, 2006-05-30
Kelly Martin takes a step back from e-mail's unstoppable phishing-virus-spam epidemic and imagines a world where secure e-mail could be the next big killer app.
Expand all |
Post comment
Rubbish! What are the probIem ISSUES ????
2006-05-31
Dom De Vitto (1 replies)
Dom De Vitto (1 replies)
Um, I Have Your Solution
2006-06-01
Reynolds Kosloskey (3 replies)
Reynolds Kosloskey (3 replies)

Simply pointing to a protocol or standard and saying 'here, we have all these solutions' isn't enough if the infrastructure that supports them doesn't work or can't be trusted. Of course some new e-mail replacement or fix will be some new standard or use of an existing set of standards but the infrastructure must support them correctly.
The problem is ease of use. To make certificates of any form trustworthy, one must issue them securely. This would probably mean I'd have to turn up, in person, at a suitable issuer's office with suitable referring documents. Even then there would be issues with fake IDs and so on. No one commericial or free-spirited organisation can hope to process enough people to achieve this. Even governments have trouble (witness the projected difficulties with issuing ID cards in the UK regarding sheer manpower required).
As for users failing to check identities, this is an education and software design failure. Why not require e-mail software to prompt you each time you open an unsecure untrusted e-mail? This forces the user to think about 'who do I trust?'.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/404/33690#33690