Draft Transcript Day2.Pdf (542.72
Total Page:16
File Type:pdf, Size:1020Kb
1 1 2 3 4 5 EMAIL AUTHENTICATION SUMMIT 6 7 8 9 SPONSORED BY 10 THE FEDERAL TRADE COMMISSION 11 AND THE 12 NATIONAL INSTITUTE OF STANDARDS AND TECHNOLOGY 13 14 15 WEDNESDAY, NOVEMBER 10, 2004 16 8:30 a.m. 17 18 19 FEDERAL TRADE COMMISSION 20 601 NEW JERSEY AVENUE, N.W. 21 WASHINGTON, D.C. 22 23 24 25 For The Record, Inc. Waldorf, Maryland (301) 870-8025 2 1 A G E N D A 2 PAGE 3 4 Opening Remarks, Commissioner Leibowitz 4 5 6 Email Authentication: How Spammers 7 Circumvent Authentication Methods 11 8 9 Email Authentication: Real World Effects 85 10 11 Global Impact of Email Authentication: 12 International Perspectives 149 13 14 Email Authentication: Overcoming 15 Spammers' Tricks and Moving Towards 16 Implementation 185 17 18 Beyond Email Authentication: The Role 19 of Reputation, Accreditation and 20 Other Tools 245 21 22 Closing Remarks, Commissioner Swindle 317 23 24 25 For The Record, Inc. Waldorf, Maryland (301) 870-8025 3 1 P R O C E E D I N G S 2 - - - - - 3 MS. ROBBINS: Thank you all for arriving back 4 for day two. We had a very exciting day yesterday and 5 we expect nothing less from today. Before we begin, I 6 just want to make a few housekeeping announcements. If 7 you have a cell phone or other device that beeps, please 8 make sure to turn it off. And panelists, if you could 9 speak directly into your microphone, and if you want to 10 respond to a question or comment, please just remember 11 to raise your table tent. 12 Again we would like to thank the Direct 13 Marketing Association and the Association For 14 Interactive Marketing and Cisco Systems for providing us 15 refreshments today. 16 Before we begin day two, I would like to 17 introduce Commissioner Jon Leibowitz who will start off 18 the day by giving us some introductory remarks. 19 Commissioner Leibowitz is our newest Commissioner and 20 started here in September of 2004. Prior to joining the 21 FTC, Commissioner Leibowitz was the Vice President of 22 Congressional Affairs for the Motion Picture Association 23 of America, and held several positions on Capitol Hill, 24 including Democratic Chief Counsel and Staff Director 25 for the U.S. Senate Antitrust Subcommittee. For The Record, Inc. Waldorf, Maryland (301) 870-8025 4 1 I am pleased this morning to introduce to you 2 Jon Leibowitz. 3 (Applause.) 4 COMMISSIONER LEIBOWITZ: Thank you, Colleen, for 5 making me look much more impressive than I know myself 6 to be. Good morning. As noted, I am Jon Leibowitz. 7 Thank you all for being here at this early hour, very 8 early, to participate in the Email Authentication 9 Summit. I want to open the second day by encouraging 10 everyone in this room with an interest in 11 authentication, whether an IP-based model, 12 signature-based model, some other technology or some 13 combination of technologies to work together to develop 14 the tools necessary to help solve the spam problem. 15 It's a goal we all share, and it's one that's attainable 16 through your cooperation and creativity. 17 With that said, let me also thank the National 18 Institute of Standards and Technology for cohosting this 19 event, doing some of the heavy lifting yesterday in 20 moderating the technical panels and helping us sort 21 through the various authentication proposals and 22 acronyms. From BATV, IIM and DomainKeys, to SIDF and 23 CSV, not to be confused, if you live in the Washington 24 area, with CVS. 25 Courtesy of my colleagues on the Commission, let For The Record, Inc. Waldorf, Maryland (301) 870-8025 5 1 me add the usual disclaimer: The views I express here 2 today are my own and not necessarily those of the 3 Federal Trade Commission or any other individual 4 Commissioner or of my staff. 5 As many of you know, the Federal Trade 6 Commission -- can you guys hear me in the back? Over 7 there? Okay. 8 As many of you know, the Federal Trade 9 Commission has a special interest in the electronic 10 marketplace. In the past decade, a whole new 11 free-flowing exchange of goods and information has 12 emerged, with huge benefits for consumers. As this 13 cybermarket has blossomed, in fact even expanded 14 exponentially, so, too, have technological challenges 15 and the creativity of those engaging in cyberfraud and I 16 suppose cybernuisance. Simply put, we can't let spam, 17 spyware and spoofing, undermine the promise of the 18 Internet. 