Security people shouldn?t pay the "spam support system" for email lists to send SPAM
Yes this is a pet peeve of mine. I am not going to out the various security companies that do this but when I get SPAM from a “security company” I often report them to their ISP for AUP violation and attempt to educate the SPAMMER who sent the SPAM.
I recently replied to one of the many such SPAMs I received.
They were advertising a Security & Risk Management Summit taking place in Washington, DC.
I asked how they got my email address and was told they buy their lists from various sources. I explained that by buying those lists they were feeding the spam support system. They didn’t respond to that comment so either they already knew and don’t care or felt it was justifiable.
I recommended that they ONLY use doubly opted-in lists. (Ones that you opt-in to and get an verification email sent to you to ensure someone else didn’t opt you in).
They did provide an opt-out option and when confronted stated that they were can-spam compliant. If you’re a security company and you send me SPAM expect me to respond and request termination of your service for AUP violation!
Comments
Every time I attend a conference, I get SPAM from SANS (who buys the attendee list). I kindly ask them to opt-out and go on my way. No Big Deal.
I track "where" my email got loose by changing the title I use when I register. So when I receive an unsolicited marketing email from SANS and they use a title I used at RSA(for example) I know where they purchased my name.
Marketing messages are what brings customers to organizations. If a vendor (SANS) wants to try and build their revenue, they will do this. If they don't - they risk imploding revenue (no new markets).
The real question is do they make it easy, AND if you opt-out - when they purchase a new list are they scrubbing your email from it based on your first opt-out? If they do that, I'm generally happy. When they don't, I get cranky.
Grab a cup of coffee and relax. Only provide your "work" email at conferences and the like if absolutely necessary. Make use of burn accounts when you can and give people (and ISPs) a break.
-Mark
Mark
May 25th 2010
1 decade ago
Nathan
May 25th 2010
1 decade ago
Pachy
May 25th 2010
1 decade ago
Steve
May 26th 2010
1 decade ago