Monopoly, Abuse of Power, and Self-Serving Goals or a Helping Hand in a Sea of Spam? Representatives from several internet companies spoke with technical journalist Lars Sobiraj to discuss the controversial Spamhaus project. An adapted analysis is below.

Who is the Spamhaus Project
If you search briefly online, you'll learn that Spamhaus is an international non-profit organization founded in 1998. However, according to former CIO (read: spokesperson) Richard Cox, Spamhaus is a British Limited Company. At the time of the interview with Cox (2011), Spamhaus's headquarters was in Geneva. Yet, all information about the company is contradictory, inconsistent, and mysterious.
Sven Olaf von Kamphuis (SOvK), one of the founders of Cyberbunker, speaks very unfavorably about Spamhaus. He claims that Mr. Cox has been inactive for over 20 years, if he even exists at all. The project is supposedly controlled solely by Mr. Stephen John Linford and his wife Myra Peters. Moreover, as SOvK suggests, non-profit organizations usually do not need offices in the Seychelles or Mauritius. The Cyberbunker co-founder is also puzzled as to why many journalists are 'infatuated' with the project – the media industry is largely responsible for the issues related to Spamhaus. All information that the project passes to technology publications is typically published without any verification, continues SOvK.

Spamhaus Project Twitter account, nearly 4000 followers
A judge and executioner in one without any legal authority to do so
What stands out immediately: no matter how significant and reasonable the company's function may seem, the Spamhaus project has no legal basis for its activities. Moreover, their operations have never been officially authorized by the government or competent authorities: SOvK emphasizes that Spamhaus is not even a member of RIPE (Réseaux IP Européens – the European regulator responsible for registering and distributing internet resources). Nevertheless, the outside world gets the impression that Spamhaus acts as a kind of 'internet police,' while, as Campuis points out, the company itself 'needs some police attention.' He also states that the publication of many data on the Spamhaus website is illegal and violates data protection rights. The publication of all information about spammers in the project should be prohibited. According to SOvK, the issue lies in the publication of personal data in the Register of Known Spam Operations (ROKSO). This data should be protected like any other personal information, not to mention that the contents of Spamhaus databases may not always have been obtained legally.
The position of Roskomnadzor on Spamhaus in RussiaSpeaking of the legality of the project's activities. According to from Roskomnadzor clarifying Spamhaus's situation, their activities in the Russian Federation are illegal:
Except for including the site in the Register based on the Information Law, a court ruling, or specific agreements with the telematics service user, the operator has no other grounds for restricting access to the site (network) (including at the request of the company 'Spamhaus').
If the telecom operator unjustifiably restricts the user’s access to the site (network), the operator's actions will constitute a breach of contract with the user.
How it was: Cyberbunker against the 'internet police'
In 2013, the conflict intensified between the underground web hosting service Cyberbunker and Spamhaus. Spamhaus, which was based in Switzerland at the time, blacklisted Cyberbunker due to the questionable activities of its clients and made this public. Following this, one of the largest DDoS attacks in Internet history occurred: Spamhaus.org was inundated with digital debris at a rate of 75 Gbps. It is said that due to its volume, the attack temporarily weakened global web traffic. In April 2013, local police visited the suspected criminal, SOvK, who was living in Spain at that time. Computers, storage media, and mobile phones belonging to a man referred to by the prosecutor as Mr. K. were confiscated.
The Spamhaus Project – a book behind seven seals
Regardless of the Cyberbunker incident, we tried to determine what the Spamhaus project actually is, as it is unclear from the information on their own website. To date, there have been no responses to inquiries sent to the press address since late January 2020. Mr. Kampuis claims that Spamhaus had only one non-profit limited liability company mentioned earlier, but it was removed from the registry in early 2020. The remaining companies did not have charitable purposes. The upstream provider and backbone operator, SquareFlow, has sued Spamhaus. SquareFlow offers services similar to Cogent, HE, GTT, LibertyGlobal, and others, hosting VPN services. Two executives from SquareFlow Group responded to our inquiry on March 1, 2020:
We cannot afford to arbitrarily disconnect a client or deny them all services solely based on Spamhaus deeming them bad. Under net neutrality, we cannot determine whether traffic is malicious without performing deep packet analysis, which would seriously harm the data privacy of our clients and their users. We are guided by the law, not the opinion of a third-party company that wants to dictate to the entire internet who is allowed to operate online and who is not. At this moment, we have no evidence, court orders, or other grounds to believe that our clients are engaged in malicious activities.
Because we did not collaborate with Spamhaus, they made several attempts to damage the reputation of our company, our suppliers, and partners. Under no circumstances can we or our clients be held accountable for suspicions.
Intimidate, warn, forcibly divide
Their attempts to influence entire networks can rightly be viewed as coercion, which is a criminal act in all EU countries. There have been several instances where Spamhaus blacklisted entire provider networks due to one client, forcing them to stop serving the undesired. We believe data privacy and anonymity are fundamental human rights. As a result, we will never blindly follow unfounded demands from Spamhaus or any other party attempting to dictate terms. Due to their actions, we have started taking measures against their business practices.
We also support our partners in legal actions against Spamhaus, as Spamhaus is still attempting to compel us to stop servicing certain clients through appeals to our partners and suppliers, labeling us criminals for not complying with their requests, which is clearly an abuse of power. We assume that their move to Andorra is linked to their criminal behavior, which has confronted the legal system in Britain.
Sincerely.
SquareFlow Group – Public Relations
On behalf of the Board of Directors: Wim B., Florian B.
The relocation of Spamhaus to Andorra
The Spamhaus project is now based in Andorra – a small country located in the Pyrenees, which is primarily known for its ski resorts, duty-free shops, and status as a tax haven, according to Wikipedia. It is important to note that Andorra is not part of the EU; relations between Andorra and the European Union are governed only by treaties.
Gathering information about the new organization associated with Spamhaus was not easy, but I eventually managed to find the necessary details in EUIPO (European Union Intellectual Property Office). According to EUIPO data, a company named Spamhaus IP Holdings S.L.U. currently owns trademark No. 005703401, registered on February 8, 2007. The registration application was submitted by Boyes Turner LLP.

