Spam is getting horrible lately. I get all sorts of new techniques including:
- using legitimate sites to bypass filters, like sending you a bill through a legitimate bill-creation site
- pretending to be a tracking service for something you supposedly ordered, then over the course of days pretending the package got lost on the way and offering a discount code for the 'purchased' amount, expecting you to use it on their phising site.
Gmail not only fails at spam classification, they classify these messages as important and nag you with first priority notifications and summaries.
I can’t prove it, but it feels like the world recently decided that spamming/scamming is acceptable, so the number of spammers/scammers has increased dramatically.
The number of spam calls, texts, emails, iCloud account unlock requests, etc I’ve received in the last year is insane.
I believe that these spammers now concentrate their efforts towards e-mail addresses hosted by major providers, like Gmail.
The reason is that I have an opposite experience, during the last couple of years I have received much less spam messages than before.
I have hosted my own e-mail server for more than 2 decades. Previously, I had to filter large quantities of spam messages, but lately the number of spam messages is much less than 10% of the total number of received messages.
I use fastmail, I love it. I have a catchall and thus can use a different address per service. Leads to sometimes awkward conversations as to why the email address contains the company name in it, but can also be a life saver. For instance, free recently got hacked and all their email db was online. I can just block this email address and not receive the spam.
Fastmail itself is reliable and fast on the web, but I only use it through IMAP anyways. It works perfectly.
Lack of accountability for the companies that allow their services & platforms to be used for spam/scamming.
Take DocuSign for instance. Still, this many years later, is a major source of phishing emails from their free trials. DocuSign could easily shut this down today by either requiring a CC for the trial, or forcing a call with a sales rep to start a trial. But they don't, they continue to allow their service to be used for wide scale phishing.
Atera, an RMM, is another one that has been a big source of malware delivery, also via the free trials.
Shutting down the trial accounts after the fact does nothing, the emails already went out.
I feel like there's no way for them to win, though. The kind of accountability you're talking about what require them to do essentially tons of KYC/AML vetting, and HN would be equally outraged about that.
It's a little hard to get outraged about that hypothetical, given that legitimate usage of DocuSign typically involves sending them documents containing all sorts of sensitive information.
Every single day since around the start of the year I get at least 1 text with the content of roughly: "FROM TRUMP: You could be the next winner of this PRIZE/MONEY!", "Click here to receive your $10,000 tariff refund!", "DEMOCRATS are trying to DESTROY EVERYTHING!". Plus I get almost daily calls that immediately hang up, and leave a 30 second voicemail with no audio.
I've always had some level of political spam, usually only close to voting months, but this year has been the worst for me.
In addition, it feels like the past 5 years have brought on more marketing spam. I've been slowly reappearing onto marketing lists that I either never signed up for or unsubscribed from. They're coming from legitimate companies that I've done business with.
It's AI that's doing a lot of it. For a lot of spam, scammers would want to exclude anyone who may not fall for the scam due to the costs associated with dealing with people who won't pay you. Now that AI decreases the need for a human scammer to scam, expect them to start to widen their scam nets.
Yeah this feels like one of those cases where the term "AI" gets broadened out so far it becomes meaningless.
This stuff is automated. The ability to automate spam calls (using the same form of APIs developers love, like Twilio) make it absurdly easy for one person to set up a spam machine. No AI required.
The lead generation was automated ten years ago ("Hello?"), but the actual scam conversation was not. Until recently, you still had to pay somebody in South Asia better than the prevailing wage of ~$1/hr to have these conversations, as well as set them up in an office with computers and managers, and bribe local police (call it $5/hr of fully burdened work product). If your success rate is ~1% and the average human portion of the scam lasts 12 minutes, you're getting 0.05 successes per hour, and you better be netting an average of $100 per successful scam (accounting for financial clearing issues / reversals!) or you're losing money on every hour worked.
You're correct about the calls, but the ability to talk with the people was the rate limiter. Even if you have many people in Cambodia or India, the scammers still needed to scam more than they paid out. Now you can have AI bots that do the first level of filtering.
Unfortunately scamming is a business and if certain actions become less expensive, I would expect more of them.
I think part of it is AI allowing sophistication at scale, but there's also a generational factor. The techbro + business shark culture, influencers who manipulate people being role models, and so on.
Oh no - you can definitely 100% prove it, this is the direct consequence, the exact intended consequences, of Trump gutting consumer protections - across the board, not only online but with food and laws about not dumping chemicals in rivers.
The man is the absolute worse person - unless your a rich guy, who wants to make more money by screwing over people who mostly don't even know it.
Anyone who reads this, I dare you to find out why that thing in your life you hate so much, sucks so bad - nothing is ever by accident or unintentional.
The United States, and its People, will be discovering/realizing different ways we have been absolutely f-d by that grifter for likely the rest of my millenial life, thankfully (silver lining!!) US life expectancy has dropped substantially for the 150 million Americans in the bottom 50% of income - rich people in America have to deal with this bs for almost 8 more years than we do
Oh yeah, if you want a faster out even yet - just make 30k or less per year, your life caps at 71 then.
