Computer Science
Computer Science
bullet At Rowan Graduate Commencement: Levine to speak to graduates; Bartolozzi to receive honorary degree | More

bullet Rowan partners with the Philadelphia Science Festival to bring science education to the public | More

bullet Rowan Commencement ceremonies moved to Coach Richard Wackar Stadium | More

bullet CCCA Showcase a focus on talent, achievement | More

bullet Rowan Engineers Without Borders works with elementary school students on engineering-related projects | More

Technical Report Number TR1995-1

Title
Can You Trust Your Email?


Authors
Kyle Cassidy
Office of Academic Computing
Rowan College of New Jersey
Glassboro, NJ 08028

A. Michael Berman
Department of Computer Science
Rowan College of New Jersey
Glassboro, NJ 08028

Abstract

Everyday, millions of electronic mail messages (email) pass through
the Internet. Most academics depend upon email to do their
jobs. However, email is not trustworthy. Specifically, it is almost
never possible to verify, using the email alone, that a received
message has come from the apparent sender. The problem can come from
at least three sources: the design of the Internet mail protocol;
specific attacks designed and distributed by hackers; and generally
lax security standards, particularly at academic institutions. The
issue of trust in communications is not entirely new -- after all,
forgery has been recognized as a crime almost since the invention of
writing. However, the lack of general understanding of this new
medium, combined with the lack of non-digital information associated
with paper mail (in particular, the signature) have created an
environment in which forged messages are easy to send and hard to
recognize. We discuss two specific actions academics ought to take
that can help the situation: user education and improved system
security. Finally we briefly describe a technical approach -- the
digital signature -- that promises to greatly reduce the problem in
the future.