ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


Security threats Toolkit

AOL dumps Microsoft's Sender ID

Dan Ilet ZDNet.co.uk

Published: 17 Sep 2004 10:05 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

America Online (AOL) has ditched Microsoft's Sender ID technology in favour of Sender Policy Framework (SPF).

The move follows concerns over Sender ID voiced by the Internet Engineering Task Force (IETF) earlier this week. Explaining its decision, AOL cited a low level of support for the technology in the open source community, as well as possible problems with backward compatibility.

"AOL has decided to move forward with SPF-only checking on inbound email at this time. This means AOL will now not be moving forward with full deployment of the Sender ID protocol," said a spokesman for the firm in an email statement. "The licensing of Sender ID technology has never been a focus of concern for the company and its potential deployment of Sender ID technology."

Although AOL said it would take into account the interests of the open source community, its chief reason for the move was that the Microsoft technology was inadequate, AOL said. "AOL has serious, technical concerns that Sender ID appears not to be fully, backwardly-compatible with the original SPF specification -- a result of recent changes to the protocol and a wholesale change from what was first envisioned in the original Sender ID plan," the statement said.

But AOL still intends to publish Sender ID files so its users can use applications that require the technology.

In a prepared statement, Microsoft said: "AOL's decision to conduct only 'MAIL FROM' checks as outlined in the original SPF proposal reflects exactly the kind of flexibility and room for choice provided by the IETF's revised Sender ID proposal. What's encouraging about AOL's announcement is that they will join us in publishing both records and we continue to recommend that all mail senders do the same."

Earlier this week, the IETF rejected Microsoft's controversial proposal for Sender ID because of possible conflicts with pending Microsoft patents. Critics charged that Microsoft's licensing requirements would have prevented open-source software makers from sublicensing the technology, although others argued sublicensing would not have been a problem.

Sender ID, like SPF, is a technology that verifies the authenticity of an email sender's "@" address, such as "@yourbank.com", by validating the underlying, numeric Internet Protocol address. The system combines Microsoft's "Caller ID for Email Technology" and SPF, authored by Meng Wong, chief technology officer at Pobox.com.

AOL's announcement illustrates the brewing standards battle for email authentication technology for fighting spam. One of the most reviled byproducts of the Internet, spam has become a problem that plagues consumers, corporate networks and email providers such as AOL, MSN and Yahoo.

All three of the Internet giants are putting their weight behind their own systems. AOL has used SPF since 2003; Microsoft is pushing for Sender ID; and Yahoo is supporting Domain Keys, which uses digital signatures and can be employed alongside SPF or Sender ID. These technologies take different stabs at the same problem, and each company is trying to drum up support among industry players.

Despite public statements about cooperation, AOL, Microsoft and Yahoo made independent moves to turn their systems into standards. All three companies have submitted proposals to the IETF in the hope that their preferred technology will become the industry standard for antispam efforts.

Yahoo spokeswoman Mary Osako said in an email that the company "is continuing to evaluate a variety of industry solutions including those that are IP-based, such as SPF and Sender ID, and those that are cryptographic, such as DomainKeys. Yahoo is focusing efforts around DomainKeys, which provide an effective and scalable solution to solving the phishing and email forgery problem."

CNET News.com's Jim Hu, Stefanie Olsen and Rob Lemos contributed to this report.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
123 out of 180 people found this useful



Company/Topic Alerts

Create a new alert from the list below:






Sentry Posts Blog

Nasa and the virus

Yesterday the BBC ran a story about a computer virus making it into orbit, which I read with incredulity. OK, it's a nice silly season story on the surface, but what really got me was... More

3 comments

Customer data found on eBay server hig...

The recent news about customer details being retrieved from a server sold on eBay is yet another story about the sorry state of information security in the electronic age (see: http://news.zdnet.co.uk/...m).... More

Post a comment

Does it matter if you are an aardvark...

In spam terms, apparently it does. According to Cambridge University security expert Richard Clayton, if your email address is aardvark at animal.net, you are more likely to receive... More

1 comment