I joke but I hate so much that people will read this and then promptly go back to sustaining this system at their job.
We work our lives away so the rich dont have to and they get to live 14 more years on average than poor people.
Oh, I was just really upset having found out that the IRS is going to settle Trumps 10 billion lawsuit against the IRS, for releasing his tax returns but showed he payed 0 dollars in taxes - AND, the terms of the settlement are that the IRS cannot investigate his family or any of their businesses in the future.
That is the most corrupt thing a Leader in a western country has ever done in the modern world.
While you're correct that this is a trend that has been going on for a while, the keyword is trend. Do you understand what a trend is? It's a direction. Meaning, under Trump, it has gotten worse, and that is directly related to the piss-poor policy choices of this administration.
I won't mince words here. People who think policy is completely detached from outcomes are dim, and should spend less time talking because it wastes everyone's brain space.
If I put on my tinfoil hat, it seems to be something deliberate, to push us all towards accepting hardware / software attestation and better "online id" stuff - "Don't you want to identify and stop the spammers and phishers?".
Email scanning and file scanning (on our computer) became acceptable when the level of spam and malware became intolerable. But it was at cost of our privacy. Today, Gmail scans all your mails and makes money from it. Both Windows and macOS have built-in anti-virus or malware scanners, and file indexers, and thus know all the applications and files in your system (which provides for more data on your profile with them). Now with both OSes, and even browsers like Chrome and Firefox, including AI, they will now use our own computers to not only collect our personal data, but even process it on our system and use it to build even better profiles to more profitably exploit us.
It doesn't have to be deliberate; it's just the economic incentives at work. AI providers are inclined to sell AI to everyone with a pulse, and it just so happens that a lot of its use will for towards spam generation.
It also just happens that they're the ones best positioned to provide attestation and identity services.
Gmail spam filtering is so bad that I believe it has to be intentional. I think they see email as a long term ad revenue opportunity and want to desensitize people to the spam.
I wonder how come I have such a diametrically different experience. I don't remember the last time any spam email got through the automatic filter into my inbox, and I had a gmail account for 20 years now.
> pretending to be a tracking service for something you supposedly ordered
There’s a leak or someone is selling the data in a lot of the delivery companies in my country. I order something then without fail the fake text message pretending to be the delivery service. Only thing they screw up is claiming it’s failed to deliver too soon and the weird urls.
Messed up these companies are either selling it or being irresponsible with data.
Seems to be involved with government services too. I signed up for a welfare program that had me input all my data before denying me the service a few months ago, and the next day I started receiving spam calls and texts using some unique pieces of information that I had submitted in that form.
Called my state senators to complain about it and ask for assistance. Enjoyed the complete lack of follow through.
I'm not seeing any of this, and I've have been using the same email address that forwards to gmail for decades at this point, and it's in every major email data breach.
I get, maybe, one actual spam email per year through gmail's spam filters.
I get more actual spam at my work email, which is not hosted by gmail, even though the email volume of emails sent from outside of my employer's network is orders of magnitude smaller than my personal email volume.
> like sending you a bill through a legitimate bill-creation site
Why aren't these things opt-in? Ditto for every other thing that sends you email. I reflexively mark anything I didn't sign up for as spam on principle.
Google is fine with everything if it's their service. I've completely blocked *.bc.googleusercontent.com, because it's basically used as a spam farm for years now, but Google couldn't care less as they apparently can't be bothered to even slightly inconvenience their compute engine users.
That doesn't really change the fact that it's hard. Do you know how many full movies are on YouTube that infringe on copyright? How many pirated streams are hosted on S3? How many piracy sites are behind Cloudflare. It's just very hard to police at scale and if something is flying below the radar it will be there for a while. They probably spread out their assets over many accounts, or even use misconfigured buckets with write permissions to drop some files in there.
Google's inability to scale their services should be a regulatory issue.
If their platforms (Gmail, YouTube, DoubleClick) are being used to launch scams, they're failing at scale and governments are failing at legislating / regulating.
The only way to use Google services somewhat safely is with hefty ad (and the rest) blocking.
All this ID and surveillance and privacy invasion and metadata retention and yet all these scams only seen to grow. It never seems to end up protecting anyone deserving of protection.
Trust and safety doesn’t have the same maturity as cyber security. Things like trend and signal sharing between tech firms doesn’t exist, except through informal slack channels and WhatsApp groups.
The first major safety conferences for trust and safety came together only in 2023.
This argument actually doesn’t work in Google/your-point favor since finding pirated content on Google is now practically impossible.
The reality is, Google is driven strictly by incentives and there are no consequences for letting spam/scams run wild vs. pirated content which gets automatically removed when a DMCA notice is received.
There is 100% pirated content on Youtube - not too much from Hollywood and you won't find anime on it - but if you watch foreign language media, there is very often the Official account and then like 4-5 others just blatantly providing the identical content, which is promoted alongside the legitmate content, so its fairly easy to start watching legit stream and find yourself not watching legitimatly a few episodes later, playlists are huge to prevent that.
