Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Because email is a system designed for ARPAnet not Internet, and it was designed to be used be people who could be trusted to not spam. No protections were built in, and email hasn't fundamentally changed since the late 70's. In mid-late 90's the masses came, and since then we've been adding band-aids to it to keep it alive but the truth of the matter is that it's still an open door just waiting to be walked into. You can DKIM, SPF, and do all the SMTP authentication you want, but the spammers still get through.

Sure, it might end up in the spam box. But so do real emails. So, spammers still get their emails viewed. As do phishers.

https://www.bankinfosecurity.com/tricked-rsa-worker-opened-b...

    A well-crafted e-mail with the subject line "2011 Recruitment Plan" tricked an RSA employee to retrieve from a junk-mail folder and open a message containing a virus that led to a sophisticated attack on the company's information systems,
https://www.wired.com/story/the-full-story-of-the-stunning-r...

TL;DR: Email is fundamentally broken because it was designed in a time when you could leave your doors unlocked at night.



Any system that runs off anonymous messages is going to have a spam problem. There isn't anything special about how email is designed that enables spam past that. If you were to design a new system you would have to have signed messages. But we could just do that now with email.

It isn't a design choice, it is a choice that we make every time we send an unsigned email.


I think this is the essential fact, thanks for posting.

Lots of people complain about the “insecurity” of email, but as long as you want this feature (sending anyone a message knowing nothing more than just their email address), there will always be spam.

And if this is a feature you can do without, then there are lots of alternative communication systems, or you can always use signatures in email.


Yes, it was a design choice made in the early 1970's before public key cryptography was even invented. And that's why it's broken and always will be. This is why email needs to go away completely.

But then again, there are still laws on the books saying the only way to securely transmit a document is by fax machine. So even if somebody reinvents a backwards compatible email system tomorrow that solves all the problems, people will be to afraid to use it.


HTTP was invented before SSL/TLS. Does that mean that the web needs to go away completely?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: