Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If your bank is any good, it doesn't send you emails about your account activity or problems. Yet, it could, if everybody was signing their emails.


My bank and broker send an email or text telling me to log in and check the "secure email" system on the bank's site.



This has already been touched on in the article and the comments. DKIM isn't any good when it tells you that the email from fraudulent mybankk.com is verified just because the phishers were clever enough to set up DKIM on their site.


That's true. I guess we need something like https://en.wikipedia.org/wiki/Extended_Validation_Certificat... for email then.

I'm not sure how PGP would help though, as the user also has to check, if the email from his bank was signed with the correct key. Checking the exact domain name is something he can already do and I guess is also easier to understand.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: