6 ms·
A second root problem is the insanity of public SMTP on today's Internet: allowing anyone, claiming any identity, to send you any content without limits. I sta
by networkimprov 5y ago
A second root problem is the insanity of public SMTP on today's Internet: allowing anyone, claiming any identity, to send you any content without limits.
I started the "mnm" open source project to enable a new email network, on a new protocol.
More: https://mnmnotmail.org/ https://mnmnotmail.org/
Follow: https://twitter.com/mnmnotmail https://twitter.com/mnmnotmail
- bouncycastle 5y agoIt looks very similar to Slack / Discord. However, if an org needs email, why can't they just configure their filters to move everything from outside the org in a special folder, and email server could further filter any link and put it through a warning page before redirecting to the link. We already have DKIM and SPF to verify if the domains of the sender. Just setting up these can work.
- networkimprov 5y agoHave you looked through the FAQ and protocol draft? https://mnmnotmail.org/faq.html https://mnmnotmail.org/faq.html https://github.com/networkimprov/mnm/blob/master/Protocol.md https://github.com/networkimprov/mnm/blob/master/Protocol.md The mnm client app isn't chat-oriented like Slack & Discord, altho it does provide presence status for contacts who've opted into that.
- corinroyal 5y agoThank you! I'm a huge fan of the mnm approach. I wish you tremendous success.
- networkimprov 5y agoYou're most welcome! Patreon link on website ;-)
- citrin_ru 5y agoThis problem is partially solved by DMARC/SPF/DKIM. There a few issues with DMARC, but the main one - adoption by senders is well below 100% so you just cannot block mail without DMARC. But the main question I have - does a typical mail users actually care about sender domain? I suspect - not at all. And I see two main reasons for this. First notion of domain is de-emphasized everywhere - browsers turned address bar into a search bar and make real URL hard to notice, MUA (e. g. Outlook) don't show full email for senders in an address book. Second problem - legitimate senders often behave in exactly the same way as phishers - use unrelated/unknown domain and give no way to verify that the domain is legitimate. For example Charter/Sirius ISP sends mail from domain customeremailnotifications.com [1] and I found no ways to see for sure that is domain is owned or used by Charter. My memory is fuzzy, but PayPal (or ebay) AFAIR used a phishy domain too, something like managemypaypal.com. A largish ZA utility sends mail from eskomstatements.co.za having the main domain eskom.co.za and of course there is no good way to verify that both domains owned/used by the same company. List can be continued. All this conditions users to trust mail which is coming from a random-domain-registered-by-phishers, because legitimate senders do the same. [1] https://www.reddit.com/r/Spectrum/comments/dfpres/email_domain_customeremailnotificationscom_for/ https://www.reddit.com/r/Spectrum/comments/dfpres/email_doma... (1 year old, but situation hasn't changed a bit)
- naturalauction 5y ago>There a few issues with DMARC, but the main one - adoption by senders is well below 100% so you just cannot block mail without DMARC. I wonder if this could be fixed by email clients marking emails that fail DKIM as spam/attaching a large warning. Most users use email clients and they really don't do a great job of notify users of potential spoofing issues (with Gmail, you have to find "view original" to see that DKIM fails). I'm sure that spam filters would notice after a few hundred/thousand emails, but a successful spear-phishing attempt may not require that many emails. If customers complain about legitimate emails being marked as actually fraudulent, I'm sure adoption rates will increase.
- networkimprov 5y agoMy understanding is that most phishing attacks are launched from webmail accounts, which implement DMARC.