Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Abandon e-mail!
Kelly Martin, 2006-05-30

Kelly Martin takes a step back from e-mail's unstoppable phishing-virus-spam epidemic and imagines a world where secure e-mail could be the next big killer app.

Comments Mode:
Abandon e-mail! 2006-05-31
Anonymous (6 replies)
Re: Abandon e-mail! 2006-05-31
Anonymous
Re: Abandon e-mail! 2006-05-31
Stephan Sokolow
Re: Abandon e-mail! 2006-05-31
Paul
Re: Abandon e-mail! 2006-05-31
Anonymous
Re: Abandon e-mail! 2006-05-31
J
Re: Abandon e-mail! 2006-07-27
Anonymous
Rubbish! What are the probIem ISSUES ???? 2006-05-31
Dom De Vitto (1 replies)
Re: Rubbish! What are the probIem ISSUES ???? 2006-06-01
Jeff H (1 replies)
Re: Re: Rubbish! What are the probIem ISSUES ???? 2006-06-01
Anonymous (1 replies)
Re: Re: Re: Rubbish! What are the probIem ISSUES ???? 2006-06-06
Jeff H (1 replies)
True, X.509 does provide a form of identity, if specified correctly. However, you point out yourself that the problem is trust.

Simply pointing to a protocol or standard and saying 'here, we have all these solutions' isn't enough if the infrastructure that supports them doesn't work or can't be trusted. Of course some new e-mail replacement or fix will be some new standard or use of an existing set of standards but the infrastructure must support them correctly.

The problem is ease of use. To make certificates of any form trustworthy, one must issue them securely. This would probably mean I'd have to turn up, in person, at a suitable issuer's office with suitable referring documents. Even then there would be issues with fake IDs and so on. No one commericial or free-spirited organisation can hope to process enough people to achieve this. Even governments have trouble (witness the projected difficulties with issuing ID cards in the UK regarding sheer manpower required).

As for users failing to check identities, this is an education and software design failure. Why not require e-mail software to prompt you each time you open an unsecure untrusted e-mail? This forces the user to think about 'who do I trust?'.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/404/33690#33690
The real problem with X.509 is... 2006-06-08
Roger (1 replies)
Abandon e-mail! 2006-05-31
Kevin Black (1 replies)
Re: Abandon e-mail! 2006-06-01
PDC (1 replies)
Re: Re: Abandon e-mail! 2006-07-12
Anon
Babies and bathwater 2006-05-31
Anonymous
Abandon e-mail! 2006-06-01
Anonymous
Abandon e-mail! 2006-06-01
Anonymous (1 replies)
Re: Abandon e-mail! 2006-06-04
Anonymous
Abandon e-mail! 2006-06-01
Erik N
Abandon snail-mail! 2006-06-01
Phlash (1 replies)
Re: Abandon snail-mail! 2006-06-01
Anonymous (1 replies)
Abandon e-mail! 2006-06-01
Mercury/|Hermes
Um, I Have Your Solution 2006-06-01
Reynolds Kosloskey (3 replies)
Re: Um, I Have Your Solution 2006-06-01
kwesi (1 replies)
Web Based Email 2006-06-01
Reynolds Kosloskey
Re: Um, I Have Your Solution 2006-06-02
Mr. Mail
Abandon e-mail! 2006-06-01
Paul Kosinski (1 replies)
Re: Abandon e-mail! 2006-06-01
Paul Kosinski
Abandon e-mail! 2006-06-01
JeHicks
Abandon e-mail! 2006-06-02
Brush-Head
A bottin 2006-06-02
lucmars
Top 500 Supercomputer 2006-06-02
Anonymous
Abandon mail, too? 2006-06-02
Anonymous
Abandon e-mail! 2006-06-02
Anonymous (1 replies)
Re: Abandon e-mail! 2007-07-25
Anonymous
You're crazy and uninformed! 2006-06-02
Anonymous
Abandon e-mail! 2006-06-02
Anonymous
Abandon e-mail! 2006-06-05
ITDefpat
This is silly. 2006-06-06
Anonymous
The final solution 2006-06-12
Anonymous
Abandon e-mail! 2006-07-01
Richard







 

Privacy Statement
Copyright 2009, SecurityFocus