Delivered-To: gmkarl@gmail.com Received: by 2002:a05:7022:23a9:b0:6b:e8d0:f7e2 with SMTP id bz41csp1346492dlb; Sun, 17 Sep 2023 07:44:04 -0700 (PDT) X-Received: by 2002:a25:d70b:0:b0:d7b:ac56:493b with SMTP id o11-20020a25d70b000000b00d7bac56493bmr6382705ybg.7.1694961844028; Sun, 17 Sep 2023 07:44:04 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1694961844; cv=none; d=google.com; s=arc-20160816; b=FHjLPj5frZLA0apza5s60HJ5z6BBHpmxufiF07tD1p3ddHvLqlWthTbf9boztZVsZe KfFQE9/SaNfknO8q0Mp+a/MEXzBJ5lBLDUrzgePCoavuk9meGBDqLM7t/8Lz1PSmYf0P VoszR1ul0UGz8SDKA8iGadwB5xQ1zEinXUTNysXNLSkpmKmIV2EBChcCKe09JDV8zL+M IKy9Mp7zT2gg7sp/Pe7tQrRLyUA5jsgoRU/9wOUFQ0zTE+OuUbZh/wW2/E33w3HV9LUg lX6anxoZd23jBNLusEV0SFkt4qr/sCuC0qXM/GmxWUARqZGzr3bCZLEP9UPdE3sDt1MH xGxA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=GBGkHO+HoeatW8JMVTtqMcixxae/0ppN8wq7hDZb4Sk=; fh=uplQ6BchJlFXdCsRITGfjprsvpwKzCui9iBYcAaKsY0=; b=OkugW1ZQzYBE5cxLXt7eaI9wATaT63v8O6C9b5g7maCa5OssE7Msy6uQz5Pi5ngH4s +7yXO4k/+vAz+FrOYgxbMZbRYGa9QXkI159y7w8Bt8VqTAJoeS+1ihF0DelF9LBtVfwf wnioUEoExTBSnL64XyZGXSwZUjuSAxGt8kAy4KfAdHCJrDGOll5nkIZTQcHZwzn1inNu yM4xcLR//vaFEQGCBHRK8lSf/nXgB+ffOLm1RUppu8J72rIo52BQQroSDmnR1mL/LWRv zv4N6taBcA/ML9bY+Qj8m0FsQtdqRVuxZ2SNcK3sGh7oqeVgNBu/xA+PUklo+WWhUYms wlTw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@petascale-org.20230601.gappssmtp.com header.s=20230601 header.b=GM8DitOz; spf=neutral (google.com: 209.85.220.41 is neither permitted nor denied by best guess record for domain of gbnewby@petascale.org) smtp.mailfrom=gbnewby@petascale.org Return-Path: Received: from mail-sor-f41.google.com (mail-sor-f41.google.com. [209.85.220.41]) by mx.google.com with SMTPS id l21-20020a25b315000000b00d7f1bb3d662sor1262000ybj.2.2023.09.17.07.44.03 for (Google Transport Security); Sun, 17 Sep 2023 07:44:03 -0700 (PDT) Received-SPF: neutral (google.com: 209.85.220.41 is neither permitted nor denied by best guess record for domain of gbnewby@petascale.org) client-ip=209.85.220.41; Authentication-Results: mx.google.com; dkim=pass header.i=@petascale-org.20230601.gappssmtp.com header.s=20230601 header.b=GM8DitOz; spf=neutral (google.com: 209.85.220.41 is neither permitted nor denied by best guess record for domain of gbnewby@petascale.org) smtp.mailfrom=gbnewby@petascale.org DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=petascale-org.20230601.gappssmtp.com; s=20230601; t=1694961843; x=1695566643; dara=google.com; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=GBGkHO+HoeatW8JMVTtqMcixxae/0ppN8wq7hDZb4Sk=; b=GM8DitOzAZ+tCx+rwtF0byf2YNsdeznTzgliP6JHse59LFAl6u85uvOPYDs7adZhFO rThYbA0JppOs+TtRa7aryJ81hrXL+qMgM+E4KiCKFR17fQBsjHYIp5RYa1gaNDpCW6Fo MddZ5p0nYbf0uN4e3cMdXRd5Rv3rzYmaaIuVE0cjhPD/hOMKJ2Nh45eYftz3Qhs4CF+P ElCuXJREOSEBi/UTsIEkOo0AwRUTZTm0aIbOR/7YZntRObHfZZcvCa9TXN9iIaTrSoMc mfUoVNr2YAzAfg2g+fhxuFp6GJlzxL3tLXmQYeck9pXacpwca3bmDaBpF1+nj4f8xNHX unzQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1694961843; x=1695566643; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=GBGkHO+HoeatW8JMVTtqMcixxae/0ppN8wq7hDZb4Sk=; b=orZuFUqJLdEDAbGQ/NRweyRyamT1wgVGb0Euf+R8ABrBBc9c5vomLd7xQatI8zAJPh EgTb698vj6nrxvx/N593fRYVZh7g7c9q/qsGLCa4AZhegud/HEdUcrIp+cFiKigKUhVH svfPNrTKd25xnf5qc8MB47Ui6XtTd5D8/PqH22DHachVINWEPBrsZZNHn2hyjMpyH9S7 UZYULGGNyYHBpc6KUXXMK9AMkSuxadXm2YvPBTKXK6Xf6HAXK+bKK+UNfhKjexzNKk5P 0oUdcNV9K6l1fRqMEqhyjNyZkspx34xl4C6skn0ci6GNRlvs0Q6VeYlqET4EAvfCLnBh ur2A== X-Gm-Message-State: AOJu0YyGcvUxUueteyre0I1ZcmhrPIbxn+e4iH+DaDg6694TqyYorTXH tTa92SR+wW/Df/IB1pJ+5Sn5e1ezFnP6A8dNy2kPWg== X-Google-Smtp-Source: AGHT+IE7scZENnWMqEVqoQWVqLRMJIFS8Yt8N70k+/7b3yA2ZfVjN1A890Gixs1PJBcgmx5qWmkRtx1GJwcbTu8Mgz4= X-Received: by 2002:a25:aa2a:0:b0:d81:62fe:9488 with SMTP id s39-20020a25aa2a000000b00d8162fe9488mr4291464ybi.5.1694961842824; Sun, 17 Sep 2023 07:44:02 -0700 (PDT) MIME-Version: 1.0 References: In-Reply-To: From: Greg Newby Date: Sun, 17 Sep 2023 07:43:51 -0700 Message-ID: Subject: Re: Your messages to cypherpunks To: mailbombbin Cc: Karl Semich , Greg Newby Content-Type: multipart/alternative; boundary="0000000000008cec7f06058f0eb2" --0000000000008cec7f06058f0eb2 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Hi Karl. Thanks for your note. There are indeed two problems. I spent several hours yesterday going through logs and making a few adjustments to the settings on the server, so I think I have a reasonable understanding of the situation. For the messages that YOU send, there is definitely a problem. There are thousands of bounces still in