4 ms·
The incredibly damaging and widespread exploitation of SMTP for cybercrime (via phishing, etc) implies that the correct model for Internet messaging is non-fede
by networkimprov 5y ago
The incredibly damaging and widespread exploitation of SMTP for cybercrime (via phishing, etc) implies that the correct model for Internet messaging is non-federated, i.e. more like HTTP than SMTP. That's not to say that federation isn't valuable in other applications, e.g. social media.
Federation in SMTP was necessary given the Internet's topology when email was invented. That network is long gone.
See TMTP, from the mnm open source project, which implements both the client & server:
https://mnmnotmail.org/ https://mnmnotmail.org/
- giantrobot 5y agoI don't think federation is the core issue with e-mail. I see the core problem as terrible MUAs don't use nearly enough signals to interpret identity of senders. SMTP has means to identify servers and domain ownership, web browsers have infrastructure to identify and verify arbitrary websites, and S/MIME exists. Most MUAs ignore basically all of this and instead trust whatever address is in a message's From header.
- networkimprov 5y agoMost phishing attacks originate on webmail accounts, which implement DMARC.
- giantrobot 5y agoDMARC is only as effective as the domain's suggested policy and the receiving server doing the right thing. It also doesn't have much if anything to do with the MUAs as they don't see any of the SPF/DKIM operations happening. DMARC doesn't do and isn't intended to do anything to verify the content or validity of an individual message.
- josephg 5y agoI strongly disagree. If email was non-federated (like HTTP) then either it wouldn't be so ubiquitous, or a single company would control the digital communication of most of the world's citizens. Either of those outcomes would result in a poorer world. The fact that facebook, telegram, whatsapp, etc are all centralized doesn't seem to stop criminals using those platforms.
- doublepg23 5y ago> or a single company would control the digital communication of most of the world's citizens. I agree with your point but has this not happened with Gmail, Microsoft and Yahoo! for email anyway?
- josephg 5y agoIt’s certainly a worry, but at least other options do exist. And if you own a domain name, you can move your email hosting (including all your addresses) to the provider you like the most. And it’s certainly a much better situation than other chat systems, where your identity is fundamentally tied to your account on that particular service. You can’t move to signal without moving everyone else to signal at the same time. I only need one email provider and one email app. But for messaging, everyone ends up needing signal, and WhatsApp, and Facebook to talk to each other. Imagine if you needed half a dozen email apps and accounts for each one to use email. “Oh, you’re emailing a company who uses Microsoft? Better open the Microsoft email program and remember your Microsoft login”. No thanks!
- networkimprov 5y agoZillions of websites have active discussion boards, despite the success of Reddit and FB Groups. A handful of webmail providers have centralized a large fraction of all email users. They already have the control you're concerned about. Non-federated email means you have accounts at several sites, and most sites have membership requirements (customers-only, employees-only, etc). A client app keeps track of all your accounts. A webmail intermediary is unnecessary. The mnm demo gives a sketch of this [1] and the FAQ gives more detail [2]. [1] https://mnmnotmail.org/demo.html https://mnmnotmail.org/demo.html [2] https://mnmnotmail.org/faq.html https://mnmnotmail.org/faq.html
- shkkmo 5y agoGiven that you could easily "unfederate" SMTP/pop3 and have the exact same model, I don't see how exactly the lack of federation will be a selling point. I see any value in TMTP in the improvements as a protocol and I think it will be only be hurt by having no provision for federation in the protocol.