Details of the Spamhaus trademark registration

Contact information is understandably hidden
Translator's noteFinding anything about the legal side of Spamhaus is indeed challenging. Moreover, the information available on the surface is frankly misleading. The only accessible information on Spamhaus's own site regarding the company's location pertains to the trademark – the word 'Spamhaus', which is registered in the EU.
ROKSO as a stumbling block

Clearly, the goal of the Spamhaus project was to identify spam distributors. As mentioned earlier, information about spammers is stored in the ROKSO database. However, since this database is public, Spamhaus literally puts all suspects on a blacklist. Not only can a wealth of personal data be found in the database, but it also includes unedited messages from victims. And since Spamhaus operates outside the EU, no repercussions from GDPR are expected for the company.
ROKSO literally tracks all suspicious activities, whether they involve actual spam or simple mistakes. Thus, there is no presumption of innocence in this case. Quickly contacting the company also does not seem possible. Their website lacks a phone number, email, or even a contact form for support. Some fragmented information can be gleaned by carefully reviewing the FAQ. I attempted to reach the company directly: from late January 2020 until the publication of this article [ed. note: April 6 of the same year], I received no responses to any inquiries.
Critique of Spamhaus's SBL by the VPN service nVPN
The VPN provider nVpn criticizes the project for other reasons. The Spamhaus Block List (SBL) is a constantly updated database of IP addresses. Spamhaus strongly recommends not accepting emails from addresses listed in the database. The company even claims that this database can be accessed in real-time. The Spamhaus website in the SBL section states that the blacklist "allows mail server administrators to identify, tag, or block incoming connections from IP addresses that Spamhaus believes are associated with the sending, hosting, or creation of unwanted bulk email." It also mentions that the SBL database is maintained by a special team of investigators and criminologists from 10 countries who work around the clock to monitor spam-related issues. However, how exactly the identification, verification, or even removal of records functions within the company is not explained.
nVpn always has issues with SBL records, which causes hosting companies to threaten to terminate their contracts. For example, in January 2019, a representative of a hosting provider from Albania informed the company that their VPN servers had been shut down due to "possibly being listed in SBL."
And this is not the only case. "Of course, something like this happens from time to time. Either the server is temporarily shut down due to SBL records, or companies completely cancel their contracts. At the beginning (we specifically ask), they claim that there will be no problems with SBL, but as soon as their entire IP range is blacklisted by Spamhaus, the situation changes. For example, we lost our server in Niš, Serbia, this way just a few weeks ago. Fortunately, the company provided us with a partial refund for the server rental that was paid several months in advance. Spamhaus is indeed dangerous for VPN services, but we just have to come to terms with it.
A representative of nVPN continues:
We provide a VPN service without registration and are among the few that offer clients the ability to open up to eight ports (TCP and UDP). Inevitably, some malicious actors will attempt to abuse this feature for illegal purposes. Although we explicitly state in our terms of service that such usage is prohibited, it doesn't mean that all clients adhere to the rules. As a result, some of our prefixes have ended up on EDROP. However, in our view, being listed on EDROP is not the end of the world, even if it blocks a few websites or a streaming service or two.
However, this still creates problems. Suppose we rented a server somewhere and created our own /24 subnet to announce under the ASN of a hosting company or our own. Spamhaus contacts our host and requests to disable the client, meaning us. If the provider does not comply with their requests because they trust us, Spamhaus starts adding clean prefixes of the host to the SBL, resulting in all its other clients being unable to send mail. Then the company has no choice but to disconnect us to avoid incurring significant financial losses.
Example of a host refusal letter:
Hello,
Unfortunately, we can no longer host you on our network as Spamhaus has blacklisted all our IP addresses due to your presence with us.
Your server will be disconnected on the last day of the rental without the possibility of extension.
Please make a backup as soon as possible and switch to another provider.Sincerely,
Vikas S.
(Director / Founder)
Skype: v **** vp *

