The problem with SPAM is that what some may consider to be a 'fascinating circular' will be perceived by others as SPAM.
SPAM is often in the eye of the beholder.
The problem with SPAM is that what some may consider to be a 'fascinating circular' will be perceived by others as SPAM.
SPAM is often in the eye of the beholder.
Doesn't work unless you teach people about security, which is difficult. We have padlocks next to URLs but it's amazing how many people are still willing to send CC info over HTTP.
> SPAM is often in the eye of the beholder.
There's a lot of grey area, but when a particular string has a 99% unread/deleted rate, you can make statistical inferences. An enormous percentage of email falls into this category, and it's why "spam filters" exist and generally do a good job.
GPG has email clients and key management clients (e.g. seahorse) which make it increasingly user friendly.
> Doesn't work unless you teach people about security, which is difficult.
Simple, transparent security is hard. But this is again a UI problem, not a failing of email.
Think about this for a second: let's say Google decided that it was going to transparently PGP-sign all GMail users' emails. Now GMail knows that any message with a from address that ends in @gmail.com but without a valid PGP signature is fraudulent.
Now let's say Yahoo wants to adopt this too. So we add some syntax to SPF that advertises, "any mail coming from this domain must be PGP signed." And another field that points to a public key server. So then all other SMTP servers (or even end-user mail clients, if they want), can auto-reject mail based on this criterion.
Sure, this leaves out some details, like people sending mail from an @gmail.com address using their own SMTP server via a thick mail client that doesn't support PGP (or requires complicated setup to do it properly, like most do). But it's a (hopefully) interesting idea that might work with some modifications.
This has nothing to do with email per se, nothing about its successes or failings. It's just building an easier-to-use distributed authentication system that mail recipients can use.
Paypal and eBay do this. Gmail filters out any DKIM-fail or SPF-fail mails purporting to be from @paypal.com and sends it to spam, with 100% accuracy. Gmail also puts the little 'key' icon next to the sender name, but that's not really important, the point is that any and all fraudulent emails are filtered out with unerring accuracy.
Thus, we don't need to use PGP or whatever, which needs to be handled at the client level. DKIM + DMARC is already here and working at the server level. You don't need to wait for your favourite email client to adopt DMARC.
Yes, if people send emails without going through that SMTP server etc etc.. that's a problem, but also solvable/solved.
GPG is not user friendly. Remember, the public are stupid.