[ NNSquad ] "How a Google Headhunter's E-Mail Unraveled a Massive Net Security Hole" + my comments

"How a Google Headhunter's E-Mail Unraveled a Massive Net Security
Hole" + my comments
http://j.mp/QXdOnZ  (This message on Google+)

 - - -

http://j.mp/QXeppK  (Wired)

   "The problem lay with the DKIM key (DomainKeys Identified Mail) Google
    used for its google.com e-mails. DKIM involves a cryptographic key
    that domains use to sign e-mail originating from them - or passing
    through them - to validate to a recipient that the header information
    on an e-mail is correct and that the correspondence indeed came from
    the stated domain. When e-mail arrives at its destination, the
    receiving server can look up the public key through the sender's DNS
    records and verify the validity of the signature."

 - - -

Well, what appeared to be mail from a headhunter anyway.  But the
irony here is that DKIM is much less useful in preventing these kinds
of (spam-related, human engineering) attacks than might be thought,
since (a) most sites -- including legit ones -- don't routinely
support it, and (b) most email recipients are largely oblivious to any
associated warnings.  So, while DKIM indicating a problem with mail
from the citi.com domain might be noticed by some users running
compatible MUAs (Message User Agents), mail coming from a forged,
non-DKIM supporting domain like citi-banking.com would probably be
accepted as reasonable by many or most recipients.

