I wish to preface this with the fact that I am a deep believer in cooperation and data sharing. Also, I really appreciate the work that volunteers put into maintaining different resources (like the excellent CastleCops forums).
But you have to remember that these people are not professionals and sometimes don’t have a complete understanding of all the aspects of issue. Still people cite them as references and base decisions on their opinions. The Internet was regarded as the ultimate place for meritocracy, however sometimes it turns into a
how can yell louder and/or a popularity contest.
The DNS Black Hole project puts out a list of domains to block (or black-hole – hence the name I suppose). Until recently they did not have an official policy on removing domains. Recently they put up a post in which they try to clarify their take on the issue of false positives, and seem to take a (from their point of view) quite reasonable stance that they are just an aggregator and if you wish a domain to be removed, you should contact the original source.
However this begs the question about the quality of their data. I understand that they don’t have the capacity to validate every single submission, but if they can’t even check out false positives, is this really a blocklist you wish to use? You might as well start blocking entire countries…
Sometimes they realize that they are blocking an unrelated third party service (like recently when they announced that they are adding some dynamic dns providers to the blacklist because
they are used extensively by malware, and sometimes they don’t. The current list includes at least two free services from Romania which offer free webhosting and probably from time to time host malware, just like geocities. But you won’t find all geocities sites blocked by it, even though both of these Romanian / lesser known sites are blocked completely. I tried to contact them a few weeks back to let them know about the problem and I yet to receive any feedback.
The maintainer of the site also offers his (or her?)
PS Sorry for ranting / sounding jaded. I want emphasize again that I do appreciate all the work put into these (free) services, it’s only that I wish that people would investigate claims before putting their faith in some of these sources (and also the fact that I can’t seem to get to sleep :-)).