By Jay Lyman TechNewsWorld Part of the ECT News Network
11/15/04 11:44 AM PT
There are several technologies similar to DomainKeys, including Cisco's Identified Internet Mail and Microsofts's SenderID. But the technology that is deployed most frequently will be the winner. "Sometimes, the better solution is the one that's simply there," said analyst Joyce Graf.
Success is just a matter of knowing the right "secrets." Download the free eBook, "The Edge of Success: 9 Building Blocks to Double Your Sales." You will discover the fastest, most effective ways to grow your business and still have time to live your life.
Yahoo (Nasdaq: YHOO) announced enhancements to its e-mail service, adding search, more
storage and its DomainKeys sender authentication technology -- which is also
being deployed by Internet service provider EarthLink (Nasdaq: ELNK) in a test roll-out.
While the news of the DomainKeys deployment was welcomed by most, there
were also calls for the different methods of validating e-mail sender
identity to be merged in order to adequately address spoofing.
Security and spam experts report a rise in the incidence of spoofing -- faking the
"from" address -- and related online scams and crimes such as phishing, or
baiting users into divulging information with official-looking solicitations
and sites.
"Eventually, I think their ideas will be piled into one, but for now,
it's just a matter of them jockeying to see who owns it," said industry
analyst Joyce Graf. She told TechNewsWorld that the DomainKeys rollout was "on
the right track."
Deployment Key
Yahoo, which also announced a free e-mail storage boost to 250 MB and
e-mail search and transfer capabilities, said its DomainKeys will provide
increased protection from spammers who use spoofing to
steal information or damage reputations.
Although Graf said that DomainKeys will likely go through an awkward period because it is new, she lauded both the technology, which operates as a sort of caller ID for e-mail, and the consortium behind
it.
The similar
Microsoft-backed SenderID scheme is similar, but the technology that is deployed most frequently will
likely be the winner. "Sometimes, the better solution is the one that's simply there," Graf
said.
Identity Variety
DomainKeys is a sender validation technology that relies on public/private
key cryptography to verify the sender of an e-mail message at the domain
level, Yahoo said. A sending system uses a private key to generate a
signature and inserts it into the e-mail header. The receiving e-mail system
then uses the public key, published in the Domain Name System, to verify the
signature.
Basex chief analyst Jonathan Spira told TechNewsWorld there are several
similar technologies that accomplish the same thing, including Cisco's (Nasdaq: CSCO)
Identified Internet Mail and the SenderID. That method, which checks
the IP addresses of the servers in domains, recently moved ahead with
release of a second version of the specification, Spira said.
Spira said there is a need for both technological and organizational synergy
on the spoofing issue, which has tarnished e-mail as a communication medium.
"In order for the industry to move ahead, we need one merged technology
in order to ensure interoperability and greater control, as well as one
centralized authority to turn to," he said.
Spira, whose firm estimates spam costs business around the globe more
than US$20 billion each year, said service providers such as Yahoo are also
being forced to lower the rate at which spam slips into e-mail accounts.
"The cost is simply too high otherwise," Spira said.
Major Support
Spira, who noted that Google (Nasdaq: GOOG) is also using the DomainKeys technology
for its e-mail service, said the test by EarthLink comes after a Federal
Trade Commission/NIST summit held last week.
The summit "seemed to prompt all of these previously unplanned tests and
announcements," Spira said. "EarthLink is only in the testing phase, whereas
others are already using the technology.
"However, Earthlink is the first major ISP to announce a test," Spira
said.
EarthLink, which recently rolled out its free ScamBlocker software to
guard customers against phishing attacks, said it is testing DomainKeys to
determine how it can best implement the solution.
Last year, EarthLink was the first major ISP to provide a
permission-based spam-fighting tool, spamBlocker, to block unwanted junk
mail, the company said.
Will Antiphishing Legislation Be Effective? November 13, 2004
James Gildea, director of marketing for e-mail management firm IntelliReach, does not put much faith in such legal proposals. He sees attempts to legislate curbs on phishing attacks as having much the same results as recently enacted antispam laws. "To date, 32 states have enacted antispam laws. These laws haven't done much to stop the flood of spam," he said.
Related Stories
Dow Jones Buys MarketWatch; Yahoo Snags WSJ Editor November 15, 2004
Yahoo might believe that having its own source of content is a competitive necessity as portal wars with MSN and AOL grow. AOL has the advantage of a deep pool of Time Warner content from which to draw. Under CEO Terry Semel, who has a Hollywood background, Yahoo has struck content deals with the likes of Sony and others.
Yahoo Enters New Arena November 14, 2004
"I give Yahoo a tremendous amount of credit for recognizing the shift in distribution of films and music from the physical to digital," Phil Leigh, senior analyst for Inside Digital Media, a firm that follows the Internet entertainment industry, said. "What we are seeing is a beginning, just like cable programming in the early 1980s."
Phishing Without a Lure November 04, 2004
While the victims of the latest phishing technique may not have to click on a link to be victimized by the effort to steal information, the attack is similar to traditional phishing scams because it is dependent on a Web site to capture the data. That fact cuts down the level of threat.
Related News Alerts
More by Jay Lyman
Open Source Developer Dumps Novell Over Microsoft Deal December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0 December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.