Welcome | Sign In
ECommerceTimes.com
Security

IETF Conference Debates Antispam Proposals

Print Version
E-Mail Article
Reprints
IETF Conference Debates Antispam Proposals

"The spam issue has created enough urgency and even desperation, so ... there's been a rush to market to get solutions into place and experiment with them and let their strengths and weaknesses come out through real-world trials," Gail Goodman, CEO of Constant Contacts, told TechNewsWorld.


How Much is 'Free' Costing You?
Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.

The recent rush to adopt technologies for countering e-mail abuses like spam and phishing could pose a dangerous threat to freedom on the Internet.

"These proposals are extremely dangerous," Eric Johansson, a networking consultant for the TriArche Research Group in Cambridge, Massachusetts, told TechNewsWorld.

"We're at the decision point right now of whether or not we're going to have a relatively free and open Net for e-mail Increase Customer Sales with Email Marketing -- Free Trial from VerticalResponse or [whether it is] going to be centrally controlled," he added.

Johansson explained that the prominent e-mail authentication technologies being pushed in the online community at the moment attempt to identify a sender and create a mechanism for shutting off that sender should he or she misbehave. "That's a threat to free speech because if you can shut off a spammer, you can shut off anybody," he said.

Johansson is working on his own decentralized authentication scheme that involves electronic "franking" of e-mail.

Authentication Desperation

Dangerous or not, the movement to adopt authentication technologies is rapidly gaining momentum. And in the rush to attack e-mail malpractitioners, corners are being cut.

At a conference of the Internet Engineering Task Force in Seoul, South Korea, this week, supporters of a technology called Sender Policy Framework (SPF) -- designed to counter common ploys used by unscrupulous spammers, including e-mail address spoofing and mail-server hijacking -- will push for expedited approval of that technology as an Internet standard.

"The spam issue has created enough urgency and even desperation, so rather than following traditional standard-setting practices where different proposals are hashed out at lengthy and infrequent meetings with standards bodies, instead there's been a rush to market to get solutions into place and experiment with them and let their strengths and weaknesses come out through real-world trials," Gail Goodman, CEO of Constant Contacts of Waltham, Massachusetts, an e-mail marketing service and charter member of the Email Service Provider Coalition, told TechNewsWorld.

Proposal Proliferation

This experimental approach already has led to a proliferation of announced solutions. In addition to SPF, there's "Caller ID" backed by Microsoft (Nasdaq: MSFT), DomainKeys being developed by Yahoo (Nasdaq: YHOO), and PostX, another antispam authentication technology.

Although SPF and Caller ID have been characterized as potential competitors, that's not the case, according to Meng Weng Wong, chief technology officer of Pobox.com, an e-mail service firm in Philadelphia.

"Caller-ID and SPF are not actually in competition, despite what the media say," Wong told TechNewsWorld via e-mail.

Different Problems

Wong explained that the technologies try to solve two different problems. The problem Caller-ID targets is phishing. In phishing, spammers forge authorship of a message to convince readers that the message is from, for example, eBay (Nasdaq: EBAY) or PayPal -- and to get their hands on a user's credit card number.

The problem SPF tries to solve is joe-jobbing. When spam e-mails, worms and viruses send malicious payloads, they do so using a forged envelope sender or forged return-path, which is where bounces go. When millions of spam e-mails go out, some of them go to undeliverable addresses, and those bounces end up in the mailboxes of innocent third parties because the reply-to addresses have been forged.

"Both are real problems, and both deserve solutions," said Wong. "There is no one solution to spam; the approaches are complementary and will work together."

Immediate Action Needed

Any widespread change to e-mail will take years to implement, noted Sean Eldridge, director of product marketing Download Free eBook - The Edge of Success: 9 Building Blocks to Double Your Sales strategy at PostX Corporation in Cupertino, California.

"In the meantime, something must be done to address the problem today because it is an epidemic that's growing month by month," he told TechNewsWorld.

PostX will pull the wraps off its e-mail authentication technology in the second quarter of this year.

Asked if Internet authorities should consider junking the existing e-mail protocol -- SMTP -- and creating a more secure one, Eldridge responded: "No. I still believe e-mail is the killer app.

"E-mail is such a part of our daily way of life, right behind the telephone as our most popular form of communication, I think it would be virtually impossible to destroy it," he continued. "But if this problem keeps escalating, there will be an impact on e-mail as a mode of communication."


Print Version E-Mail Article Reprints More by John P. Mello Jr.


More by John P. Mello Jr.

VMware Fuses Performance With Convenience
November 16, 2009
Fusion 3.0, the latest virtualization app from VMware that lets Mac users run Windows alongside OS X, puts an emphasis on performance. VMware built it specifically to leverage the 64-bit capabilities of Snow Leopard with a new 64-bit native engine. Its Migration Assistant for Windows lets Mac switchers recreate their old Windows PC inside a Mac, file by file.
Mouse Meets Multi-Touch
November 09, 2009
Apple's latest peripheral, the Magic Mouse, takes the concept of multi-touch that the iPhone and iPod touch popularized and merges it with a button-free mouse. As one's mouse is a direct point of contact between human and machine, any changes made to it can be a divisive issue. Some users love the new abilities Magic Mouse brings to the table; others just can't stand the thing.
Samsung Intrepid: Sleek Hardware Makes Up For Uncomfy OS
November 09, 2009
Samsung has built its Intrepid smartphone with a solid set of hardware. Its physical keyboard is comfortable for thumb-typing, and its camera sports a number of advanced features for a phone cam. The Windows Mobile 6.5 OS it's saddled with can be uncomfortable and unintuitive at times, but it may be at least a familiar interface for the business users the Intrepid targets.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network