19 Most people have a visceral reaction to spam, 20 and it's no wonder why. Consider the statistics: 21 Experts say that spam accounts for as much as 70 percent 22 of all email and costs businesses $10 billion a year, 23 much of that passed on to consumers. It also caused 24 consumers countless hours of wasted time and 25 immeasurable frustrations. Consider, also, that the For The Record, Inc. Waldorf, Maryland (301) 870-8025 6 1 vast majority of spam is deceptive, from false headers 2 and phony identities to simply fraudulent offerings. 3 Just look at the spam in our inboxes, and here's 4 some examples that came from one of my staffer's 5 computers in the last week, ads for discount software, 6 sometimes spelled W-E-A-R. Here's the tip: If they 7 can't spell it, you shouldn't buy it. Unbelievably low 8 interest rate mortgages, too unbelievable to be true, 9 phishing expeditions by anglers looking to steal your 10 financial account information and maybe even your 11 identity, and ads for herbal Viagra and so-called 12 vitality products that won't extend anything except the 13 time you spend on your computer. That was a joke. I 14 know it's early in the morning. 15 More seriously, spam is a problem that has 16 literally hit home with me. I have two young girls, 17 ages seven and nine, who have just started to navigate 18 the Internet. The oldest one has her own email account, 19 she's often online IMing her friends, and I am just 20 extremely concerned and more than a little nervous that 21 she and her younger sister are going to encounter this 22 type of brazen and offensive spam and something far 23 worse. Obviously we need a multifaceted approach to 24 combat this serious problem. 25 Aggressive law enforcement is one part of the For The Record, Inc. Waldorf, Maryland (301) 870-8025 7 1 solution. The Commission has brought dozens of 2 spam-related cases and the CAN-SPAM Act has given the 3 Commission and ISPs, I think, some additional tools to 4 go after illegal spammers. 5 Last month the Commission filed its first 6 spyware case against defendants who downloaded spyware, 7 changed consumers' homepages and search engines, 8 delivered a barrage of pop-up ads and caused CD-ROM 9 trays to open and close. Even more outrageous, the 10 defendants then sold anti-spyware products to the very 11 consumers to fix the same problems the defendants had 12 originally caused. 13 To my mind, this is not only wrong, it is just 14 unacceptable, and hopefully the Commission's law 15 enforcement efforts against spam and spyware will send a 16 strong signal to the Internet crooks that we are on the 17 beat. 18 It was also heartening to see AOL, Earthlink, 19 Yahoo! and Microsoft join together last month to file 20 more CAN'T-SPAM cases. For those of you who know me, 21 you know I am not a big fan of private litigation, too 22 often in America people say "I'll see you in court" 23 rather than "let's work this out," but these lawsuits or 24 this lawsuit and the criminal prosecution in Virginia 25 seem to me to be totally appropriate. For The Record, Inc. Waldorf, Maryland (301) 870-8025 8 1 Beyond law enforcement, though, we need consumer 2 and business education to increase awareness and help 3 users secure their computers and avoid being spammed and 4 scammed. 5 The Commission is vigorously pursuing education 6 initiatives and some corporations and consumer 7 organizations are also beginning to help build consumer 8 awareness. These efforts are crucial. But law 9 enforcement and education alone can't do the trick. And 10 rather than a do-not-email registry that could cause as 11 many problems as it would solve, at least until 12 technology improves, we do need to approach it beyond 13 filtering, which could be both over and underinclusive. 14 For example, one of my staffers emailed a draft 15 of my remarks home with "spam summit" in the subject 16 line and it was caught by her spam filter, and filed 17 along with the rest of the daily diluted spam. The next 18 day she emailed another draft and just labeled this one 19 "summit," again it was caught by a spam filter, but at 20 least it was retrievable. 21 Discussed at length during yesterday's session, 22 several authentication systems do show promise, 23 including both IP-based and signature-based approaches. 24 Market forces appear to be working, but in determining 25 some type of authentication system, or combination of For The Record, Inc. Waldorf, Maryland (301) 870-8025 9 1 systems, we need to ensure balance and flexibility to 2 accommodate various types of users.