Termination of services and cessation of further cooperation
nVpn claims to have lost many servers due to refusals from hosts in recent years. Ultimately, it has become difficult to find a company willing to accept them. nVpn submitted a suspension of cooperation and termination of services request to Tarnkappe.info dated July 11, 2019. The letter from the Swiss hosting provider states that the Spamhaus project will engage in 'criminal coercion' — that is, forcing the provider to refuse hosting for another company under the threat of litigation.
A representative from nVpn commented:
Sometimes Spamhaus does not hesitate to contact companies and demand that they stop routing our prefixes. However, not everyone complies with this request. One such company decided to sue Spamhaus Ltd in the United Kingdom, where the project's official headquarters used to be located. At that time, Spamhaus could not use Ltd in its name.
As a result of the legal proceedings, Spamhaus had to relocate its headquarters from the United Kingdom to Andorra.
Since then, nVpn still receives notices from SBL, but Spamhaus has finally stopped threatening their hosting providers. Additionally, Spamhaus has ceased responding to the VPN service's requests for the removal of listings from SBL, meaning that numerous old records remain in the database even though they are no longer relevant.
The VPN provider mentions that in the past, Spamhaus helped reduce global spam, which was useful. However, over time, the project began to monopolize efforts, publishing personal data of those listed and manipulating hosting companies.
There are still no answers to critically important questions.
There are many more questions regarding the Spamhaus project that nobody wants to answer. I have yet to receive a response to my inquiry sent three weeks ago to American spam researcher and journalist Brian Krebs. Perhaps the questions were too pointed, but it's unclear. Inquiries were submitted to other companies as well, but almost nobody knows the whole story of the Spamhaus project.
About the Author of the Original Article
Lars “Ghandy” Sobiraj
Lars Sobiraj began his career in 2000 as a writer for various computer magazines. He is the founder of Tarnkappe.info. Since 2014, Ghandy, as he calls himself on stage, has been educating students at various universities and other educational institutions about how the Internet works.
From the Translator
The activities of Spamhaus have already It was covered on Habr, and exclusively in a negative light. In Russia, Spamhaus has hindered (and continues to hinder) both private companies and large hosting providers. In 2010, the entire Latvia was added to the blacklist: a complaint from one of the largest providers in the country was met with a response from Spamhaus suggesting that Latvia is one of the smallest countries in the world. For some reason, the latest posts related to Spamhaus are dated 2012-2013, although the company still exists today; I believe this unjust obscurity needs to be broken.
Source: habr.com
