San Francisco, February 20, 2018 – Providing increased protection for people who use email and websites to communicate with the U.S. government, most federal civilian agencies have begun to adopt additional anti-abuse technologies outlined in a recent U.S. Department of Homeland Security directive. The DHS will be recognized for this progress when its chief cybersecurity official presents the keynote address at the M3AAWG 42nd General Meeting in San Francisco tomorrow.
“Over two-thirds of agencies have taken critical steps in enhancing email security and protecting users against email spoofing, up from less than 20 percent on the day the directive was issued,” said Jeanette Manfra, assistant secretary for the Office of Cybersecurity and Communications, DHS. “It is crucial for U.S. citizens to trust that an email from a government agency is legitimate.”
M3AAWG Chairman of the Board Severin Walker said, “We estimate that only about 35 percent of Fortune 500 companies are using DMARC today so this high adoption rate is a significant accomplishment, along with implementing the other security measures in the directive. Several of the major data breaches we've seen recently have started from phishing emails, which can be hard to identify, but these steps can help prevent these fake messages from getting to users and are important in protecting American citizens.”
DHS issued the directive in October 2017 calling for civilian agencies within the federal government to adopt proven industry standards over the course of a year that can help safeguard the confidentiality of internet-delivered data, minimize spam and protect against phishing. Binding Operational Directive 18-01 requires agencies to:
- Enable STARTTLS for better email security. This “opportunistic TLS” protocol supports encrypted email as it moves across the internet and helps protect against man-in-the-middle attacks where criminals eavesdrop on email communications without the users’ knowledge. (See TLS for Mail: M3AAWG Initial Recommendations for background information.)
- Improve email authentication by using SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail) and DMARC (Domain-based Message Authentication, Reporting and Conformance), making spam and phishing emails easier to identify and block.
- Improve web security with HTTP Strict Transport Security (HSTS) so that users’ browsers select the more secure HTTPS address option when navigating to a government agency’s website.
All of the cited technologies were developed or actively championed by M3AAWG over the last several years and are often referenced in the best practices documents it publishes to help the industry fight online abuse and crime. This includes Operation Safety-Net, Best Practices to Address Online, Mobile and Telephony Threats, which M3AAWG co-published with UCENet (Unsolicited Communications Enforcement Network, formerly the London Action Plan), describing exploitations aimed at businesses and governments with expert advice on how to protect against them, according to Walker.
A M3AAWG certificate of merit will be presented to the DHS on February 21 during the keynote for the work by the National Protection and Programs Directorate’s CS&C Office in implementing these standards across its civilian agencies. The M3AAWG 42nd General Meeting is expected to attract over 500 security experts, public policy advisors, law enforcement personnel and researchers during the February 19-22 event. It will offer over 50 sessions with authorities sharing information on email and text messaging, mobile and telephony threats, malware, Internet of Things security, hosting and cloud services, and DNS abuse.
About the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG)
The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) is where the industry comes together to work against bots, malware, spam, viruses, denial-of-service attacks and other online exploitation. M3AAWG (www.m3aawg.org) members represent more than one billion mailboxes from some of the largest network operators worldwide. It leverages the depth and experience of its global membership to tackle abuse on existing networks and new emerging services through technology, collaboration and public policy. It also works to educate global policy makers on the technical and operational issues related to online abuse and messaging. Headquartered in San Francisco, Calif., M3AAWG is driven by market needs and supported by major network operators and messaging providers.
# # #
Media Contact: pr@m3aawg.org
M3AAWG Board of Directors: AT&T (NYSE: T); Cloudmark, Inc.; Comcast (NASDAQ: CMCSA); dotmailer; Endurance International Group; Facebook; Google; LinkedIn; Microsoft Corp.; Oath (Yahoo and AOL); Orange (NYSE and Euronext: ORA); Proofpoint; Rackspace; Return Path; SendGrid, Inc.; Vade Secure and Verisign.
M3AAWG Full Members: 1&1 Internet AG; Agora, Inc.; Akamai Technologies; Cisco Systems, Inc.; CloudFlare; Cyren; ExactTarget, Inc.; IBM; iContact/Vocus; Inteliquent; Internet Initiative Japan (IIJ, NASDAQ: IIJI); Liberty Global; Listrak; Litmus; McAfee Inc.; Mimecast; Oracle Marketing Cloud; OVH; PayPal; Rackspace; Spamhaus; SparkPost; Splio; Symantec; USAA; and Valimail
A complete member list is available at http://www.m3aawg.org/about/roster.