Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Abandon e-mail!
Kelly Martin, 2006-05-30

Kelly Martin takes a step back from e-mail's unstoppable phishing-virus-spam epidemic and imagines a world where secure e-mail could be the next big killer app.

Comments Mode:
Abandon e-mail! 2006-05-31
Anonymous (6 replies)
Re: Abandon e-mail! 2006-05-31
Anonymous
Re: Abandon e-mail! 2006-05-31
Stephan Sokolow
Re: Abandon e-mail! 2006-05-31
Paul
Re: Abandon e-mail! 2006-05-31
Anonymous
Re: Abandon e-mail! 2006-05-31
J
Re: Abandon e-mail! 2006-07-27
Anonymous
Rubbish! What are the probIem ISSUES ???? 2006-05-31
Dom De Vitto (1 replies)
Abandon e-mail! 2006-05-31
Kevin Black (1 replies)
Re: Abandon e-mail! 2006-06-01
PDC (1 replies)
Re: Re: Abandon e-mail! 2006-07-12
Anon
Babies and bathwater 2006-05-31
Anonymous
Abandon e-mail! 2006-06-01
Anonymous
Abandon e-mail! 2006-06-01
Anonymous (1 replies)
Re: Abandon e-mail! 2006-06-04
Anonymous
Abandon e-mail! 2006-06-01
Erik N
There is no way you can get rid of the spam/scam problems when you want to enable users unknown to eachother to establish a communication. At least not unless you add a cost. Your own idea won't work as long as spammers can get hold of large bot nets where each host will only send 1000 mails.

Maybe the following will be what you call yet another attempt to fix e-mail. But, there are a few basic things that could and should be done:

* All users must authenticate to send e-mail to non-local destinations

* All servers must use TLS, both when accepting mail from clients or other servers

Ofcourse this won't solve all problems, as long as bot-networks are available for spammers.

But:

This means that the server can check that the senders address exist and is authenticated before accepting the mail for delivery.

Supporting TLS on all servers will mean that one can limit mail acceptance to servers with certificates signed by trusted CA's, much like the SPF.

Further, it will mean that you can send your e-mail protected against sniffing en-route.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/404/33660#33660
Abandon snail-mail! 2006-06-01
Phlash (1 replies)
Re: Abandon snail-mail! 2006-06-01
Anonymous (1 replies)
Abandon e-mail! 2006-06-01
Mercury/|Hermes
Um, I Have Your Solution 2006-06-01
Reynolds Kosloskey (3 replies)
Re: Um, I Have Your Solution 2006-06-01
kwesi (1 replies)
Web Based Email 2006-06-01
Reynolds Kosloskey
Re: Um, I Have Your Solution 2006-06-02
Mr. Mail
Abandon e-mail! 2006-06-01
Paul Kosinski (1 replies)
Re: Abandon e-mail! 2006-06-01
Paul Kosinski
Abandon e-mail! 2006-06-01
JeHicks
Abandon e-mail! 2006-06-02
Brush-Head
A bottin 2006-06-02
lucmars
Top 500 Supercomputer 2006-06-02
Anonymous
Abandon mail, too? 2006-06-02
Anonymous
Abandon e-mail! 2006-06-02
Anonymous (1 replies)
Re: Abandon e-mail! 2007-07-25
Anonymous
You're crazy and uninformed! 2006-06-02
Anonymous
Abandon e-mail! 2006-06-02
Anonymous
Abandon e-mail! 2006-06-05
ITDefpat
This is silly. 2006-06-06
Anonymous
The final solution 2006-06-12
Anonymous
Abandon e-mail! 2006-07-01
Richard







 

Privacy Statement
Copyright 2009, SecurityFocus