Showing posts with label Spam. Show all posts
Showing posts with label Spam. Show all posts

Monday, March 3, 2025

Reader Comments and SPAM

I ‘moderate’ comments to this blog, I have since its inception. For the most part, I have rejected comments that are purely efforts to trade on the ‘popularity’ of this blog to drive traffic to other websites that are unrelated to the topic at hand. Today, I ran into a fringe case, one where it was an obvious attempt to drive traffic, but it was related to the blog topic. So, gritting my teeth, I approved the comment and I am now calling further attention to it.

The comment in question came from himaram and it was posted to July 14th, 2022 post on CISA control system security advisories. The comment included a generic positive comment about the post and then provided links to 11 training programs for the Siemens Mendix system. Those training programs were at least thematically related to three CISA advisories for vulnerabilities in Siemens Mendix products discussed in that post. I have not looked at any of the training programs, and I certainly do not endorse them.

Is this comment SPAM? Probably. It is certainly advertising, ads for which I am receiving no compensation (and no, I am not soliciting ads for this site). But, it was notionally on topic, so it met my less than stringent moderation guidelines.

In my view, the whole point about reader comments is that they should be a mechanism to expand the discussion that I have started with a blog post. I want to encourage readers to correct me when I make a mistake or provide additional information on topics where their experience or expertise is different than mine. In the broadest interpretation this comment fulfils that last requirement. I would have preferred more discussion beyond just listing the courses available, but in the interest of encouraging discussion, I allowed this comment to be posted to the blog.

Wednesday, July 20, 2011

Chemical Spam

Last Friday Steven Partridge from ADT had an interesting blog posting over at ChemicalProcessing.com concerning an alert from the FBI about a bogus FBI letter that had been sent to at least a couple of chemical facilities. The letter asked for money for a ‘Clearance Certificate’ and threatened legal action if the money was not forthcoming.

Apparently this was an example of one of the more outrageous types of cons typically seen more often in electronic mail boxes than snail mail boxes. Most of us have seen at least a few of these leak past our spam filters. They are typically so over the top that one wonders how these folks ever get a response that makes their efforts pay off.

The only reason that I even mention this is that the electronic counterparts of these silly messages may actually pose a risk to chemical facilities. These emails may be so over the top that individuals might investigate the links in the message just to see ‘how stupid people really are’ just for the fun of it.

People need to be constantly reminded that their surfing through a properly crafted web site may be all that is necessary to place malware on their computer and the corporate network. Inadvertently inviting these folks behind the corporate firewall can be a first step along the road to compromising the manufacturing control system.
 
/* Use this with templates/template-twocol.html */