Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

1/27/2012
08:09 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Google, Microsoft Say DMARC Spec Stops Phishing

New email authentication framework called DMARC, backed by major email and security tool providers, aims to make spoofed domains in messages a thing of the past.

Leading free email providers AOL, Google, Microsoft, and Yahoo have banded together with financial, social media, and message security companies to make it easier to verify the authenticity of email messages.

Together, the companies on Monday announced the formation of DMARC.org, an organization that aspires to make email more trustworthy and phishing more difficult. DMARC.org will promote the DMARC specification, which describes how email senders should authenticate messages, how they should communicate their authentication practices, and how message recipients can discover and implement sender policies.

The acronym stands for domain-based message authentication, reporting, and conformance. Think of it as a set of rules that can make email more secure.

"It's a specification that the DMARC.org group has worked on over the last 18 months to produce," said Google product manager Adam Dawes in a phone interview. "It's a proposed mechanism by which senders and receivers can work together to fight phishing, and to lock down and prevent abuse of domains in the email channel."

[ Find out how the cloud can help security. Read Stolen iPhone Saved By iCloud. ]

Malicious email senders can easily make their messages appear to come from someone else's Internet domain, and such messages often are used for phishing--attempts to dupe message recipients into providing sensitive information under false pretenses or through malware.

According to the Anti-Phishing Working Group, there are presently about 20,000 to 25,000 unique phishing campaigns every month, each targeting hundreds of thousands to millions of email users. And thousands of fake phishing websites are set up every day.

Those involved in DMARC have a stake in making email a better experience. Dawes said that being duped by a phishing message often leads to compromises at multiple online services, because people tend to use the same password across different websites. Losing control of one's account, he said, "is one of the worst experiences that a user can have. If that happens because someone received a phishing message in his or her Gmail inbox, that's a terrible Google experience. Users rely on us to protect them against those threats."

In addition to AOL, Google, Microsoft, and Yahoo, other organizations participating in the DMARC group include financial companies Bank of America, Fidelity Investments, and PayPal; social media companies American Greetings, Facebook, and LinkedIn; and email security companies Agari, Cloudmark, eCert, Return Path, and Trusted Domain Project.

To fight phishing, various forms of email authentication are available, such as SPF, DKIM, and Sender ID. But there's no common standard. As a result, companies that authenticate their email have to coordinate with email providers to make sure that everyone is on the same page when it comes to which messages should be discarded for lack of authentication. PayPal began doing this with email providers in 2007, but approaching each email provider individually isn't ideal. DMARC isn't intended to replace existing specifications, but rather to tie them together.

"We view this as adding significant value to SPF and DKIM," said Microsoft engineer Paul Midgen.

The DMARC framework offers a way to formalize and automate message authentication processes and reporting so that security scales.

"What DMARC now allows is for any domain owner to have control over unauthenticated messages in the Gmail inbox," said Dawes. And the same holds true for inboxes operated by other email providers.

Agari, an email security provider, implemented DMARC last year and subsequently partnered with AOL, Google, Microsoft, and Yahoo. The company's Email Trust Fabric adds value to DMARC by turning raw DMARC data into actionable reports, to help companies understand their email infrastructure and message deliverability. Agari claims it has rejected approximately 4 billion threat messages since the technology was initially deployed in January 2011.

"For me, Monday is going to be one of the most auspicious days in the history of Internet security," said Agari founder and CEO Patrick Peterson in a phone interview in advance of DMARC's launch. "People will be able to send a message and recipients will be able to know where it came from."

Find out how to create and implement a security program that will defend against malicious and inadvertent internal incidents and satisfy government and industry mandates in our Compliance From The Inside Out report. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Bprince
50%
50%
Bprince,
User Rank: Ninja
1/31/2012 | 12:49:01 AM
re: Google, Microsoft Say DMARC Spec Stops Phishing
This is a great step. The key will be the extent of adoption. There is still though the issue of people using similar domain names.
Brian Prince, InformationWeek/Dark Reading Comment Moderator
DevSecOps: The Answer to the Cloud Security Skills Gap
Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
Attackers' Costs Increasing as Businesses Focus on Security
Robert Lemos, Contributing Writer,  11/15/2019
Human Nature vs. AI: A False Dichotomy?
John McClurg, Sr. VP & CISO, BlackBerry,  11/18/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: -when I told you that our cyber-defense was from another age
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-3350
PUBLISHED: 2019-11-19
masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
CVE-2011-3352
PUBLISHED: 2019-11-19
Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context ...
CVE-2011-3349
PUBLISHED: 2019-11-19
lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation.
CVE-2019-10080
PUBLISHED: 2019-11-19
The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of Java, Jersey, and Apache that the NiFI ...
CVE-2019-10083
PUBLISHED: 2019-11-19
When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.