That's the beauty of bayesian filters - you don't declare anything in
particular as a spam indicator, you just tell the filter "that's spam"
when it is wrong. If you filter enough such emails as spam, and assuming
you don't get non-spam html comments, eventually <!-- and --!> will be
considered strong indicators to spam, and that's it, they're filtered.
That the learning in the filter.

Of course, then the spammers learn to stop using comments, and start
using tiny pictures as separators, and so forth - the arms race will
never end. But at least now intelligent users can mechanize their battle
to read just mail, and spammers will have to think about new schemes.
Hopefully, this will send most spammers looking for easier
get-rich-quick schemes, that make less noise for us.... (unfortunately,
what I think will happen is that they'll mechanize the invention of
workarounds, so things won't be quite that rosy).

Daniel

Nadav Har'El <[EMAIL PROTECTED]> wrote:
> On Fri, Jan 24, 2003, Tzafrir Cohen wrote about "Re: spam mail filter":
> > I have also noticed quite a few spams recently that were made to pass such
> > filters:
> > Every suspicious keyword was cut in the middle (som of them: a number of
> > times) by html comments.
> > Something like:
> > 
> >   MA<!--  sdfsdf -->KE MO<!-- sfsad -->NEY FA<!-- aweyj-->ST
> 
> The simple workaround: declare every HTML mail as spam :)
> 
> Or, even if you're not an anti-html-mail-activist, all these HTML comments
> should tell you something is fishy. Normal HTML mail should not have
> comments in it (or have very few, usually mentioning Microsoft)...
> 
> -- 
> Nadav Har'El                        |      Friday, Jan 24 2003, 21 Shevat 5763
> [EMAIL PROTECTED]             |-----------------------------------------
> Phone: +972-53-245868, ICQ 13349191 |If you tell the truth, you don't have to
> http://nadav.harel.org.il           |remember anything.

=================================================================
To unsubscribe, send mail to [EMAIL PROTECTED] with
the word "unsubscribe" in the message body, e.g., run the command
echo unsubscribe | mail [EMAIL PROTECTED]

Reply via email to