[ih] mail security, was Meta: attachment policy (was Re: clever usc creation)
John Levine
johnl at iecc.com
Sun Jul 19 05:31:05 PDT 2026
It appears that Jack Haverty via Internet-history <jack at 3kitty.org> said:
>But few users of the Internet use, or perhaps even know how to use, or
>that they should use, such technologies. Personally, all of my emails
>are digitally signed, but I rarely see signatures on incoming email.
>Perhaps that's because few know how to use it. Perhaps it just doesn't
>work. Perhaps it has serious flaws, such as the fact that passing
>through a "forum" such as this one invalidates a digital signature,
>making it ineffective and looking like a forgery. Perhaps no one thinks
>it's a problem to address.
We became painfully aware of the mailing list digital signature problem a decade
ago when AOL and Yahoo, which were then separate, each published a DMARC
p=reject policy which made large amounts of the mail their users sent through
mailing lists bounce. They'd each had user records stolen which let crooks send
their users spam pretending to be from a friend of the recipient. This led to
vast numbers of user complaints, which the p=reject fixed at the cost of
oursourcing the costs of their security failures to the rest of the Internet.
Since then we came up with ARC which was intended to log a message's security
history as it went through things like mailing lists, but turned out not to work
because the ARC chain was too easy to forge. Now the IETF DKIM working group is
designing DKIM2 which is sort of like ARC, but with a signed chain of message
changes that recipient systems can mechanically verify and look back through
mailing list changes. All of the large mail operators are involved in this so
the chances of it getting adopted in practice are high.
S/MIME and PGP have been around since the last millenium but as you note, hardly
anyone uses them, which tells us that they're unusuable. I think that's because
their key management problem is intractable and the practical benefits for most
people are marginal. They are intended to be "end-to-end", but these days most
people send and read mail through webmail or mobile apps controlled by their
mail operators, not the individual user, so I have no idea what end-to-end even
means any more.
We have made some progress. DKIM really works for mail sent directly from the
sender to the recipient which is the vast majority of mail most people get. If
any ISOC employee sends you mail, the message has an isoc.org DKIM signature
which is a strong indicator that it's really from them. Most other mail systems
including all the big ones add DKIM signatures, too.
R's,
John
More information about the Internet-history
mailing list