Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

E-mail authentication: Cost, standards remain problems

"Fragile nature" of DNS could hamper spam protection

By Grant Gross, IDG News Service
November 10, 2004
 

WASHINGTON - E-mail authentication can help fight the growing spam e-mail problem, but vendors need to come up with a single, open standard to avoid confusion and crippling costs for small ISPs (Internet service providers), participants in a U.S. government summit said Wednesday.

Free IT resource

Hear how top CIOs turn change into a competitive advantage.

Sponsored by HP

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

The security of the DNS (the Internet's Domain Name System), on which some leading e-mail authentication proposals are built, was also called into question at the conference, hosted by the U.S. Federal Trade Commission (FTC) and the National Institute of Standards and Technology (NIST). Holes in the DNS, which translates numeric addresses into readable Internet domain names, could allow spammers to enter false authentication information, said Scott Chasin, chief technology officer of MX Logic Inc., an e-mail filtering company.

"I believe the fragile nature of DNS will affect those trying to thwart e-mail authentication schemes," Chasin said.

MX Logic supports efforts to create e-mail authentication, but Chasin also called for the widespread adoption of DNS Security Extensions (DNSSEC), a security project that's been in the works for a decade, and is now being approved by the Internet Engineering Task Force (IETF). "(Authentication) is not a cure-all for spam," he added in an interview. "It is not a cure-all for phishing."

Participants in the summit seemed divided about the potential of e-mail authentication that would establish DNS rules to allow e-mail recipients to receive e-mail only from trusted senders. Such authentication schemes would be based on a reputation system, similar to so-called white lists, in which e-mail from certain domains, such as Yahoo.com or IBM.com, would be cleared as legitimate e-mail. There could be multiple reputation systems run by multiple companies or organizations.

Elizabeth Bowles, president of the 40,000-subscriber ISP Aristotle.Net Inc., raised concerns about at least six e-mail authentication proposals moving forward, including Sender ID, advanced by Microsoft Corp., and Sender Permitted From (SPF), being used by America Online Inc.

Small ISPs can't afford to configure their e-mail to comply with a variety of authentication standards, she said. Bowles and others who had concerns about e-mail authentication noted that various proposals require ISPs and Internet domain owners to publish different types of DNS records to comply with authentication standards.

"We can't have AOL implementing one system, and Microsoft implementing another, and everyone having to comply with a bunch of different standards," said Bowles, whose company is based in Little Rock, Arkansas. "It has to be unified."

E-mail authentication standards should be easy to implement and the solutions should be easy to tailor to an ISP's needs, she added. "I don't think it can have a part of it that's proprietary, that would require us to basically get a license for a piece of software that we couldn't subsequently modify or improve," she said. "If it is proprietary, at least it needs to be open, and it needs to be a flexible system."

Despite these concerns, others at the summit said e-mail authentication represents the best hope for senders who want to distinguish their e-mail from spam.

Small Internet-based businesses are "getting slammed from all sides" because of spam, and members of the International Council of Online Professionals, a trade group for small online businesses, would welcome a way for their e-mail marketing campaigns to be tagged as legitimate e-mail, said Dawn Rivers Baker, a founding member of the council.

Small businesses engaging in marketing campaigns have to fight being labeled as spammers by customers who have forgotten they signed up for the e-mail, Rivers Baker said. Other members of the council have to deal with disgruntled customers who have paid for a newsletter, but had that newsletter labeled as spam and blocked by an ISP.

"We will jump through all of the hoops that you tell us to jump through," she said. "You want us to publish 57 records, you bet. You want us to encrypt, we will do that, too. You want us to tango, we will tango."

A recent study conducted by Return Path Inc., an e-mail services provider, found that 18 percent of legitimate e-mail was blocked by the top 10 ISPs, said J. Trevor Hughes, executive director of the Email Service Provider Coalition, which represents 52 companies. For some companies that use e-mail marketing, that's a cost of doing business, but for an e-commerce site sending a shipping confirmation, or a telephone company sending a phone bill, those blocked e-mails are a problem, Hughes said. An e-mail authentication standard could solve some of those problems, he said.

Many of the concerns voiced at in the FTC summit will be easily addressed, said David Anderson, chief executive officer of Sendmail Inc., which supports Microsoft Corp.'s Sender ID e-mail authentication initiative. Anderson estimated that the cost of establishing a good reputation in authentication schemes will be small. In most cases, domains will establish reputations with each other, and individual e-mail users will not need to comply with multiple authentication schemes, he said.

"It you are an established (e-mail) user, you will find it almost impossible not to establish a reputation," he said.





 

TOP NEWS:


»  Antitrust review of Google-Yahoo deal no surprise
While serious antitrust problems are unlikely, both Google and Yahoo expected their partnership to be subjected to instense DOJ scrutiny

»  Top 10: Coreflood, more Microsoft-Yahoo, iPhone plans
This week's wrapup of the top tech news stories includes more Microsoft-Yahoo rumors, iPhone updates, Flash searches, Oracle's BEA roadmap, and more

»  Four 'important' Microsoft patches due Tuesday
Not rated "critical," fixes apply to "Elevation of Privileges" and "spoofing" bugs for Windows, Exchange, and SQL

»  Judge grants RIM a stay in Visto patent trial
Trial delayed from beginning next week while patent office studies validity of certain parts of e-mail provider Visto's patents as requested by RIM

»  Developers satisfied with Apple's enterprise work
Mac developers feel that Apple shouldn't try to make a broad attempt to win over enterprises and should instead focus on certain areas within the enterprise

»  Opera patches multiple bugs in flagship browser
Opera 9.5.1 fixes several flaws, including one ranked 'highly critical'




Solutions to the Toughest IT Challenges in Remote Offices
Though small in size, remote offices face many of the same IT challenges as larger central offices. This Webcast zeroes in on the top line challenges to deliver information that can provide immediate benefits to your business. Sponsor: AMD and Dell

»  Click here to view this Webcast
  Zombie PCs Are Attacking Your LAN
A recent study showed that malware-infected zombie PCs are now a bigger threat to ISPs and Web infrastructure than DoS attacks. As this brand new IT Strategy Guide explains, an increased use of peer-to-peer techniques by the attackers has made it harder to fight back. Download now, compliments of Verio:

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist