pmcnamara
News Editor

E-mail’s declining value

Opinion
Aug 16, 20044 mins

Here’s how rotten phishing has gotten for those brand-name companies that are most targeted: Some are promising their customers that they will never, ever ask them a question of any kind in an e-mail, meaning there would never, ever be any reason for the customer to volunteer any personal information in response. No questions, no answers, no phishing victims, or so the theory goes – it isn’t quite that simple.

Here’s how rotten phishing has gotten for those brand-name companies that are most targeted: Some are promising their customers that they will never, ever ask them a question of any kind in an e-mail, meaning there would never, ever be any reason for the customer to volunteer any personal information in response. No questions, no answers, no phishing victims, or so the theory goes – it isn’t quite that simple.

One credit card company went so far as to toss the baby out with the bath water – it pulled the plug on customer-bound e-mail altogether – a moratorium that since has been rescinded but nonetheless should sound alarms.

These unsettling stories come from secure e-mail vendor PostX, whose executives care dearly about phishing because the future of their company depends on the survival of e-mail as a trustworthy communications channel between major companies and their customers. As unthinkable as the notion might be to some, that survival is not guaranteed as long as the phishing epidemic remains out of control.

“We just want this problem to go away,” laments Cayce Ullman, who recently was bumped up from PostX CTO to CEO. In an effort to hasten the problem’s departure, PostX helped launch the Trusted Electronics Communications Forum, one of a handful of organizations – including the Anti-Phishing Working Group and the Online Identity Theft Coalition – working to thwart the scam artists.

“Part of the problem is that if you start to have these rules around e-mail – we’ll never ask you a question; we’ll never drive you to our Web site – that also starts to decrease the value of the e-mail you’re sending,” Ullman says. “E-mail is the killer app, and for organizations to lose their ability to use it – use it at all, or with links in it, or questions – greatly diminishes its power.”

In the short term, heightened worries about phishing might draw customer attention to providers of secure messaging products such as PostX. The problem is long-term.

“PostX is really concerned about phishing because the majority of our business is based on selling things like [secure electronic] statements and secure messaging,” Ullman says. “So if the e-mail channel becomes dirty or unsafe or noisy that’s a huge problem.”

The rush to devise anti-phishing strategies has brought with it unintended consequences. Scott Olechowski, vice president of product strategy at PostX, tells the story of a banking industry customer that wanted to extend its use of PostX Envelope from commercial accounts to consumers.

“They realized they had a policy they published that said we’ll never send you an e-mail that asks you any questions. And one of the questions that a [PostX] Envelope is going to ask you is your password,” Olechowski says. “So they had a policy that prevented them from deploying this to their retail customers.”

Moreover, such corporate e-mail policies are of limited value in the first place, Ullman says.

“The problem with this [policy] approach is that an organization deciding they aren’t going to send e-mail doesn’t prevent a spoofer from sending e-mail to their customers,” he says.

So what might help more? PostX has “a lightweight signing mechanism that we’re going to put forward to the group that we believe is as good a solution as we’ve heard of,” Ullman says, although the company is by no means married to its own idea.

“We want to have a solution that is open, free, non-proprietary and not encumbered by patents,” he says. “We want buy-in from the actual [corporate] victims. And we want to have something together in six to nine months; it might not be the ultimate solution, but at least it will stop the hemorrhaging.”

Not that I’m cool enough to be a fan, but I’ve wondered what the rock band Phish makes of all this. The address is buzz@nww.com.