Trent Adams's Library tagged → View Popular
24 Apr 09
A Few More Thoughts on Email Authentication… errr… Trust
-
For authentication to be useful, you also need some sort of evaluation mechanism, whether an ad hoc, private whitelist or a trusted, third-party assessment service. Authentication is only one component of a trust service. This, of course, leads to a chicken-and-egg problem trying to get adoption by parties who might not see concrete benefit anytime soon. While the mechanics and operation of authentication are well understood, they aren't cheap to implement. Absent an immediate value proposition, why should an organization go through the expense? Operations folk are not usually swayed by vague promises of eventual benefit. So what are the specific, immediate assessment, whitelist, reputation, certification benefits available for an adopter of DKIM or SPF? Absent a meaningful assessment mechanism, the answer is: none.
-
The simplest is application of classic Bayesian content analysis, to develop a reputation history for a particular identifier. Perform the usual types of statistical evaluation of a stream of messages having the same signature. You will quickly formulate an assessment. If your assessment is negative, you are in the unusual position of knowing who to complain to: Since the message stream is authenticated, there is an explicitly and reliably specified responsible party. If your assessment is positive, you can start treating that stream differently (and better) than messages lacking authentication.
- 1 more annotations...
1 - 2 of 2
Showing 20▼ items per page
Sponsored Links
Ads by Google
Top Contributors
Groups interested in authenti...
Related Lists on Diigo
-
LDAP Authentication
Creating a tie to LDAP via php
Items: 4 | Visits: 18
Created by: Colby Smart
-
RADIUS/OS X
Items: 1 | Visits: 1
Created by: Jeff Johnson
Diigo is about better ways to research, share and collaborate on information. Learn more »
Join Diigo
