3 ms·
This. And the effectiveness of targeted phishing is why we must replace SMTP-based email, and eventually block SMTP on public networks. It isn't suited to the 2
by networkimprov 6y ago
This. And the effectiveness of targeted phishing is why we must replace SMTP-based email, and eventually block SMTP on public networks. It isn't suited to the 21st Century Internet.
Hence, the mnm project[1] (open source client & server) and TMTP[2][3].
[1] https://mnmnotmail.org https://mnmnotmail.org
[2] https://github.com/networkimprov/mnm/blob/master/Protocol.md https://github.com/networkimprov/mnm/blob/master/Protocol.md
[3] https://mnmnotmail.org/rationale.html https://mnmnotmail.org/rationale.html
- md_ 6y agoHmm, the value proposition of MNM here (in preventing phishing) seems to derive from the design goal of not allowing arbitrary content on first contact between arbitrary users, or do I misunderstand? This strikes me as a cure worse than the disease. There’s a strong social need for people—especially those who are public figures or soliciting job offers—to be reachable by “never before seen” contacts. There’s also a strong social need to allow people to send emails from self-provided (I.e. unverified) names or identities, given the currently burdensome process of getting “verified”. I think you could argue that there’s an opportunity to move business email to “real ID”-verified identities (e.g. with SMIME), but I struggle to see how that’s a problem with SMTP or how replacing the protocol will help there.