6 ms·
Anyone willing to share opinions on BIMI? I’m wondering if it is worth it for most medium-large organization or if this is specifically worth it if you are doi
by hashstring 3y ago
Anyone willing to share opinions on BIMI?
I’m wondering if it is worth it for most medium-large organization or if this is specifically worth it if you are doing a lot of commerce and sending e-mails to customers etc.
Furthermore, (stating the obvious) DKIM, SPF and DMARC are also implemented by malicious parties and only authenticate that the server was allowed to send using a particular domain name. BIMI seems to require a VMC (Verified Mark Certificate). Is this verified and is it effective in preventing unauthorized parties from BIMI verifying their domains using stolen brand logo’s etc.
Also, is Microsoft Outlook (still) not supporting/adopting BIMI?
- layer8 3y agoAs an end user, this is gimmicky to me, and I wouldn’t want to use an email client that causes the respective emails to appear more prominent by showing their BIMI logo. It would be similarly annoying as emojis in the subject line.
- Avamander 3y agoA lot of mail clients do display it though. Plus it does help the average user differentiate between rnicrosoft.com and microsoft.com, I'd guess.
- brightball 3y agoHappy to. BIMI is worthless. It's a carrot to get your marketing department on board with setting up DMARC because they are the most likely to push back due to fears of the project affecting their email deliverability. You have to fully deploy DMARC to setup BIMI. Now, BIMI and the costs to "verify" your mark is pushed by exactly the same people who tried to sell you extended validation SSL that would turn your browser address bar green when you visited a site that had gone through this verification. Just like with EV SSL, BIMI has no positive impact on user security. They're just as likely to open / not open an email with BIMI as they are to visit a site with or without EV SSL. In some cases, it's actually worse. The only benefit to BIMI is it gives you another place for the marketing department to stick the logo so they'll stop fighting the DMARC rollout. That's it. Otherwise it's total waste of money and time. Wrote about it here: https://www.brightball.com/articles/enterprise-challenges-with-dmarc-deployment https://www.brightball.com/articles/enterprise-challenges-wi...
- hashstring 3y agoThank you for the info! DMARC roll-out in itself could also attract the marketing department because it improves deliverability under the hood. I also think implementing SPF, DKIM and DMARC can be done without compromising availability by planning and monitoring well.
- albertgoeswoof 3y agoHere’s what we wrote about BIMI. Some selected excerpts: > To ensure that logos are actually truly representative of the brand involved, and more cynically, to make money and penalize small senders, an optional Verified Mark Certificate can be added to the DNS records, which some mailboxes will validate before showing the logo. > Unfortunately VMC certificates cost upwards of $1000 USD to purchase. Which puts them out of reach for casual or small senders (of which we are big supporters here at MailPace), and undermines the BIMI effort overall. https://blog.mailpace.com/blog/what-is-bimi/ https://blog.mailpace.com/blog/what-is-bimi/
- chedabob 3y agoWhile there's multiple competing standards I'm ignoring it. At least with MTA-STS and DANE you didn't have to fork out $1000+ to support both. There was also this which showed up a month after Google started their rollout of the BIMI checkmark: https://twitter.com/chrisplummer/status/1664075886545575941 https://twitter.com/chrisplummer/status/1664075886545575941
- Avamander 3y agoMTA-STS and DANE are not fulfilling an even remotely similar purpose. Plus nobody significant really follows/uses DANE, because how shit DNSSEC is.
- starfox64_ 3y agoI think it's a good initiative, it's obviously there for CAs to make a buck but it's finally a way to arguably curb phishing emails that rely on similar domain names or IDN characters all the while making your brand identity more prominent. It seems to also have learned from one of Extended Certificate's shortcomings by relying on trademark instead of company name. I actually wish something similar was created to replace EV certificates as it's easier than ever to perform phishing attacks now that everyone and their grandmas has a DV certificate on their site (which is a good thing).
- crote 3y agoTrademarks still aren't 100% unique, though. For example, Apple Records is easily confused with Apple Music - both have a similar name, and both use an apple as logo. It is better, but not foolproof.
- torgard 3y agoYes, but Apple Records aren't going to be phishing Apple Music customers. Phishers won't be applying for trademarks to impersonate Apple.
- pnpnp 3y agoWhy not?
- Avamander 3y agoExpensive, you'll leave a paper trail, get shut down rather quickly. There's little to no profit that can be made like that.
- hashstring 3y agoRegistering a domain and hosting a phishing website usually comes at a small price (around 10$) which is just 1% of the VMC (I just learned that). “Expensive” is very subjective, I think it highly depends on the financial standard of the actor and the expected value. In the case of Apple: if it is expected to aid in phishing an interesting iCloud user, or scamming 100 users for 10$, then I expect that there will be actors that will pay this initial cost to make more later on. I agree that the classic mass-mail LQ phish actors would probably not go here, but the same holds for smaller organizations. With the current price-tag, end users then still have to trust non-BIMI and BIMI verified e-mails daily. That seems to leave plenty room for phishing. Also, if VMC prices drop, it will also attract more phish actors. Though I see your point, I do not think that a financial bar is effectively combatting phishing. I do not know how valid the paper trail concern is; I haven’t gone through the VMC procedure(s).
- Avamander 3y agoIt's helpful to raise the priority on fixing DMARC in an organization. It is annoyingly expensive, but I'm expecting it to change with additional CAs entering the market. Very "EV" vibes though, but it is literally for that, so. End users might also appreciate something nicer than autogenerated one-letter icons. Matter of taste. It also makes phish stand out more than usual, if the user has grown accustomed. We'll see its efficacy long-term though, too early to say.
- jeroenhd 3y agoBIMI solves various problems DMARC/DKIM/SPF still leave open. In that sense, I applaud the initiative. The $1000 certificate makes it unusable for anyone but the most annoying marketeers, though. Any EV certificate would've worked to serve the "business verified by a trusted third party" requirement, but CAs being CAs, they had to invent a new certificate for business reasons. The process is further complicated by leaving it open to recipient servers whether or not they actually trust you after buying the special certificate. This does make sense for the small number of companies actually using BIMI, but it does hurt the scalability of the solution.
- crote 3y agoBIMI looks to be exactly as broken as EV, in that it assumes that company names and logos are unique - which they are not. It also suffers from the vast majority of legitimate emails not having it. The only people who benefit from BIMI are the ones selling the quite expensive certificates.