The time has come to ditch email
Fair enough, but what's the alternative?
I'm a messaging junkie. Today's store-and-forward email is fundamentally broken, but I still like the concept very much. Instant messaging is too instant, and peer-to-peer networking is, ironically, too anonymous. Video conferencing is fantastic – if it's someone you know, and they're online (and you've combed your hair). Written communication is never going away. We're tied into an antiquated email system that needs to be abandoned and replaced.
I would love to see a secure email system that did all the hard-crunching on the client and perhaps generated a unique private-public key for each piece of mail, without user interaction. However it is done, let's make it rather mathematically difficult to send email, and even more difficult to send email to many recipients – while the process remains very simple to the end user. Make it a requirement that one mail sent to a thousand recipients securely would require a very fast client doing unique encoding, hashing, compression, and encryption on each piece of mail just to send it. I enjoy the thought of a spammer needing a giant Bewolf cluster ranked rather high up in the Top 500 list of supercomputers to send one piece of spam to ten million people. At that point, the source of spam and the spammer himself would be a little bit easier to track down.
Before you skip to the end of this column and submit your comment, telling me that I'm crazy or uninformed, understand that I realize the problem with email is very complex. It would be nice if the solution "appeared" to be rather simple. I've spent the past 18 years with an email address of some sort, dating back to 1988, and I get more email than most. But like most people, I'm just an end-user of email and it's very clear that email is a sinking ship. And millions of people were online in the 1980s before me.
Getting email clients to work with a new infrastructure will be a major hurdle, and the plumbing itself will take some time. Getting major ISPs and Yahoo Mail, Gmail and Hotmail to adapt an open solution will be even harder. Fine. There are many technical hurdles. But time and again, truly innovative technology will catch on. With the rise of the web, HTTPS and SSL, Napster, SSH, BitTorrent, and so much more, superior technologies have created many new storms.
With all the security problems stemming from 1981's nuclear explosion of SMTP, it seems only fitting that the bright minds in the security community should develop the internet's next killer app.
Far too much effort is spent preserving today's [email protected] format, to the exclusion of everything else. The @ symbol was a novel hack, so let's find a similar new one.
Maybe I'm dreaming, but a gateway from e-mail to a new secure e-mail infrastructure, electronic identity or e-num system might be the first place to start. Perhaps using one of the reserved symbols first outlined way back in RFC 821 or 822, whether it's a bangpath secure![email protected], or secure?[email protected] or name=[email protected] might work – but it would have to degrade nicely with current email systems. However it's done, a very simple, elegant solution would be a fantastic way to start.
I'm confident that there is no solution using today's massive email infrastructure problems, because so many bright people have been working on it for such a long time. Maybe I am indeed dreaming that we can "abandon" today's email SMTP much like the Usenet's NNTP was "abandoned" years ago for something better – because that "something better" for email still doesn't even exist.
Copyright © 2006, SecurityFocus
Kelly Martin has been working with networks and security since 1986, and he's editor for SecurityFocus, Symantec's online magazine.