January 28, 2004

Virus hell

Like most people, I lost count of the number of virus-infected emails I got yesterday. (See this Microsoft page for more information on the virus.)

Adding insult to injury in all of this was the number of well-intentioned auto-replies I got from other mail gateways, saying that the email I had sent to one of their users was infected. Typical was this one:

A message containing a virus was sent from your e-mail address. It is very likely this machine (or any other you use for e-mail) is infected!
CHECK IT AS SOON AS POSSIBLE WITH AN ANTIVIRUS PROGRAM!

At one time, this was indeed how viruses were often transmitted. A user would inadvertently pick up the virus, and then might email the infected file to another user.

But those days are pretty much gone. Now, viruses forge the 'From' address all the time. I didn't send a single virus-infected email out yesterday, but lots of infected PCs sent out dozens or hundreds of emails claiming to be from various mohea.com addresses. The odds of getting a virus with a legitimate 'From' address are virtually nil.

Until we have authenticated-sender in email, I think it's past time for the mail gateways to give up on the bounce messages to infected emails. I bet none of the bounce emails actually got to anyone really infected, but they probably scared a lot of people who weren't. And they certainly didn't help reduce the deluge of useless emails flying across the Internet yesterday.

Posted by Mike at January 28, 2004 07:59 AM