confusing, insulting, and unnecessary. SMTP has invisible meta-tags in its headers to allow for that, and agents are supposed to respect them.

    This is fine for using SA's global config as your personal config for your own little systems, but not for an ISP or business.

    According to spamassassin.org:

    We strongly urge ISPs installing the product to notify their users when it's installed, and to not enable it by default -- but many seem to ignore this advice. We agree, that's totally unprofessional. :(
  • The algorithm by Mr_Silver (Score:1) Tuesday November 25 2003, @10:05AM
  • Arsehole by FinestLittleSpace (Score:2) Tuesday November 25 2003, @10:06AM
  • SpamAssassin+PostFix vs Exchange+Comm'l Product by texspeed (Score:2) Tuesday November 25 2003, @10:10AM
  • tech vs. consultant, humorous by motorsabbath (Score:2) Tuesday November 25 2003, @10:12AM
  • I got SpamAssasin running in 15 minutes! by MrJerryNormandinSir (Score:2) Tuesday November 25 2003, @10:18AM
  • 10x as long.. does he type with a straw.. by Bruha (Score:2) Tuesday November 25 2003, @10:27AM
  • Personalized Bayesian training (Score:3, Informative)

    by gvc (167165) on Tuesday November 25 2003, @10:33AM (#7558289)
    The Bayes filter in SA 2.6 works very well but unfortunately is not well-suited to site-wide learning.

    -- casual readers may skip the following details

    In an attempt to mitigate this, SA makes an unfortunate mistake in its unsupervised learning algorithm - it uses a different set of rules for training than it uses for marking mail as spam or not. So you can easily have email marked as spam but have the system trained as non-spam (or vice versa). This introduces systematic bias into the learning so that spam detection can get worse in the long run. As a further attempt to mitigate this problem, the learner uses a higher spam threshold, so many spams that are correctly marked do not contribute to the learning process. There is no way to set the SA configuration parameters to eliminate these biases (setting the learn threshold does *not* do it).

    --- end of gory details

    It is not too difficult to set up SA for personalized learning. Just pipe your mail to the following command:

    spamassassin -e

    If the return code is 0 (non-spam) also pipe the mail to

    sa-learn --ham --single

    If the return code is 1 (spam) pipe to

    sa-learn --spam --single

    If you do this you are guaranteed that the statistics recorded in your personal bayes db correspond exactly to the judgements made by SA.

    In addition to this you must correct SA when it makes a mistake, by piping the message to sa-learn again with the right flag. You may be able to set up a macro in your mail reader to do this.

    This isn't as easy to set up as it should be, but it is *very* effective.

    In the last year I've received 20,000 non-spam and over 100,000 spam messages & viruses (30,000 if you eliminated the "Cumulative Update" messages, which SA caught just fine.) About 100 spams have gotten through (a couple a week) and about 10 false positives have occurred. All of the false positives have been 'weird' - advertising, automatic responses, or web pages that were forwarded to me. As far as I know (and I do check periodically) I've had no false positives in the last 50,000 spams.

    My preliminary analysis indicates that personalized learning reduces both false negatives and false positives by a factor of ten. I'll report more systematic analysis in due course.
  • what is it with those guys? (Score:3, Insightful)

    by jqh1 (212455) on Tuesday November 25 2003, @10:42AM (#7558367)
    (http://www.spamgourmet.com/)
    Larry Seltzer did a similar job with a review of disposable email address services in
    PC Magazine [pcmag.com].

    Spamgourmet [spamgourmet.com] (open source and free to use) was lined up against several commercial offerings, and was rated the lowest. It was clear from the review that he didn't spend much time learning about how spamgourmet works -- he wound up faulting it for perceived problems that were addressed by features that he ignored in the review.

    Not to be cynical, but if I were a tech reviewer, I might be afraid of lawsuits resulting from my reviews -- open source projects have no revenue, and therefore can't prove up any damages in court. This might make me more likely to choose the open source alternative to get the shaft. Hopefully that's not what's going on here, but you've got to wonder...

  • Easy Spamassassin for Windows by tedhiltonhead (Score:1) Tuesday November 25 2003, @10:45AM
  • SpamAssassin for WinBlows users... by ChrisKnight (Score:2) Tuesday November 25 2003, @11:18AM
  • Article from July 18, 2003 by NoSuchGuy (Score:1) Tuesday November 25 2003, @11:21AM
  • Took me 10 minutes by EmagGeek (Score:1) Tuesday November 25 2003, @11:23AM
  • Just got this from the article author by bruns (Score:2) Tuesday November 25 2003, @11:44AM
  • 2.44 is Almost recent... by EnglishTim (Score:2) Tuesday November 25 2003, @11:50AM
  • took me 1 day... by martin (Score:2) Tuesday November 25 2003, @12:05PM
  • What makes SpamAssassin cool! by Muerte2 (Score:1) Tuesday November 25 2003, @12:17PM
  • MailScanner on Fedora Core 1 by Anonymous Coward (Score:1) Tuesday November 25 2003, @12:19PM
  • Goatse? by iantri (Score:2) Tuesday November 25 2003, @12:28PM
  • How to learn on a relatively steep learning curve. by donsaklad (Score:1) Tuesday November 25 2003, @12:32PM
  • No Bayesian filtering?... by LnxAddct (Score:1) Tuesday November 25 2003, @12:45PM
  • Spamassassin and other tools. by hoyhoy (Score:2) Tuesday November 25 2003, @12:48PM
  • latest spam by SCHecklerX (Score:2) Tuesday November 25 2003, @12:48PM
  • SpamAssassin on Steroids by papason (Score:1) Tuesday November 25 2003, @12:57PM
  • Technical expertise of the media is a factor. by merc (Score:2) Tuesday November 25 2003, @01:41PM
  • My letter to the author (Score:5, Insightful)

