July 11, 2005 3:35 PM PDT

Antispam spec sets off on path to standard

Related Stories

Antispam proposals advance

June 29, 2005

Yahoo, Cisco team on antiforgery tech

June 1, 2005
An antispam technology that focuses on identifying forged e-mail addresses has been proposed as a standard by Cisco Systems, Yahoo and partners.

The companies, along with software makers Sendmail and PGP, submitted their DomainKeys Identified Mail specification to the Internet Engineering Task Force this weekend. The IETF, a standards setting body, is expected to start discussing the technology during its meeting at the end of July in Paris, a Yahoo representative said on Monday.

With DKIM, which relies on public key cryptography, a digital signature is attached to outgoing e-mail so recipients can verify that the message comes from its claimed source. The idea is to make it easier to eliminate spam or phishing e-mails with spoofed addresses by marking out legitimate messages. The specification merges two earlier proposals, Yahoo's DomainKeys technology and Cisco's Internet Identified Mail system.

"This is a big milestone for us and the e-mail authentication world," said Miles Libbey, an antispam product manager at Yahoo Mail. "This submission to the IETF represents collaboration between a lot of players in the e-mail authentication world." Other companies involved include Alt-N Technologies, America Online, EarthLink, IBM, Microsoft and VeriSign, Yahoo said.

Standardization of a technology is important for its acceptance. Nonstandard technology is not likely to be implemented in products or adopted by users. The IETF will likely establish a working group to further debate DKIM, the Yahoo representative said.

The specification calls for e-mail domain owners to create a pair of public and private cryptographic keys. The public key is published in the Domain Name System record, while the private key is stored on a DKIM-enabled mail server. Each outgoing message is then signed, with the signature stored in the e-mail header.

On the receiving end, a DKIM-enabled mail server extracts the signature and uses the public key to verify that the signature was generated by the sending domain.

The announcement of the IETF submission comes a day before the start in New York of the Email Authentication Implementation Summit 2005, where experts will discuss e-mail security technology and encourage its adoption.

At the event, attention is likely to turn to another e-mail security technology, Sender ID, which has Microsoft as its main backer. The Sender ID specification is making its way through the standards process.

Sender ID and DKIM have similar goals: to improve the security and reliability of e-mail and to stop the tide of spam, phishing and e-mail fraud. The technologies can work side by side, Yahoo said.

Yahoo first submitted DomainKeys to IETF last March. The new submission is for the merged technology with Cisco. The partners now have some real-world examples of DKIM at work, the Yahoo representative said.

See more CNET content tagged:
DomainKeys, Sender ID, e-mail authentication, e-mail security, submission

Add a Comment (Log in or register) 6 comments
YAY! ITEF Rocks!
by Bytesmiths July 11, 2005 6:55 PM PDT
Stamp out proprietary, controlled solutions!

Where can I sign up? I get THOUSANDS of spams a week!
Reply to this comment View reply
YAY! ITEF Rocks!
by Bytesmiths July 11, 2005 6:55 PM PDT
Stamp out proprietary, controlled solutions!

Where can I sign up? I get THOUSANDS of spams a week!
Reply to this comment View reply
One major disadvantage compared to SPF
by hadaso July 12, 2005 2:19 PM PDT
One major disadvantage compared to SPF is that Domain Keys requires that email headers be received before the sender's address can be authenticated, which is rather late in the process. SPF is better in that as soon as the sender's envelope address is given it can be authenticated, before any part of the message is passed. SenderID suffers from the same disadvantage.

And all of these systems suffer from the basic design, which is trying to authenticate the wrong data: the sender's alleged address. The only part of an email transaction that cannot be forged if the email transaction is to succeed is the recipient envelope address, and this is the data that should be used to authenticate that email received is wanted.
Reply to this comment
One major disadvantage compared to SPF
by hadaso July 12, 2005 2:19 PM PDT
One major disadvantage compared to SPF is that Domain Keys requires that email headers be received before the sender's address can be authenticated, which is rather late in the process. SPF is better in that as soon as the sender's envelope address is given it can be authenticated, before any part of the message is passed. SenderID suffers from the same disadvantage.

And all of these systems suffer from the basic design, which is trying to authenticate the wrong data: the sender's alleged address. The only part of an email transaction that cannot be forged if the email transaction is to succeed is the recipient envelope address, and this is the data that should be used to authenticate that email received is wanted.
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Samsung contemplating SanDisk acquisition

    South Korean consumer electronics giant is considering a buyout of the chipmaker to reduce its NAND flash memory costs, according to PaidContent.

  • Gallery

    Photos: Ron Paul's RNC alternative

    As the Republican convention took place just miles away, a crowd rallied for the former presidential candidate and his message of limited government, ensured civil liberties, lower taxes, and peace.

  • The Open Road

    Analysts as a lagging indicator of success

    Gartner, Forrester, and other analyst firms tend to be great predictors of the past, probably because that's where they get their money.

  • Beyond Binary

    Memo: Windows chief on new ads

    Windows business unit head Bill Veghte send a memo to troops late Thursday promising that the debut Seinfeld/Bill Gates ad was just an "icebreaker."

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Digital Media

    About time: Joost to launch browser-based player

    Company's desktop client failed to catch on with the public, so the Web video service is retooling, but is it too late to catch up to Hulu and Google's YouTube?

  • Video

    Political party playlists

    We know the Democrats and Republicans are split over policy issues, but does their musical taste fall down party lines too? And what kind of gadgets did they bring to the conventions to listen to their music? CNET reporter Kara Tsuboi finds out.

  • News - Politics and Law

    Google and 'Vanity Fair' party with the GOP

    Google and Vanity Fair hosted one of the most talked-about parties at the Republican convention.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Photos: The brains behind Google Chrome

    Here's a look at some of the engineers and executives who took the stage at the company's headquarters as they unveiled the new browser.

  • Gadgettes, the blog

    Gadgettes 105: The Sing, Sing a Song Episode

    We have music on the brain in today's episode of Gadgettes. Don't worry, we won't destroy your ear drums with ear-piercing renditions of your least favorite '80s tunes. Instead, we'll soften the blow with a slew of musical gadgets and accessories.

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.