« Skype Video Gets Exposure; Oprah.com Suffers Congestive Internet Failure | Main | Could Skype be as open as Open AIM 2? as the iPhone? »

The Skype Journal Evil Genius Award: Sexy SPIM for Skype

This is evil genius. The evil is the Spam over Instant Messaging (SPIM) time wasting, behavior changing, unsolicited contact.

Let me explain the genius part...

SPIM like this is hard to do. Especially if you want it to scale. And you need it to scale to make money. (Compare the difficulty with that of building an  enterprise CRM system.)

Ten Steps to Build a SPIM Empire

1. Spider for Skype names. spim09You'll find Skype IDs on the web, Skype's authentication server, and the Skype cloud. Skype.com is locked down tight, hacking supernodes is complicated, so I'll bet they got an off-the-shelf web crawler to search for Skype names in the wild. The spider will have fun in the Skype forums, public email archives, and open social networks.

2. Generate Skype accounts. spim08You want to make it hard for Skype to blacklist you, to bar you from logging on to the Skype network. So:

  • write a script that automatically makes new profile data, combining art, names, and text from a small collection.
  • for each profile, create an email address. You need an email address to authenticate each Skype account, one per profile. You'll want many email servers for this, again so Skype.com doesn't block you at the domain level.
  • Script creating the Skype account using the profile data and email address.
  • Confirm acknowledgement email from Skype.com email. You'll write a script to do this.

3. Run lots of Skype. spim03You'll need a farm of Skype clients running. One client for each account. Skype IM is cheap on bandwidth but can chew up lots of memory and CPU. You can run a handful of Skype clients on a Windows PC, but lots on a well-tweaked linux box with tweaked Skype installations.

Skype farming is a practice proven by all the companies that make Skype-to-PBX gateways or offer services that connect to the Skype cloud. iSkoot, Mobivox, and others keep hundreds of Skype clients running in production data centers. 

4. Reach out and touch someone. spim06Now it's time to hit your targets. Your management software keeps track of your relationship with each target, each time and way you touched them, and what the response was. Here's where you try different patterns of art, language, time of day, day of week, profile elements. With Skype, you'll send IMs and friend requests. 

5. Automate the first answer. spim01Assure your prospective customers, victims, or voters have a prompt response. Having a robot say "Hi!" or "Hola!" may give your human a chance to get in place and catch up.

6. Route incoming chats. spim04So a dozen of you are sitting in a room with a thousand Skypes running. You'll need to write a Skype plug-in that alerts you whenever someone takes the bait. The plug-in needs to tell the management software whenever there's a new friend. It will also bring a Skype chat window into focus so a human can see it.

You may also find the best operator available for a given prospect. Language, gender, time availability are all factors that might boost conversion rates.

7. Sell, Sell, Sell. Now you have a prospect in a chat room. Good luck!

8. If at first you don't succeed, try, try again. spim02Experimentation is the key. You won't know if I like blondes or brunettes, naughty nurses or the sexual object next door, regular or decaf, blue or green. Brute force trial and error is the plan.

9. Then quit. It's a world full of prospects, so you don't want to waste system or staff time on unlikely prospects. At some point you cut your losses and leave a prospect alone. For now.

10. Pssst. Hey, buddy, wanna buy a million Skype names? Count on it.

What does Skype do about it?

Skype's Chief Security Officer, Kurt Sauer, explained the problem from Skype's view.

"Skype defines SPIM from a behavioral point of view, not from a message content point of view, as messages are sent directly from one user to another peer-to-peer.  Because of that, each copy of Skype software attempts to identify patterns of activity that appear to mimic the sending of unsolicited message content to a broad audience.  Once this pattern of behavior has been identified, the software limits the number of messages that can be sent. In addition, each Skype user has a range of privacy settings at their disposal that can prevent the receipt of any kind of unsolicited contact, whether by video, voice or chat.

Skype is constantly reviewing its software architecture to find new ways to ensure its customers’ protection from receiving unwanted communications.  SPIM control is a growing area of research, not only for Skype but for the online communications industry as a whole.  Consequently, Skype continues to develop and test innovative solutions to improve the quality of the Skype experience.

Skype's privacy policy only promises they protect your information on their computers.

What can you do for yourself?

Basically,

  1. Keep your Skype name private.
  2. Keep your Skype account unlisted (only accept contact from people already in your buddy list).

Related Skype support articles:

How does Skype's SPIM problem compare to other IM networks?

From what I can tell, it's astoundingly better than Yahoo!'s, long polluted with massive quantities.

No idea about Microsoft or AOL.

On the net:

The Evil Genius Song

Spim spimminy
Spim spimminy
Spim spim sperree
I'm searching the net
For vulnrabil'ty

Spim spimminy
Spim spimminy
Spim spim sperroo
Bad luck will rub off
when I make friends with you

TrackBack

TrackBack URL for this entry:
http://skypejournal.com/blog-mt/mt-tb.fcgi/3917

Comments

It is very convenient that neither the Skype Journal nor the Skype "Chief Security Officer" mention the fact that Skype connection requests, complete with whatever picture the requester chooses to include, cannot be blocked from popping up in the middle of your screen. As long as Skype refuses to acknowledge this problem and do something about it, you, your family, your children, are helpless recipients of whatever spam, garbage, or pornography anyone wants to send.

anybody at any time can assume any identity in skype, being anywhere (over and over) it is an unmanageable system. it's the perfect tool for spamming and other activities in which normal people would not engage. add to that the permissive link to email-addresses and there you have biggest permissive free database for global spammers. congratulations skype. now go solve the problem...

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Brought to you by:

Convenos_125x125.active.gif

Auto generated tags