3 ms·
I get they don't use gmail for their own email... I'm thinking more about s/mime and really why aren't companies emailing their account holders with signed emai
by rubyfan 12y ago
I get they don't use gmail for their own email... I'm thinking more about s/mime and really why aren't companies emailing their account holders with signed email.
When I get an email from my bank why doesn't it have any sort of authentication so I know it is from my bank and not someone pretending to be my bank.
- dangrossman 12y ago> When I get an email from my bank why doesn't it have any sort of authentication so I know it is from my bank and not someone pretending to be my bank. It probably does, but the mechanisms are directed at MTAs and not displayed to end-users. http://en.wikipedia.org/wiki/DomainKeys_Identified_Mail http://en.wikipedia.org/wiki/DomainKeys_Identified_Mail http://en.wikipedia.org/wiki/Sender_Policy_Framework http://en.wikipedia.org/wiki/Sender_Policy_Framework They're the reason all the phishing spam that looks like it's from your bank ends up effectively spam filtered, while real mail from your bank makes it to you. All of the top 10 US banks have SPF/DKIM set up.
- rubyfan 12y agoSure SPK will stop someone from falsely sending from my bank's domain and I get that most email providers will use SPK and other frameworks. Those frameworks really don't stop anyone from sending phishing email where the sender is poorly hidden but the email body looks real. I get stuff from "PayPal" all the time... None of which are from PayPal. Why can't I get a little lock icon like I have in my browser with the name of the signing party? What really is the barrier for something like this? Why do we demand this for outgoing connections to these institutions through our browser but not for inbound communications like email?
- johntash 12y agoDKIM is essentially signing outgoing e-mail at the server-level. Receiving MTAs are supposed to verify the signature using the public key available through DNS. I can't find any examples now, but I swear I've seen gmail say "Verified Sender" or something to that extent on some random messages I've received before. I don't know if that was due to domain keys or something else.. This would still only be signing; I agree it'd be better if e-mail was more commonly encrypted.
- rubyfan 12y agoYeah, I mean mua based message encryption is totally doable from sender to receiver but apparently too confusing, ie. GPG/PGP. I kinda buy that as a UX problem if I assume most people are not technical enough to understand how PKI works. mta transfer encryption probably needs more uptake and plugging of simple degradation attacks that cause transfers to flow unencrypted - in my opinion having providers do this for us is a losing battle. But considering S/MIME is likely the lowest acceptable form of email authenticity, why don't we have an interest in progressing the adoption of this technology?