Sign In
Terry Zink's Cyber Security Blog
Discussing Internet security in (mostly) plain English
Common Tasks
Blog Home
Email Blog Author
About
OK
RSS for comments
RSS for posts
Atom
Search Form
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tag Cloud
Authentication
Backscatter
Botnets
Economics
Education
Entertainment
Facebook
Foreign language
Hacking
Legal
Malware
Miscellaneous
Net Neutrality
Outbound
Pages
Privacy
Reputation
Security
Social Networking
Spam
Stories
Monthly Archives
Archives
February 2012
(6)
January 2012
(21)
December 2011
(6)
November 2011
(12)
October 2011
(13)
September 2011
(12)
August 2011
(15)
July 2011
(14)
June 2011
(11)
May 2011
(11)
April 2011
(11)
March 2011
(11)
February 2011
(9)
January 2011
(1)
December 2010
(19)
November 2010
(16)
October 2010
(18)
September 2010
(16)
August 2010
(16)
July 2010
(16)
June 2010
(16)
May 2010
(16)
April 2010
(21)
March 2010
(25)
February 2010
(17)
January 2010
(13)
December 2009
(13)
November 2009
(17)
October 2009
(18)
September 2009
(13)
August 2009
(12)
July 2009
(15)
June 2009
(12)
May 2009
(13)
April 2009
(10)
March 2009
(9)
February 2009
(9)
January 2009
(16)
December 2008
(15)
November 2008
(16)
October 2008
(13)
September 2008
(19)
August 2008
(16)
July 2008
(16)
June 2008
(15)
May 2008
(14)
April 2008
(15)
March 2008
(17)
February 2008
(15)
January 2008
(14)
December 2007
(16)
November 2007
(12)
October 2007
(16)
September 2007
(16)
August 2007
(8)
July 2007
(15)
June 2007
(16)
May 2007
(15)
April 2007
(11)
March 2007
(10)
February 2007
(9)
January 2007
(20)
December 2006
(14)
November 2006
(8)
October 2006
(14)
September 2006
(13)
August 2006
(22)
July 2006
(12)
Browse by Tags
MSDN Blogs
>
Terry Zink's Cyber Security Blog
>
All Tags
>
authentication
Tagged Content List
Blog Post:
New email authentication protocol – DMARC
tzink
Today, a consortium of companies including Google, Microsoft, Facebook and Paypal announced that they were collaborating and coming up with a new protocol known as DMARC – the Domain-based Message Authentication, Reporting and Conformance. What is DMARC? This is very much a summary of DMARC in a nutshell...
on
30 Jan 2012
Blog Post:
Should trust be implicit or explicit?
tzink
It sure seems like I am having a lot of debates with my co-worker lately about the nature of mail filtering. Why do I say this? Because I had one today. This one is over the issue of trust. I can’t remember whatever it is we were discussing (I think it was something to do with product...
on
7 Sep 2010
Blog Post:
Yahoo now does SPF checks
tzink
Well, what do you know? I don’t know if they have been doing them all along and have only finally decided to expose the result, but I logged into my Yahoo mail the other day and checked out the message headers of a mail in my inbox. I was surprised to discover that Yahoo is now exposing the Received...
on
21 Jul 2010
Blog Post:
Why send spam over TLS?
tzink
In my previous post, I noted that rustock had started sending us a whole pile of spam over the TLS protocol. The question now is why do it at all? I mentioned in my post that this is clever behavior and one of my readers posted in a comment “What makes this so clever?” The issue of authentication...
on
3 Mar 2010
Blog Post:
Some stats and figures on DKIM and SPF
tzink
Did you ever wonder how many organizations out there are signing their mail with DKIM? Or how many organizations rely on SPF as a tool to validate their inbound mail? Well, I’ve wondered as well. DKIM supposedly is getting more popular, but how widespread is it? Are lots of people using...
on
23 Feb 2010
Blog Post:
Yahoo now signs with DKIM
tzink
This went unnoticed by me for a very long time, but I was going through some of my personal mail and I discovered that Yahoo is now signing its outbound mail with DKIM in addition to DomainKeys. Long time readers may remember that about two years ago, I started a series on Sender Authentication and covered...
on
12 Aug 2009
Blog Post:
The concept of Safe Senders
tzink
Sometimes an end user wants to flag a specific sender as a safe sender, that is, they always want messages from that user to go to their inbox. You've probably seen this in some newsletters where they say at the top or bottom of the message to please add them to your address book which will prevent...
on
24 Mar 2008
Blog Post:
Response to Trust-based messages
tzink
In my other post in a Q&A excerpt with Dave Crocker by Investor's Business Daily, I'd like to now respond to some of my selected quotes. Crocker: You have to create what I call a trust overlay to the existing e-mail system. Existing senders and receivers can continue to use e-mail as before... All...
on
29 Dec 2007
Blog Post:
Some early stats on TMA
tzink
We finally got around to deploying all of our new features from our latest release. As I explained a couple of months ago, I created a hybrid of SPF and SenderID in response to customer demand. I called it TMA, or Terry's Message Authentication. It was an SPF check on the From or Sender...
on
27 Dec 2007
Blog Post:
Spam's new nemesis: Trust-based messages
tzink
The other day I was reading Investors Business Daily and came across an article whose title you see in the subject line of this blog post. The article is a Q&A Dave Crocker of BrandenBurg InternetWorking. If you're like me and too lazy to click the link and read the article, allow me...