    by macdaddy (38372) on Tuesday November 25 2003, @01:53PM (#7560517)
    (http://slashdot.org/ | Last Journal: Monday January 31 2005, @05:48PM)
    This guy's article was a joke. Not only did he use an ancient version (in the spam world) of SpamAssassin but he either flat out lied in his article or was too lazy to seek out the truth. Hard to configure? Can't find docs? Doesn't support A B C D or E? If this guy had spent 5 minutes of his precious time doing to research on SA he wouldn't have made these flagrant lies. I don't get these people. I really don't. I CCd the Editor-in-Chief at InfoWorld, Mr. Steve Fox, as well.

    Mr. Harbaugh,

    This letter is in response to your InfoWorld article titled "Commercial solutions win, spam loses." In that article you portray all commercial spam solutions as winners and you portray the only open-source spam solution you reviewed as a dismal failure. I must say that as a professional in the anti-spam field I'm am truly disappointed by your incomplete and inaccurate assessment.

    You start the article off quite well. Your introduction regarding two of the possible types of spam filtering is in terms that the average reader can understand. The introduction is also technically accurate, although it doesn't mention the other ways to filter spam.

    You quickly take an opportunity to kick dirt on SpamAssassin by claiming it filters a fraction of the amount of spam all the commercial solutions filter. You hint at something during that statement when you said that SpamAssassin's "age showed in my tests," yet you fail to actually make it apparent to the user what the real truth is. I must ask, why did you choose to compare such an ancient version of SpamAssassin to the current versions of the four commercial products? Version 2.44 is over 9 months old. Spam filtering techniques are constantly evolving to filter a continually changing target. Comparing a 9.5 month old copy of SpamAssassin to the current version of BrightMail is like comparing a 1990 Chevy Silverado to a brand-new 2004 model. As an author and professional in the IT industry writing a column for InfoWorld, one of your goals is accuracy and fairness in reporting, is it not?

    You make numerous false statements regarding SpamAssassin in your article:

    1) "All the products except Brightmail and SpamAssassin allow end-users to add senders to the domain whitelist themselves... SpamAssassin allows only the administrator to add to the whitelist, with no direct access for users."

    This is simply not true. SpamAssassin allows its users to add whitelist or blacklist entries to the personal preferences. It also allows its users to control the scoring for each individual ruleset with SpamAssassin's arsenal. Even the ancient version of SpamAssassin you chose to use had that simple feature. SpamAssassin also has the ability to automatically whitelist senders.

    2) "Delegation of specific administrative functions is possible with all the products except SpamAssassin..."

    This too is not true. As I said in response to number 1, SpamAssassin allows its users to control the scoring for each individual ruleset. This gives them the ability to disable certain rules, lessen the scores of others, and increase the scores of rules they wish had more weight. For example a user could disable the MAPS RBL DNS blacklist checks, whitelist joe@mydomain.tld, blacklist annoying-spammer@spamdomain.biz, and increase the score of the rule ALL_CAP_PORN to 2. The users can also create their own rulesets. SpamAssassin gives its users a high level of control over their spam filtering.

    3) "Finally, in addition to stopping spam, all four commercial products provide content-filtering features, allowing the administrator to block incoming or outgoing e-mail that contains proprietary data, audio or video files, executables, sexually explicit words, or racial slurs. They also provide protection against DoS attacks and directory harvesting attacks."

    This one baffled me at first. I'm honestly not sure why you want to compare features that have nothing to do with filtering spam. Filtering racial slurs from an email is
  • Ten times as long to install ? by oPless (Score:2) Tuesday November 25 2003, @02:32PM
  • 90 to 96% WTF? by HermanZA (Score:1) Tuesday November 25 2003, @02:40PM
  • Well here's what I sent to the author by matth (Score:2) Tuesday November 25 2003, @04:38PM
  • Huh? by haraldm (Score:1) Tuesday November 25 2003, @04:55PM
  • SpamAssassin is teh win. by Trejkaz (Score:1) Tuesday November 25 2003, @05:30PM
  • POP and IMAP by hao2lian (Score:1) Tuesday November 25 2003, @06:25PM
  • Spam Assassin == Overrated by looie (Score:2) Tuesday November 25 2003, @07:15PM
  • Hmmm by BOD-G_Anubis (Score:1) Tuesday November 25 2003, @07:17PM
  • Spam Assassin is not that simple to install.. by mcdade (Score:2) Tuesday November 25 2003, @09:57PM
  • ORFilter by PSL (Score:1) Tuesday November 25 2003, @10:28PM
  • Try it here... by the_fineline (Score:1) Wednesday November 26 2003, @01:37AM
  • Unfair Comparison by IceFreak2000 (Score:1) Wednesday November 26 2003, @04:30AM
  • Re:Photo of Author by NormalVisual (Score:2) Tuesday November 25 2003, @09:46AM
  • spamassassin-2.44-11.8.x.i386.rpm (Score:4, Insightful)

    by poszi (698272) on Tuesday November 25 2003, @10:17AM (#7558128)
    2.54, not 2.44

    To moderators. When you mod something "informative", please check the facts first. Spamassasin in RH 9 is 2.44.

    [ Parent ]
  • Re:Instructions for people who use a REAL Linux by hattmoward (Score:1) Tuesday November 25 2003, @10:23AM
  • 20 replies beneath your current threshold.
(1) | 2