this post was submitted on 28 Jun 2025
4 points (83.3% liked)

Information Security

330 readers
1 users here now

founded 2 years ago
MODERATORS
 

Some obnoxious piece of shit scumbag has been non-stop attacking Debian testers with a flood of spam the past several days.

Why attack a harmless charity? Why not target a shitty expoitive platform like MS Github instead? It’s choosing to target an organisation that just helps people. It would be like entering a public library and taking a shit on the carpet, when you could have just as well taken a shit on the hood of Elon Musk’s car hood instead, for example.

This is not just a rant. I want a serious answer. I have a vague notion of why spam exists. It’s not just malice without purpose. Cyber criminals build botnets to effectively create powerful supercomputers for very little money by hijacking their victim’s CPU cycles and the energy that drives them. Then they sell supercomputing access on the black market, or they mine cryptocurrency. Those criminal botnets need to be controlled surreptitiously.

Spam somehow facilitates the command and control of the botnets. Supposedly… though I struggle to understand why. When spam is sent to some arbitrary recipient, how does that serve as a command signal? Is it perhaps a mechanism that only serves the botnet if the spam recipient happens to be unwittingly part of the botnet? Thus everyone who is not on the botnet who receives spam, it’s just a waste for everyone?

Surely there are more clever ways to anonymously control a botnet without shitting on the world with spam. Surely the rage spam causes motivates intelligence agencies to shut them down, no?

1990s botnets were clumbsy. The greed was unhinged so they would steal as many CPU cycles from each PC as possible. When someone’s PC is so sluggish it’s intolerably dysfunctional, it was a big red flag. The victim reinstalled Windows to overcome and thus shrinks the botnet, which increases the botnet owner’s burden of having to reinfect more PCs. So they got more clever.. they only steal enough processing to go unnoticed. I’m not seeing how spam fits into modern day clever crimes.

spoiler


no comments (yet)
sorted by: hot top controversial new old
there doesn't seem to be anything here