on
26 Dec 2007
Blog Post:
Sender authentication part 32: TMA Explained
tzink
As I said earlier, I needed to come up with an authentication mechanism that protected the From: or Sender: address in the message headers. But, I did not want to replace SPF with SenderID. So, I came up with another solution which I call TMA. I would implement a "lite" version of SenderID. At first...
on
26 Oct 2007
Blog Post:
Sender authentication part 31: TMA
tzink
I'd now like to post something about the inspiration for this whole series on authentication. I'm not done with DomainKeys, I still have to post a little bit on DKIM and one other authentication mechanism, and then this series will be done. But I need to boast about one of my achievements...
on
25 Oct 2007
Blog Post:
Sender authentication part 30: The canonicalization process
tzink
Canonicalization is the process of preparing a message for signing. This process is necessary because of the way email is handled in transit by various mail servers. For example, some mail relayers handle white space and line wraps just fine, others do not and strip them or insert them. All email was...
on
25 Sep 2007
Blog Post:
Sender authentication part 29: Some DomainKeys examples
tzink
Let's plow through a few real life examples. Here's an actual DomainKey Signature: Example 1 DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com.au; h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type; b=Nin4jVEsnqKpfH6nKyRwaSxJzzaH5tX0hDJeJgNCx9af7VbBiV7kwEGn4z44Dtg...
on
24 Sep 2007
Blog Post:
Sender authentication part 28: DomainKey headers in the message
tzink
This post will again be a paraphrase of that which is found in RFC 4870 . Now that we have seen how public keys are stored in DNS, we will next look at how a signing server generates the message signature. The signature of the email is stored in the "DomainKey-Signature:" header which contains all of...
on
23 Sep 2007
Blog Post:
Sender authentication part 27: Public key notation in DNS
tzink
Now that we have an overview of how DomainKeys works, we're going to look at how a service using DomainKeys generates a DomainKeys signature. When a receiving email server gets the message and sees that there is a DomainKeys header, it has to retrieve the key from DNS. The DomainsKey header is "DomainKey...
on
23 Sep 2007
Blog Post:
Sender authentication part 26: DomainKeys in a nutshell
tzink
Now that we understand how digital signatures work, let's take a look at DomainKeys. Like SPF and SenderID, DomainKeys is a mechanism of sender authentication. DomainKeys uses public key encryption to authenticate messages. It works in the following way (much of this is based upon Yahoo's description...
on
19 Sep 2007
Blog Post:
Some stats on SPF, DomainKeys and DKIM
tzink
I'm taking a quick timeout from my series on explaining Sender Authentication to post some quick stats on authentication. I took an 8-hour snapshot of our logs to collect some statistics. I started tracking how often senders use SPF, DomainKeys and DKIM (I will go into DomainKeys and DKIM in a future...
on
11 Sep 2007
Blog Post:
Sender authentication part 25: Digital signatures
tzink
We've seen encryption, secret key encryption and public key encryption. Public key encryption allows a sender to encrypt the contents of the message and have only the intended recipient read it. They do this by encrypting with the public key and decrypting with the private key. However, recall that either...
on
7 Sep 2007
Blog Post:
Sender authentication part 24: Public key encryption
tzink
The basic idea behind secret key encryption is the following: You don't have to keep the algorithm a secret. You do need to keep the key a secret. To increase the security of the contents, you lengthen the size of the key. This is all well and good, except for one problem? How do you distribute the key...
on
6 Sep 2007
Blog Post:
Sender authentication part 23: Secret key encryption and one-way functions
tzink
We saw in my previous post that substitution ciphers are a method of encoding a message such that its contents are unintelligible (much like the ramblings of many of the presidential candidates), and they are fairly easy to break with computers that can iterate over them very quickly. Enter the concept...
on
5 Sep 2007
Blog Post:
Sender authentication part 22: Introduction to encryption
tzink
It's been a long time since I took the unit on encryption in my 4th year Telecommunications class in university, but I did quite well in it (I believe I got 5/5 on the assignment). For you see, the concept of encryption is relevant to our next section on email authentication: DomainKeys, a method of...
on
4 Sep 2007
Blog Post:
Sender authentication part 21: Some recommendations
tzink
In documentation that Microsoft is going to release shortly, they have some recommendations on how to set up your SenderID records as well as a list of frequently asked questions. I will post a link to the relevant documents when they become available. For now, here's a sneak peek at some of the comments...
on
24 Aug 2007
Blog Post:
Sender authentication part 20: Advantages of PRA vs MAIL FROM
tzink
Microsoft is shortly coming out with some documentation on SenderID and the business case for its implementation. Hopefully by now I have demonstrated its usefulness. The Purported Responsible Address has a couple of advantages when deciding to support SenderID vs SPF: It is the identity that is typically...
on
23 Aug 2007
Blog Post:
Sender authentication part 19: How spammers evade SPF
tzink
How would a spammer get around SPF? One way is the method used by Spammer-X in his book Inside the Spam Cartel . Spammer-X is a retired spammer (so he says) and goes into a lot of the details in his book. I'll give a review when I'm done this series on sender authentication in six months or so. According...
on
18 Aug 2007
Page 1 of 2 (44 items)
1
2