The fix isn't ever more heuristics - that is an uphill battle that can't ever be won. The fix is following the money and disconnecting the bad actors' ISPs from the Internet.
There was a time when abuse@<isp-domain.tld> emails were honored and administrators actually took notice of what came in, but these days are long since gone - ISPs simply don't want to spend the money, and so the cost of abuse is externalized to society at large.
ETA: Also, a fix would be to have a human with more than ten seconds time take a look at even 1% of spam reports. Spammers are lazy, they always use the same template, so if you have a human actually looking into the template and then routing every match to /dev/null, it's far more effective. Like... I can do this on Twitter for every new variation of some scam, why can't Twitter do it on its own?!
Do you really want ISPs to be in the business of deciding what should and should not be on the internet though? That sort of thing typically doesn't work too well.
Deciding what is or isn't a "scam" is really a job for the independent judiciary. But getting a ruling is difficult and time-consuming, and also largely pointless because a new website can be created almost instantly, and there are many foreign ISPs where you can't get a ruling at all.
I don't really disagree with your basic premise that "disconnecting the bad actors' ISPs from the Internet" is the ideal solution, but this is far more difficult than your comment implies – almost impossible with how the internet currently works.
I think that the parent comment was referring to the days when ISPs were local or network services were provided by a school or a some other entity which had a vested interest in keeping their network clear of bad actors.
Comments
The fix isn't ever more heuristics - that is an uphill battle that can't ever be won. The fix is following the money and disconnecting the bad actors' ISPs from the Internet.
There was a time when abuse@<isp-domain.tld> emails were honored and administrators actually took notice of what came in, but these days are long since gone - ISPs simply don't want to spend the money, and so the cost of abuse is externalized to society at large.
ETA: Also, a fix would be to have a human with more than ten seconds time take a look at even 1% of spam reports. Spammers are lazy, they always use the same template, so if you have a human actually looking into the template and then routing every match to /dev/null, it's far more effective. Like... I can do this on Twitter for every new variation of some scam, why can't Twitter do it on its own?!
Do you really want ISPs to be in the business of deciding what should and should not be on the internet though? That sort of thing typically doesn't work too well.
Deciding what is or isn't a "scam" is really a job for the independent judiciary. But getting a ruling is difficult and time-consuming, and also largely pointless because a new website can be created almost instantly, and there are many foreign ISPs where you can't get a ruling at all.
I don't really disagree with your basic premise that "disconnecting the bad actors' ISPs from the Internet" is the ideal solution, but this is far more difficult than your comment implies – almost impossible with how the internet currently works.
We are oh so close to a balkanised internet.
Thankfully, the powers that be outside of CN, RU and a few others haven't really gone to town on buggering up basic connectivity, yet.
I think that the parent comment was referring to the days when ISPs were local or network services were provided by a school or a some other entity which had a vested interest in keeping their network clear of bad actors.
The fix is to give users the tools to lean more heavily on transitive trust and less heavily on the platform.
Or we build those tools ourselves and let the platforms be dumb pipes which we selectively slurp from.
The days of trusted-by-default banned-selectively are ending. It's dark forest time.
This ignores that botnets, malware, etc exist.
Well, ISPs can hold their customers accountable as well. Get told you're running malware, you got 24h to get it fixed, or you get disconnected.