The situation involves institutions happy to opaque links to email as part of their workflow. What could change this? All I can imagine is state regulation but that also is implausible.
The situation involves institutions happy to opaque links to email as part of their workflow. What could change this? All I can imagine is state regulation but that also is implausible.
IT wasn’t amused when I reported it as phishing attempt.
In a previous client,the CIO complained about the low click rate for their security training, every one thought it was some spams.
I think (but am not sure) that something using trust networks from the ground up would be better in the long term. Consider anything dodgy until it has built trust relationships.
Eg email servers can’t just go for it. You need time to warm up your IP address, use DKIM etc. People can’t just friend you on FB without your acceptance so it’s a lot safer than email, if still not perfect. A few layers of trust would slow bad actors down significantly.
A trust network wouldn’t be binary. Having eg a bunch of spam accounts all trust each other wouldn’t help getting into your social or business network.
Thoughts from experts?
But this is fundamental to an open Internet. Yes going whitelist-only would stop bad actors but it would also hand over the entire internet to the megacorps with no avenue for individual success.
Email as it is presently is a constant opening to phishing and spear fishing. Browser exploits are common too but it's harder (not impossible) to make them personal. And phishing doesn't have to rely on a browser exploit - a fake login page is enough.
It's logical to have a whitelist (or disallow) email links but still allow browsers to follow links.
Eg certs. Let’s Encrypt equivalent for credibility, where I can trust you as we interact more, and borrow from your trust networks. Send spam and you reduce your cred. (Letscred.com is available right now if anyone is very bored :)
Gotta be tested very carefully so you don’t end up with a black mirror episode, of course.
We have sandboxing on mobile apps. Why can't we have the same for desktop?
After the limited success of the windows store you can now get the same in standalone installers. It has been adopted by approximately nobody
However, it reasonable to expect a single hole to be fixed. The "email hole" has been discussed for decades but here we are.
At that scale, expecting a core issue to be quickly (or ever) fixed is just unrealistic. I honestly wonder if fundamentally it will ever be fixed, or if instead we get a different communication path to cover the specific use cases we do care about security.
PS: the phone is now 2 century olds, and we sure couldn't solve scamming issues...
Morally? No reason why, and people are working on it (slowly).
Practically? Because sandboxing breaks lots of things that users and developers like, such as file picking (I hate snaps), and it takes time to reimplement them in a sandbox in the way that people expect them to work. If it requires the developers' cooperation, then it's even slower, because developers have enough APIs to learn as it is.
I’ll die on this hill.
or by your “friend” mentioning a highly personal issue that only you two were supposed to know, asking you to phone someone on their behalf
or by your “relative”, etc.
Same. I found a setting in legacy outlook to force all e-mails to be in plain text. So every corporate email I reply to, converts the product owners html formatted emails into junk.
Gives me a little joy that the e-mail they worked so hard on gets mangled by my outlook replies :)
How would that help? You can put links in plain text.
The only people who want to send HTML emails are marketers, advertisers, trackers, scammers, hackers, and that clueless manager who wants the cornflower blue background. (most of these actors are the same people, except for that last one).
It also does little against compromised mailboxes - heck, a sufficiently advanced spear fish might even have better chances if the user misunderstands the security improvements this would provide.
But I think other than this, there's not much else to fix. Some people are malicious, others get compromised. No fixing that.
Chrome 0-days are expensive and aren't going to be wasted on the masses. They'll be sold to dodgy middle eastern countries and used to target journalists or whatever.
If you aren't a high value target you can click links. It's fine.