4 ms·
> The real story is nobody cares. Exactly. Why should the major players care about those too small to matter? > Sure you would have to catch people buying a
by bhauer 4y ago
> The real story is nobody cares.
Exactly. Why should the major players care about those too small to matter?
> Sure you would have to catch people buying a "good" domain that expired
Adding to my earlier point, Google and Microsoft are well-enough connected to the domain registrars to know when that scenario has happened as well. If they put any effort into it, they could reliably determine whether a new IP address for an established domain is legitimate or a fraud. But as we've said, why put any effort into it when the only people complaining are not important?
- bombcar 4y agoAnd it's even worse - if we theorize a email competitor appearing out of nowhere to rival Gmail, and people complaining, all that would happen is Google and Microsoft would special-case that provider, and the underlying issue wouldn't be solved.
- gnarbarian 4y agoa class action lawsuit could make them care. as far as how to solve this problem technically, I think a reputation system based not on domains or ips but on email certificates is the real answer here.
- toast0 4y agoDKIM is certificates, so I'm guessing you're talking about sender certificates? How would that help? Spammers can get certificates too. Maybe it cuts down on some of the misconfigured http email senders, maybe, but not enough to matter. Scam sites run https these days. You can't use like age of activity of the cert to help because a) things get compromised, b) you need to rotate your certs frequently anyway.
- u801e 4y agoShouldn't the authority (or key) used to sign those certs be long lived? The certificates themselves should be rotated frequently, bit not the key used to sign them.
- Avamander 4y agoThere's only S/MIME, TLS and BIMI+VMC that use actual certificates. DKIM does not and DKIM keys should be rotated once in a while, but few do.
- Avamander 4y agoBeing able to tie together letters and senders, knowing who sent what, would help. It wouldn't help to fully trust, nothing would, it's a human problem, it would help to trust more.
- toast0 4y agoIf the email is DKIM signed, it's expected that the sender was authorized to send the message. Any wide spread certificate program will just have the email address as the identity, and it will be authorized by establishing control of the email (just like the majority of certificates used for https are domain control only, no organizational verification, not that organizational verification means much anyway). Anyway, identity is hard; there are many people with my name, including a Pulitzer winning author.