The problem with this is the piecemeal enforcement all but proves they only care about stuff they get a cut of and that fact became more clear to me recently when I was watching a random drama made in Asia that I wont name due it being one of the best historical and educational shows I've ever watched - but there was a scene (this was made in the 90s btw) that was entirely innocent, not sexualized - it was done humorously, but I'm not a pdf file either so - anyways, there were fully naked children, with absolutely no censorship, on Youtube - 100% long enough to be noticed by their trackers - they obviously just are not reviewing certain content, at all.
I don't care about piracy at all - I'd still use Youtube if it was the primary source for pirated content, the idea that there may be some obscure content, that seems totally fine, in a language nobody really uses - except for Epstein types, if ever that was discovered - that Youtube had become a haven for pdf files bc of lax application of standards - I would want Youtube split away from Alphabet and force sold on the cheap to a more responsible owner (like Tiktok minus the responsible owner part) - plus an enormous fine.
I didn't believe that such content could exist at all on the platform - until I literally saw with my eyes that it obviously can.
"It's so easy when you don't know how". I'm not sure if this phrase is in common use at all, or if I just misheard it once and attributed it to mean that when the details of a problem aren't obvious, its easy to conclude the solution is simple. "Why don't they just do ___?"
At the companies I've worked at, I refer to this as the "well, can't you just...?"
Yeah, I can "just" after I "just" do A, and B, and C, and D, and E, and F, and G.
Drives me batty on top of being insulting. "Surely you realize I thought about that weeks ago, and if it were that simple, we wouldn't be having this conversation."
It's probably possible to catch a lot more of them, but why look too hard when you can hide behind section 230 immunity and pocket ginormous profits instead of spending on this lol...
Ah! I have no answer for it, but am happy, Virgil-like, to now have a theory why the same stupid, obvious "Costco" spam from an @gmail.com address keeps showing up in my inbox no matter how many I mark as spam.
I am guessing that service returns the XML file as a directory listing; the file called winbridge.html does exist in that directory (and contains a JavaScript code to redirect to a different URL). (Another comment said they shortened the URL to remove PII (which I am guessing was in the fragment part of the original URL; the JavaScript code makes a new URL from randomly selecting a domain name (even though the list has only one) and appending the fragment part as the path), so I suppose the file name was removed and then this directory listing is the result.)
They seem unable to prevent phishers from using their acquisition, AppSheet, to send relatively convincing, targeted (to nobodies like me) emails that make it to primary inbox.
So, pleas ignored, forward these recruitment scam emails to the legal/fraud/phishing teams of the impersonated brands. For a company without the appearance of caring (in my opinion), perhaps law firm letterhead can encourage necessary prioritization.
The USPS doesn't even have to get involved. Just make it so that recipients can be compensated easily enough with high enough fines and the spam stops immediately.
You seem to be suggesting that you're going to successfully fine a postal spam sender for using a paid service offered by the USPS to do the thing that service was designed to do. If the "law was working correctly", that service would stop existing, rather than existing and then incurring fines when used.
There are some limited mechanisms for opting out of targeted mail (e.g. things that have your name on them), and mechanisms for opting out of credit offers in particular. There are not any mechanisms for opting out of "current resident" spam sent to everyone in an area.
This is an underrated distinction. Sadly, the line is so much more blurred now than even when I was a kid in the 90s.
There are so many businesses now which exist mainly to cheat you, operating at the very edge of what’s technically legal, and relying on their customers not really understanding the full terms of the deals they’re agreeing to. It’s sickening.
- Seniors are sold various quackish financial products like annuities which are a terrible deal for them.
- Timeshares, which nearly never work out in the favor of the consumer (and whose value collapses 50-80% instantly if you look at what they go for on the resale market)
- Prepaid card products that cost a bunch of money to load and then incur monthly fees too (exploiting those who have for whatever reason got blacklisted from banking)
- Every financial product that has a 25%+ interest rate, actually, which isn't limited to those with bad credit. Even if you have an 899 credit score, if you walk into Nordstrom and get their credit card, you will have a close to 30% rate on that. This whole business model is obviously built on tricking people into spending money they don't have and carrying a balance.
- Salesmen hawking solar panels that come to my front door and promise me all kinds of savings. Note: Probably only half these are scams! Just have to figure out which half.
- Health insurers, pretty much across the board. They do things like declare the most dominant ambulance service in San Francisco, the SFFD, "out of network", so the SFFD then sends you a bill for $1000 if you had to use an ambulance. The neat lifehack by the insurer is that most people will just curse, cry, maybe go into debt, and pay it. Only like 10-20% of patients will file a complaint with the insurer's state regulator, and those can just be quickly paid. Result: Savings of 80-90% for health insurance company! (If this one sounds oddly specific, you can guess why.)
Every payday loan company, the "we buy houses for cash" companies, rent-to-own companies, title loan companies, the entire buy-now-pay-later ecosystem, the timeshare industry.
Seriously dotancohen, get your people under control.
Yeah, but junk mail funds the USPS, without it Republicans would've killed the postal service long ago, See the Pension requirement that they pushed in a vain attempt.
More info here: https://news.ycombinator.com/item?id=46665414