Hacker News new | ask | show | jobs
by jazzyjackson 1020 days ago
Email actually has very well thought out authentication mechanisms such that its not unreasonable to expect a domain is not spoofed, and it came from the server it says it came from

but if some baddies have logged into your server and sending messages as you, then DKIM can't save you

so say social media companies want a higher standard of proof that emails are coming from a particular institution, what mechanisms are available that doesn't involve onboarding every individual officer to the subtleties of public key crpyotgraphy?

1 comments

Never buillding a back door for LEOs sounds like a reasonable option.