Thursday, June 01, 2006

Forgot pass, phishing, and never take the DB1 bus!

Today was my 4th day at PARC and I think I'm getting up to speed with the research project that I'm working on which has to do with task management in e-mail. However, I forgot my PARC pass at home! So, I had to get a temporary one. I usually don't forget things, but I was in a rush, so I forgot it. I still have my tuna casserole that I made last night, and I had that for lunch and also for dinner! I still have one more to finish up for tomorrow lunch.

During the afternoon, I attended a talk on phishing and I learned about the fundamental problem of e-mail and how it's difficult to detect phishing e-mails now these days and the ways that we can try to combat phishing. The real problem with e-mail is that there is no authentication of e-mail content, you can authenticate the sender e-mail but not the content itself, so anyone could write anything in the e-mail message content. So what are the ways around this? We can do sender authentication, however this won't work with forwarding. Another thing is to use SPF (sender policy framework) and add SPF records to DNS that indicate what servers are allowed to send mail for your domain. The receiving mail server looks up the SPF record of the mail’s From domain to match. Apparently, SPF is relatively widely deployed and is great for catching phishers. But the problem is that SPF records need to be added to the DNS and the mail servers need to implement that. Not all mail servers (especially forwarding mail servers) do that. So, the question is where do you catch the spam? You can do it at the mail server or at the client (with filtering techniques which many people use and so do web-based e-mail). I think we need both.

Coming home tonight, I took the DB1 bus instead of the DB bus, and I remember several people telling me not to take the DB1 bus because it is express and doesn't stop at the places I need to get off at. But I took it anyway, and because of that, I had to retrace and take the DB bus one hour and half later. So, instead of coming home at 7 pm, I came home at around 8:30 pm.

I need to continue to finish up writing a paper tonight, it's due this Friday, which happens to also be my birthday!

No comments: