KeyForge: Mitigating Email Breaches with Forward-Forgeable Signatures

04/12/2019
by   Michael Specter, et al.
0

Email breaches are commonplace, and they expose a wealth of personal, business, and political data that may have devastating consequences. The current email system allows any attacker who gains access to your email to prove the authenticity of the stolen messages to third parties -- a property arising from a necessary anti-spam / anti-spoofing protocol called DKIM. This exacerbates the problem of email breaches by greatly increasing the potential for attackers to damage the users' reputation, blackmail them, or sell the stolen information to third parties. In this paper, we introduce "non-attributable email", which guarantees that a wide class of adversaries are unable to convince any third party of the authenticity of stolen emails. We formally define non-attributability, and present two practical system proposals -- KeyForge and TimeForge -- that provably achieve non-attributability while maintaining the important protection against spam and spoofing that is currently provided by DKIM. Moreover, we implement KeyForge and demonstrate that that scheme is practical, achieving competitive verification and signing speed while also requiring 42 bandwidth per email than RSA2048.

READ FULL TEXT
research
11/17/2017

Towards the Adoption of Anti-spoofing Protocols for Email Systems

Email spoofing is a critical step of phishing, where the attacker impers...
research
05/24/2023

Spoofing Attacker Also Benefits from Self-Supervised Pretrained Model

Large-scale pretrained models using self-supervised learning have report...
research
04/04/2022

Anti-Spoofing Using Transfer Learning with Variational Information Bottleneck

Recent advances in sophisticated synthetic speech generated from text-to...
research
10/06/2021

MToFNet: Object Anti-Spoofing with Mobile Time-of-Flight Data

In online markets, sellers can maliciously recapture others' images on d...
research
02/19/2023

Liveness score-based regression neural networks for face anti-spoofing

Previous anti-spoofing methods have used either pseudo maps or user-defi...
research
02/14/2023

Forward Pass: On the Security Implications of Email Forwarding Mechanism and Policy

The critical role played by email has led to a range of extension protoc...

Please sign up or login with your details

Forgot password? Click here to reset