Computer Science
Computer Science
bullet CSMRU faculty member elected to lead National Disaster Life Support Education Consortium | More

bullet Exploring academics, enhancing social skills: Young Profs Exploration Camp to host 16 students | More

bullet Summer, sun and… snakes? | More

bullet WGLS-FM announces five inductees to station Hall of Fame | More

bullet Rowan hosts Attracting Women into Engineering for middle school girls | More

Technical Report Number TR1995-1

Title
Can You Trust Your Email?


Authors
Kyle Cassidy
Office of Academic Computing
Rowan College of New Jersey
Glassboro, NJ 08028

A. Michael Berman
Department of Computer Science
Rowan College of New Jersey
Glassboro, NJ 08028

Abstract

Everyday, millions of electronic mail messages (email) pass through
the Internet. Most academics depend upon email to do their
jobs. However, email is not trustworthy. Specifically, it is almost
never possible to verify, using the email alone, that a received
message has come from the apparent sender. The problem can come from
at least three sources: the design of the Internet mail protocol;
specific attacks designed and distributed by hackers; and generally
lax security standards, particularly at academic institutions. The
issue of trust in communications is not entirely new -- after all,
forgery has been recognized as a crime almost since the invention of
writing. However, the lack of general understanding of this new
medium, combined with the lack of non-digital information associated
with paper mail (in particular, the signature) have created an
environment in which forged messages are easy to send and hard to
recognize. We discuss two specific actions academics ought to take
that can help the situation: user education and improved system
security. Finally we briefly describe a technical approach -- the
digital signature -- that promises to greatly reduce the problem in
the future.