accountable email
James M Galvin <[email protected]>
| Newsgroups | gmane.mail.ng |
|---|---|
| Message-ID | <[email protected]> |
Fred Baker suggested he wanted an end-to-end identifiable sender. I want to generalize that and say that if I had to pick one thing that I really, really wanted from the next generation email system it is "accountable email." And agreeing with Dave Crocker that we stick to non-technical descriptions, as a receiving user of email I want a reliable and robust identifier with which I can apply the policy of my choice. That identifier is absolutely authentication, so whoever said that authentication without authorization is useless was wrong. I explicitly need various elements of the infrastructure to provide perhaps various types and levels of authentication. As the receiver I'll decide if and how I'm going to use that authentication. The identifer might be end-to-end as could be provided by a digital signature. It might be a composite of hop-by-hop signatures. It might be something provided by an anonymous remailer asserting that the actual sender wants to remain anonymous. It might be something else. It might be all of these things. The point is each of these types of identifiers mitigates a different problem with the current email infrastructure. If we had a common format for such an identifier and various mechanisms and locations for creating them then receivers would have many more tools available to them to manage their incoming email. Jim