<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Agility Loop &#187; smtp</title>
	<atom:link href="http://agilityloop.com/tag/smtp/feed/" rel="self" type="application/rss+xml" />
	<link>http://agilityloop.com</link>
	<description>The musings of the agile on the world of tech and government</description>
	<lastBuildDate>Wed, 30 Jun 2010 18:20:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='agilityloop.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/8815df9dd02a5349e4cbc3ebe20123b8?s=96&#038;d=http://s2.wp.com/i/buttonw-com.png</url>
		<title>Agility Loop &#187; smtp</title>
		<link>http://agilityloop.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://agilityloop.com/osd.xml" title="Agility Loop" />
	<atom:link rel='hub' href='http://agilityloop.com/?pushpress=hub'/>
		<item>
		<title>Government Behind the Times on Email Authentication</title>
		<link>http://agilityloop.com/2009/04/15/government-behind-the-times-on-email-authentication/</link>
		<comments>http://agilityloop.com/2009/04/15/government-behind-the-times-on-email-authentication/#comments</comments>
		<pubDate>Wed, 15 Apr 2009 20:30:16 +0000</pubDate>
		<dc:creator>Kevin Heald</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[PKI]]></category>
		<category><![CDATA[smtp]]></category>

		<guid isPermaLink="false">http://agilityloop.wordpress.com/?p=4</guid>
		<description><![CDATA[Today in GCN, there is an article entitled Industry group gives government a failing grade in e-mail authentication &#8212; Government Computer News.  The main thrust of the article is detailing how most Government domains do not support any type of email domain authentication such as Sender ID or DomainKeys. E-mail authentication technology, usually transparent to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&blog=7372259&post=4&subd=agilityloop&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<p>Today in GCN, there is an article entitled <a href="http://gcn.com/articles/2009/04/14/email-authentication.aspx">Industry group gives government a failing grade in e-mail authentication &#8212; Government Computer News</a>.  The main thrust of the article is detailing how most Government domains do not support any type of email domain authentication such as Sender ID or DomainKeys.</p>
<blockquote><p><em>E-mail authentication technology, usually transparent to the end user, lets servers verify that e-mail traffic is indeed coming from the domain or sender that it purports to be from, and that the sender is authorized to use that domain. The <a href="https://www.otalliance.org/docs/US%20Govt_4_09.pdf" target="_blank">OTA study</a> showed that only 11 of 25 government domains examined use such authentication. A similar study of top commercial sites showed that the private sector is doing a little better, with 55 percent using some form of e-mail authentication.</em></p></blockquote>
<p>To be fair, the private sector isn&#8217;t doing so great either at 55%.</p>
<p>What I find particularly ironic is that much of the government is ahead on PKI and other security technologies.  It seems like this would be a pretty easy solution to combat spam and phishing attacks.  I know in the past we have discuss using simple SMTP over SSL.  This would at least buy security of SMTP mail transfer, and authentication of domains (although it would be difficult to use with external email domains).  However, technology like <a href="http://en.wikipedia.org/wiki/DomainKeys">DomainKeys</a> (which Yahoo <a href="http://domainkeys.sourceforge.net/">uses</a>) is a more versatile solution than SMTP over SSL.  Hell it&#8217;s even open source, so costs COULD be minimal.</p>
<br /> Tagged: authentication, email, PKI, smtp <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/agilityloop.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/agilityloop.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/agilityloop.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/agilityloop.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/agilityloop.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/agilityloop.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/agilityloop.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/agilityloop.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/agilityloop.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/agilityloop.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=agilityloop.com&blog=7372259&post=4&subd=agilityloop&ref=&feed=1" />]]></content:encoded>
			<wfw:commentRss>http://agilityloop.com/2009/04/15/government-behind-the-times-on-email-authentication/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/7052384430b7f7d78ce1dbc5022cdd90?s=96&#38;d=identicon&#38;r=PG" medium="image">
			<media:title type="html">healdkw</media:title>
		</media:content>
	</item>
	</channel>
</rss>