Re: Thinking outside the box

Barry Shein <[email protected]> Mon, 18 Mar 2013 16:12:45 -0400
Newsgroups gmane.ietf.asrg
Message-ID <[email protected]>
On March 17, 2013 at 22:47 [email protected] (Paul Smith) wrote:
 > How about simple end-to-end authentication?

I agree, a very simple methodology would be to simply coordinate with
recipients to stick an X-Password or similar in the header.

I actually do that now usually right in the subject and many friends
have come to recognize it because it's sort of funny (no I won't post
it here!) and highly unlikely to be anyone else.

I believe Mailman will optionally insert something like [PHRASE] in
subject lines, such as

     Subject: [ASRG] Thinking outside the box

I don't think I've ever seen counterfeiting of that and in the case of
widely subscribed mailing lists it's exceedingly simple.

Which might tell us how low the threshold for slowing down spammers
really is.

It's a little more difficult for legitimate bulk emailers, Amazon for
example, tho if it were a convention perhaps they could tell each
email account we will stick [PHRASE], where PHRASE is different, yet
memorable, for each recipient, in your email if you care to check it.

I'd guess their main objection, besides cost-benefit, would be it'd be
most effective in the Subject:, but for them that's precious real
estate, they probably want to limit it to 60 characters or less and
giving up, say, six for brackets and a 4 letter word might provoke
resistance. Sticking it in a separate X-Header might raise questions
of utility for most recipients.

But that hardly invalidates the idea, just some potential limitations.

P.S. One can also cryptographically sign email of course but that
hasn't caught on, way too complicated?

-- 
        -Barry Shein

The World              | [email protected]           | http://www.TheWorld.com
Purveyors to the Trade | Voice: 800-THE-WRLD        | Dial-Up: US, PR, Canada
Software Tool & Die    | Public Access Internet     | SINCE 1989     *oo*