back
157 comments
Great idea! Wasting spammers time is one of the very few ways of making them effectively lose money. Still the project needs some pseudo randomization in order to fool basic research. Some of the messages I read contained the sentence "I am a bit busy now, but I am definitely interested. When can we talk?". If one searches for that sentence in quotes Google returns four pages of references to Spamnesty. A slightly more clever spammer would sense the trap in minutes. I'm not aware of any program capable of add some entropy to a sentence maintaining its semantics and readability (save for insertion of random errors), but one could use a translator in different languages. Say English->German->Russian->Spanish->Polish->Danish->English, then send the resulting string as a reply. The above string for example becomes: "Now I'm a bit busy, but I'm definitely interested. When can we speak?" which (almost) fools the search. Almost because the 1st page still contains a couple references to Spamnesty due to the above sentences strong similarity, but they're well buried together with other completely unrelated stuff.

BTW, pairing this with a personal assistant stripped of any access to personal information/property/devices (such as an hypothetical open source cloudless one) and instructed to ask for details on every possible part of the offer, one could make the perfect weapon against phone telemarketers as well.

> A slightly more clever spammer would sense the trap in minutes.

Spammers are going to develop anti-spam filters :)

there is no end to that argument, if a spammer is good enough to be able to foresee anti-spam software then they are likely beyond the target audience. BUT the average and by large general spam crew are not technical experts, most of them have bought some software to advertise to a large audience by mass email / crawl / filter, and are just looking at monetizing some product (or get your infos / CCs). By wasting time for the 95% of the spammers (ironically with techniques that are very similar to them) you can still weed out a big chunk of that sector and have a big impact.
For now they should simply "noindex" the message history. But your larger point is correct.
You could probably build a Tracery grammar that conveyed a certain set of semantic information with a large number of possible syntactic permutations.
Well done. It does get the spammers frustrated. I remember reading about a similar thing[1] where instead of emails it was automated telephone replies and the scammers were cussing at the bots and generally super confused.

It did also manage to flood their phone lines making their call center useless for a while.

[1] https://motherboard.vice.com/en_us/article/bj8wg4/we-talked-...

Some magnificent genius has created the perfect bot for hooking predatory telemarketers. "Lenny" is a slightly confused elderly man with poor hearing. He wanders off topic, he isn't sure what you just said and he is absolute catnip for crooks. If you haven't heard a call to Lenny, you're in for an absolute treat. This call from a tech support scammer lasts an exhausting 31 minutes:

https://www.youtube.com/watch?v=UJTxkPLVxrc

https://www.reddit.com/r/itslenny/

A technique described in this podcast[1] may lock up quite some time with these people.

[1]http://pca.st/yWw5

OP here. Just to clarify, because I see a lot of congratulations. I just shared the project, I'm not the author.

Based on the GitLab project, the author seems to be @stavros:

- https://gitlab.com/stavros/Spamnesty

- https://twitter.com/stavros

- https://www.stavros.io/

Yep, that's me!
I just tried to forward a lot of spam messages, and got the response:

554 Recipients' domain disabled

Reporting-MTA: dns; googlemail.com Received-From-MTA: dns; ----------@gmail.com Arrival-Date: Sat, 30 Dec 2017 20:49:25 -0800 (PST) X-Original-Message-ID: <02D8BE6D-6DEF-4FC9-9AC5-6BC6E7A44EAE@gmail.com>

Final-Recipient: rfc822; sp@mnesty.com Action: failed Status: 5.0.0 Remote-MTA: dns; mxb.mailgun.org. (54.69.170.70, the server for the domain mnesty.com.) Diagnostic-Code: smtp; 554 Recipients' domain disabled Last-Attempt-Date: Sat, 30 Dec 2017 20:49:27 -0800 (PST)

That's a cute idea. But I wonder if the system is mis-matching messages and replies.[1] How did a spam for fake Ray-Ban sunglasses turn into someone wanting app development?

[1] https://spa.mnesty.com/conversations/cturvzsr/

From glancing over some conversations, it looks like the bot is mostly talking to other bots.

That said, I think it’s nice to be able to reflect the same attack vector upon the attackers to make the attack less efficient and hopefully less attractive.

Tried forwarding three emails, got this:

Message not delivered There was a problem delivering your message to sp@mnesty.com. See the technical details below, or try resending in a few minutes.

The response was: 554 Recipients' domain disabled

As someone else mentioned here, the only risk is that spammers will blacklist mnesty.com .

There should be some type of domain rotation (or you can test spoofing, just to see if spammers use the same anti-spoof software everyone else does), just like how spammers do so.

As an aside, kudos for using gitlab instead of github.

I once made something very similar, back then it was called an autobaiter by the scambaiting community. It would actually figure out what kind of scam the spammer was pulling and adjust its script in kind to pretend to play along with the scammers script.

I should dig that up again.

So it would be hilarious if you connected the spam asking for manuscripts[1] to the fake manuscript generating code [2]. We would end up with bot published journals.