the queue from cypherpunks subscribers where the email system they use, like gmail or yahoo, started rejecting message from you saying that too many messages have been sent. This is rate limiting by the email services. It's not just gmail and yahoo that do this. The end result is that your messages are not delivered immediately to subscribers. Sometimes they bounce permanently (i.e., will never be delivered) and other times it's a temporary issue until, after a quiet period of at least a few hours, the messages are accepted again. Here is the first part of an example log message that lists around 100 gmail users: D34D811C0238 11973 Sat Sep 16 21:07:34 cypherpunks-bounces@lists.cpunks.org (host alt1.gmail-smtp-in.l.google.com[209.85.202.27] said: 421-4.7.28 [69.55.231.143 15] Our system has detected an unusual rate of 421-4.7.28 unsolicited mail originating from your IP address. To protect our 421-4.7.28 users from spam, mail sent from your IP address has been temporarily 421-4.7.28 rate limited. Please visit 421-4.7.28 https://support.google.com/mail/?p=3DUnsolicitedRateLimitError to 421 4.7.2= 8 review our Bulk Email Senders Guidelines. n18-20020a5d4012000000b003200b1e9219si887019wrp.921 - gsmtp (in reply to end of DATA command)) Unfortunately this doesn't just impact messages from you. Any message from the server to those services is held or bounced. Because cypherpunks isn't the only service on my server, this means that some of the other activities are impacted. This includes one of my key volunteers for Project Gutenberg who utilizes a yahoo.com email address -- my messages to him were rejected, even though he has nothing to do with cypherpunks and it was even from a different hostname (lists.pglaf.org not lists.cpunks.org, but they are both hosted on the same system). I hope this longish explanation explains why the frequency of your messages creates a big problem for the cypherpunks list, why many subscribers will never see your messages, and why it creates indigestion for other stuff the server needs to do. The second problem is that someone has targeted you for the unsubscription mail bombs. I spent awhile trying to mitigate this, and the only immediate solution would be to remove you from the cypherpunks subscriber list and let you subscribe from another address. Luckily those messages seem to have stopped for now. Yesterday, for perhaps 12 hours, around one password reset per second was being sent. This resulted in a backlog of over 30000 (!) messages that were clogging up my server, but could not be delivered to you because of gmail rate limiting. So, you would have gotten a whole lot more of those messages if I hadn't deleted them all. The attack was distributed. Each request came from a different IP address - I counted over 200,000 of these. I'm not sure how many you got before I deleted 30,000 and it seems the attack stopped early in the evening Saturday night (maybe by 6pm PDT). If it hasn't stopped entirely, it is definitely a lot less frequent now. I could take a closer look at the logfiles if it might be helpful. If the attack was from a single IP address or group of IP addresses I could block them easily enough. But they came from a different address every time= . Clearly someone got on the dark web and hired a botnet army to send all of these password reset requests against you. So, that is also a problem because it also caused gmail (your mail service) to start rejecting messages to anyone. I'm going to be outside for the next 8-10 hours, and will see any messages from you when I return. Thanks for your understanding about this. As I tried to say below, I'm not trying to censor your messages. But the frequency of messages should decrease to avoid the first type of problem above, and this can be done by you sending fewer longer messages rather than many short messages. Best regards, Greg On Sun, Sep 17, 2023 at 7:24=E2=80=AFAM mailbombbin = wrote: > Greg thank you for messaging me about this. > > So you know, I have been receiving high-frequency mailbombs sent via > the list, in the form of password recovery requests and removal > requests. I have tens of thousands of these filtered on this address, > and they delay the delivery and receipt of mails for me. They come > reliably, many per hour. > > Is it possible this is the source of the clog on the list, rather than > my sporadic posts? > --0000000000008cec7f06058f0eb2 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Hi Karl. Thanks for your note.

