Attacks on Email Sender Authentication
blackhat.com
blackhat.com
One of the authors of the research, Jianjun Chen, demonstrates email spoofing using Gmail, Yahoo and Outlook in these short (1 min) videos from 2020.
Email spoofing demos (2020): https://www.youtube.com/playlist?list=PL--A-gWJV1dJ19Syhkzkl...
Status:
- Gmail: "fixed"
- Yahoo: "reported to Yahoo security on Oct 28th, 2019. They disregarded our report."
- Outlook: "reported to Microsoft security on Oct 28th, 2019. They disregarded our report ("Unfortunately your report appears to rely on social engineering to accomplish, which would not meet the bar for security servicing")."
I assume the response from the Outlook team ("social engineering") refers to the fact that body of the email must still contain a phishing link.
If you want to authenticate an individual email sender then that sender would sign their email. Just like with paper mail. Sure you can try to determine if the sender is legit by looking at the postmark on the outside of the envelope but that is not what it is for. The result will and can not be reliable.
SPF is Sender Policy Framework.
Something like "Originating Entity Policy Framework" might be more correct.
Posted article uses "Sender" for the user, not the entity. Authentication inside the entity is the entity's responsibility. SPF is only concerned with verifying that the mailhosts offering to deliver messages on behalf of entity are allowed to do so.
Email being a distributed system, the responsibility of identifying the sender is shared, and if implemented property works well.
The job of the client and recipient server is to verify the domain of the sender, according to rules defined by the sender.
The job of the sender server is to authentify the user account.
Implementing things properly is hard...
https://news.ycombinator.com/item?id=29942900 (it's not my post, but it was the first one here and deserves a comment or two as it is interesting IMO)
https://www.youtube.com/watch?v=xxX81WmXjPg
I've always just checked for an @ and be done.
The use of email for important matters leads to Business Email Compromise fraud:
https://www.fbi.gov/scams-and-safety/common-scams-and-crimes...
This made me laugh out loud. I don't think "hackers" here on HN realize how much business is done by email these days, including plenty of important business. And no, if you are a CEO, and call your counterparty after your emails to confirm - you're not going to get anything done.
Meanwhile, a lot of these same hackers working in software development put email account control at the root of their trust chains (ie, with an email account I can drive a password reset).
Busy people will never get anything done otherwise. Not going to happen.