[1] https://spa.mnesty.com/conversations/cjubnfdx/

[2] https://pdos.csail.mit.edu/archive/scigen/

I have been using this site for about a month on every piece of spam that tells me to write back. But, I have not gotten any responses. How are they even making money if they don't respond to clearly interested potential customers?
Hmm. Tried it and the email bounced back with:

“554 Recipients' domain disabled”

I love the use of the subdomain and email sp@mnesty.com to hide the name from spammers. But won't human spammers eventually figure out what mnesty.com is and stop responding?
I look forward to sending many emails your way!

Spam is a daily problem for me. I can't use auto-filters, because I live in Taiwan and most emails written in Chinese are flagged as spam. That includes important messages from my bank, colleagues, and landlord. Eventually I gave up using auto-filters, and I now manually delete ~50 spam every day.

Being able to do something useful with that will make my spam-sorting a little less mind-numbing.

This is the email version of when Telemarketers call me and ask to "speak with someone in the house between the ages for x-y" to which I say, "sure just a sec", then put the phone down on the desk and walk away.
I saw www.rescam.org on here a while ago, definitely worth a visit!
Gamifying this kind of thing would be intriguing. I'm imagining some server that would work like spamnesty, i.e. you could easily let it handle your spam. But I'm also imagining the possibility of registering as a bot creator and plugging in your own algorithms. API-wise it would be super simple, much like creating a chatbot for Slack, but the logic could be as advanced as one would like. The server would then score the algorithms on established metrics such as "average number of responses" or what one might dream up. There would be leaderboards and stuff.

It would all work nicely until the spammers start creating their own bots to keep our bots busy. Bots would keep inane conversations going forever.

Then, I presume, Skynet.

Forwarding from gmail to sp@mnesty.com results in

    554 Recipients' domain disabled
<sp@mnesty.com>: host mxb.mailgun.org[54.210.206.63] said: 554 Recipients' domain disabled (in reply to end of DATA command)
What we really need is something like this for the phone scammers, particularly the "IRS" scam I've been getting regulars calls from most of this year.
Hm, I'm getting:

<sp@mnesty.com>: host mxb.mailgun.org[54.186.217.87] said: 554 Recipients' domain disabled (in reply to end of DATA command)

I guess they were a bit too successful - I'm getting "554 Recipients' domain disabled' when forwarding msgs to them.
Honestly, why don't we get insider / whistleblower posts here on HN ? I understand spamming is quite vilified among most techies, but someone is doing the spamming. Is it because the bulk of spamming is done using very unsophisticated ways ? We get anonymous posts on pretty much all other topics.
It looks like in many cases [1] it's confusing the threads? Subjects and discussions start changing after a few messages in many threads I looked at.

[1] https://spa.mnesty.com/conversations/vkeezpyz/

Just read through this one https://spa.mnesty.com/conversations/ecfrqrps/ – and was laughing stitches. Great job!
> Spamnesty is a way to waste spammers' time. If you get a spam email, simply forward it to [email protected]

Maybe it would be more appropriate to show email there, since it's intended for spammers as well.

I tried this when it was new, and saw two issues with it. Firstly, it uses western names as the responder, which may not be the best case everywhere — ideally the person submitting the email should be able to specify a name to use. Secondly, the mnesty name and Mnesty LLC wouldn't seem believable to many (human) spammers either, depending on the region. I didn't get responses for many emails I submitted — my guess is that the spammers thought it's a waste of time (which is also good, but not frustrating them enough).
Ha, my comment from earlier today [1] reposted as a top of front page post.

It's like when you say something funny in a group setting which only one person hears, and instead of asking you to repeat it for everyone, they repeat it loudly themselves like it was thier joke! :)

Edit: Heaven forbid that you should point out that HN is sometimes just like Reddit! Downvote away, I have no interest in MIPs†.

[1] https://news.ycombinator.com/item?id=16035487

†Meaningless Internet Points

I have the feeling that all of this is going to finish bot against bot.
I guess they were a bit overwhelmed - I'm getting "554 Recipients' domain disabled " when forwarding to them.
Reading some of these emails it's apparent it's not a person responding. This is simply two bots email each other.

https://spa.mnesty.com/conversations/aatajahd/

Looks like for some spammers, the game is already up.

This remembers me of rescam.org
This could easily be one of the “smallest” things to have the greatest impact. Looking forward to reading statistics on how much this software takes in % of total spam time and saved money.
I read some of the conversations on the site; it’s quite interesting that the boys managed to have the same conversation over and over almost in the exact order.
This is really cool. I tried building a similar project last year using an LSTM, but never ended up deploying it.

I wonder what James Veitch would have to say.

Let's just hope the scammers don't start using AI/NLP to generate the emails they send to us....
Add support for SMS and it’ll be perfect.
Interesting, but is there something for spam callers? It's not enough to block them or report them.
With all the emails ending with "CEO, MNesty, LLC" I doubt you'll be able to fool anyone