There are indeed two problems. I spent several hours yesterday going thr= ough logs and making a few adjustments to the settings on the server, so I = think I have a reasonable understanding of the situation.

For the messages that YOU send, there is definitely a problem. Ther= e are thousands of bounces still in the queue from cypherpunks subscribers = where the email system they use, like gmail or yahoo, started rejecting mes= sage from you saying that too many messages have been sent.

<= /div>
This is rate limiting by the email services. It's not just gm= ail and yahoo that do this.

The end result is that= your messages are not delivered immediately to subscribers. Sometimes they= bounce permanently (i.e., will never be delivered) and other times it'= s a temporary issue until, after a quiet period of at least a few hours, th= e messages are accepted again.

Here is the first p= art of an example log message that lists around 100 gmail users:
= D34D811C0238 =C2=A0 11973 Sat Sep 16 21:07:34 =C2=A0cypherpunks-bounces@lists.cpunks.org(host alt1.gmail-smtp-= in.l.google.com[209.85.202.27] said: 421-4.7.28 [69.55.231.143 =C2=A0 = =C2=A0 =C2=A015] Our system has detected an unusual rate of 421-4.7.28 unso= licited mail originating from your IP address. To protect our 421-4.7.28 us= ers from spam, mail sent from your IP address has been temporarily 421-4.7.= 28 rate limited. Please visit 421-4.7.28 =C2=A0https://support.google.com/m= ail/?p=3DUnsolicitedRateLimitError to 421 4.7.28 review our Bulk Email = Senders Guidelines. n18-20020a5d4012000000b003200b1e9219si887019wrp.921 - g= smtp (in reply to end of DATA command))

Unfortunat= ely this doesn't just impact messages from you. Any message from the se= rver to those services is held or bounced.

Because= cypherpunks isn't the only service on my server, this means that some = of the other activities are impacted. This includes one of my key volunteer= s for Project Gutenberg who utilizes a yahoo.c= om email address -- my messages to him were rejected, even though he ha= s nothing to do with cypherpunks and it was even from a different hostname = (lists.pglaf.org not lists.cpunks.org, but they are both hosted on the = same system).


I hope this longish e= xplanation explains why the frequency of your messages creates a big proble= m for the cypherpunks list, why many subscribers will never see your messag= es, and why it creates indigestion for other stuff the server needs to do.<= /div>


The second problem is that someone = has targeted you for the unsubscription mail bombs. I spent awhile trying t= o mitigate this, and the only immediate solution would be to remove you fro= m the cypherpunks subscriber list and let you subscribe from another addres= s.

Luckily those messages seem to have stoppe= d for now. Yesterday, for perhaps 12 hours, around one password reset per s= econd was being sent. This resulted in a backlog of over 30000 (!) messages= that were clogging up my server, but could not be delivered to you because= of gmail rate limiting. So, you would have gotten a whole lot more of thos= e messages if I hadn't deleted them all.

The a= ttack was distributed. Each request came from a different IP address - I co= unted over 200,000 of these. I'm not sure how many you got before I del= eted 30,000 and it seems the attack stopped early in the evening Saturday n= ight (maybe by 6pm PDT). If it hasn't stopped entirely, it is definitel= y a lot less frequent now. I could take a closer look at the logfiles if it= might be helpful.

If the attack was from a si= ngle IP address or group of IP addresses I could block them easily enough. = But they came from a different address every time.

Clearly someone got on the dark web and hired a botnet army to send all of= these password reset requests against you.

So, th= at is also a problem because it also caused gmail (your mail service) to st= art rejecting messages to anyone.


<= div>I'm going to be outside for the next 8-10 hours, and will see any m= essages from you when I return. Thanks for your understanding about this. A= s I tried to say below, I'm not trying to censor your messages. But the= frequency of messages should decrease to avoid the first type of problem a= bove, and this can be done by you sending fewer longer messages rather than= many short messages.

Best regards,
=C2= =A0 Greg
=C2=A0

On Sun, Sep 17, 2023 at 7:24=E2=80=AFAM = mailbombbin <mailbombbin@gmail.= com> wrote:
Greg thank you for messaging me about this.

So you know, I have been receiving high-frequency mailbombs sent via
the list, in the form of password recovery requests and removal
requests. I have tens of thousands of these filtered on this address,
and they delay the delivery and receipt of mails for me. They come
reliably, many per hour.

Is it possible this is the source of the clog on the list, rather than
my sporadic posts?
--0000000000008cec7f06058f0eb2--