Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Abandon e-mail!
Kelly Martin, 2006-05-30

Kelly Martin takes a step back from e-mail's unstoppable phishing-virus-spam epidemic and imagines a world where secure e-mail could be the next big killer app.

Comments Mode:
Abandon e-mail! 2006-05-31
Anonymous (6 replies)
Re: Abandon e-mail! 2006-05-31
Anonymous
Re: Abandon e-mail! 2006-05-31
Stephan Sokolow
Re: Abandon e-mail! 2006-05-31
Paul
Re: Abandon e-mail! 2006-05-31
Anonymous
Re: Abandon e-mail! 2006-05-31
J
Re: Abandon e-mail! 2006-07-27
Anonymous
Rubbish! What are the probIem ISSUES ???? 2006-05-31
Dom De Vitto (1 replies)
Abandon e-mail! 2006-05-31
Kevin Black (1 replies)
Re: Abandon e-mail! 2006-06-01
PDC (1 replies)
Re: Re: Abandon e-mail! 2006-07-12
Anon
Babies and bathwater 2006-05-31
Anonymous
Abandon e-mail! 2006-06-01
Anonymous
Abandon e-mail! 2006-06-01
Anonymous (1 replies)
Re: Abandon e-mail! 2006-06-04
Anonymous
Abandon e-mail! 2006-06-01
Erik N
Abandon snail-mail! 2006-06-01
Phlash (1 replies)
Re: Abandon snail-mail! 2006-06-01
Anonymous (1 replies)
Abandon e-mail! 2006-06-01
Mercury/|Hermes
Um, I Have Your Solution 2006-06-01
Reynolds Kosloskey (3 replies)
Re: Um, I Have Your Solution 2006-06-01
kwesi (1 replies)
Web Based Email 2006-06-01
Reynolds Kosloskey
Re: Um, I Have Your Solution 2006-06-02
Mr. Mail
Abandon e-mail! 2006-06-01
Paul Kosinski (1 replies)
Re: Abandon e-mail! 2006-06-01
Paul Kosinski
Abandon e-mail! 2006-06-01
JeHicks
Abandon e-mail! 2006-06-02
Brush-Head
A bottin 2006-06-02
lucmars
Top 500 Supercomputer 2006-06-02
Anonymous
Interesting article, but bad wording and (somwhat) wrong sort of solution 2006-06-02
Anonymous
I find the article interesting because I've been thinking along much the same lines recently. However, there are two things that I strongly disagree with in the article.

The first is that we shouldn't talk about abandoning e-mail. That's nonsense. E-mail is just a way of delivering messages from one client to another via one or more intermediate servers that store messages (for a while, at least) until the receiving client fetches them. SMTP is one protocol used for message delivery in this manner, XMPP is another (the jabber instant messaging protocol). If you were to send electronic letters via XMPP, and if your client looks much like a regular e-mail client, would the message not still be e-mail?

A better wording would be that the SMTP protocol should be supreseded by another protocol that takes today's security issues into account. I'd wholeheartedly agree with that. But abandon e-mail as such? Nope, I want to keep it.

Which leads me to the second gripe, that abandoning e-mail is just the wrong solution for the "phishing-virus-spam"-problem. As other people have pointed out, methods such as PGP work fine for protecting you, if your client simply refused to accept messages not signed by trusted entities.

The problem here is two-fold: managing trusted entities is cumbersome, and people don't understand why they should take on that burden.

So the solution must be to make managing trust in that way a lot simpler, and to educate the user.

Everything else is bound to fail.

As a sidenote, a new protocol should probably be designed in such a way that invalid/rejected messages can be rejected before the message has been passed around a whole lot. In other words, it should probably stay on the first server contacted by the sender's client until the receiver's client has signalled that it will accept the message. Running my own mailserver, I can tell you that most of my available bandwidth would be saved for useful traffic that way.

Now who will pay me to design and implement such an alternative mail system?

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/404/33677#33677
Abandon mail, too? 2006-06-02
Anonymous
Abandon e-mail! 2006-06-02
Anonymous (1 replies)
Re: Abandon e-mail! 2007-07-25
Anonymous
You're crazy and uninformed! 2006-06-02
Anonymous
Abandon e-mail! 2006-06-02
Anonymous
Abandon e-mail! 2006-06-05
ITDefpat
This is silly. 2006-06-06
Anonymous
The final solution 2006-06-12
Anonymous
Abandon e-mail! 2006-07-01
Richard







 

Privacy Statement
Copyright 2009, SecurityFocus