Agility Loop

    • Edit
    • Delete
    • Tags
    • Autopost

    Government Behind the Times on Email Authentication

    Today in GCN, there is an article entitled Industry group gives government a failing grade in e-mail authentication -- Government Computer News.  The main thrust of the article is detailing how most Government domains do not support any type of email domain authentication such as Sender ID or DomainKeys.
    E-mail authentication technology, usually transparent to the end user, lets servers verify that e-mail traffic is indeed coming from the domain or sender that it purports to be from, and that the sender is authorized to use that domain. The OTA study showed that only 11 of 25 government domains examined use such authentication. A similar study of top commercial sites showed that the private sector is doing a little better, with 55 percent using some form of e-mail authentication.
    To be fair, the private sector isn't doing so great either at 55%. What I find particularly ironic is that much of the government is ahead on PKI and other security technologies.  It seems like this would be a pretty easy solution to combat spam and phishing attacks.  I know in the past we have discuss using simple SMTP over SSL.  This would at least buy security of SMTP mail transfer, and authentication of domains (although it would be difficult to use with external email domains).  However, technology like DomainKeys (which Yahoo uses) is a more versatile solution than SMTP over SSL.  Hell it's even open source, so costs COULD be minimal.
    Tags » PKI Security authentication email smtp
    • 15 April 2009
    • Views
    • 0 Comments
    • Permalink
    • Tweet
    • 0 responses
    • Like
    • Comment
  • Kevin Heald's Space

    I grew up as a techie and first got hooked using an old Texas Instruments programming in Basic ("Hello World" app is my fav) and then learned the fun of "integration" making my PCjr actually run the old Sierra games I wanted to play. After a lot of fun at college, I found myself entrenched in the government technology world leading projects and integrating systems for the past 11+ years. I have extensive experience in technical project management, Public Key Infrastructure (PKI), Collaboration Technologies, Information Sharing, and Secure Systems Integration.

    Archive

    2012 (10)
    May (3)
    April (1)
    February (1)
    January (5)
    2011 (12)
    December (5)
    November (5)
    October (1)
    May (1)
  • About Kevin Heald

    I grew up as a techie and first got hooked using an old Texas Instruments programming in Basic ("Hello World" app is my fav) and then learned the fun of "integration" making my PCjr actually run the old Sierra games I wanted to play. After a lot of fun at college, I found myself entrenched in the government technology world leading projects and integrating systems for the past 11+ years. I have extensive experience in technical project management, Public Key Infrastructure (PKI), Collaboration Technologies, Information Sharing, and Secure Systems Integration.

  • Subscribe via RSS
  • Sites I Like

    • Lifehacker

    Follow Me

      TwitterFacebook

Theme created for Posterous by Obox