ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft revamps Sender ID

Stefanie Olsen CNET News.com

Published: 26 Oct 2004 08:20 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft has revised its anti-spam specification Sender ID following the spec's near-death in the technical community.

The software giant said Monday that it has rewritten Sender ID -- a specification for verifying the authenticity of email with Internet Protocol records -- to address criticisms of the spec's earlier incarnation. Among other changes, Microsoft removed language in its pending patents for Sender ID that could have included claims to Sender Permitted From, or SPF, a widely used system for email authentication that was merged with Microsoft's CallerID for Email to create Sender ID, according to Microsoft's Ryan Hamlin.

"We wanted to complete what we started," said Hamlin, general manager for Microsoft's safety technology and strategy group. Microsoft has resubmitted the specification to the Internet Engineering Task Force, a technical standards body.

Last month, the IETF shut down the working group that was charged with building consensus for Sender ID and turning it into an industry standard. Consensus became impossible after some people in the open-source community said Microsoft's patent claims could enable the software company to eventually charge royalties. Others were critical of the system's inability to work with previously published records in SPF.

As a result, America Online and open-source groups pulled their support of Sender ID. And Meng Wong, the architect of SPF, said he would retrench on his technical specification alone.

Microsoft's Hamlin said on Monday that the company has revised Sender ID by making it backward-compatible with 100,000-plus SPF records already published. He also said Sender ID will give email providers a choice to publish records in SPF, which verifies the "mail-from" address to prevent fraud, or in PRA -- purported responsible address.

PRA records let an email provider check the "display address" of an email in its headers against the numerical IP address of the sender. That process can prevent so-called phishing attacks by spammers who forge the display address.

Email providers and senders now have the ability to publish in and check the authenticity of email with both methods in Sender ID.

"We've been trying to make it as user-friendly as possible. We've got the spec to the point where you only have to publish one record for two purposes. I see that as a little victory," said Wong.

Still, some people in the open-source community are concerned about Microsoft's other pending patent over Sender ID, which prevents users of the specification from sublicensing it.

AOL said on Monday that it has renewed support for Sender ID in its current form.

The IETF has granted Sender ID "experimental" status so that the industry can test it, along with competing email authentification proposals, and build consensus that way.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
96 out of 293 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Communication Engineer - Utilities - Smart Metering

In the first instance, apply to this advert and I will be in touch accordingly with full details of the role and full spec etc. Purpose of the role ...

NHS Programme Manager PCT Experience Required

First let me tell you about the basics: LOCATION: A PCT in London (Zone 1) CONTRACT LENGTH: A minimum contract of 6 months (very likely to go on ...

Project Manager for Care Records System (CRS) - 400-500pd

A Project Manager role for the NHS Care Records System has arrisen due to the continued efforts of the NHS to become electronically integrated ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment