Tag: query-response verification

  • How Aliases Protect Students and Parents from Phishing

    Earlier drafts of the Contact Initiative imagined a public, browsable directory where anyone could look up a verified teacher or administrator. Review identified an obvious problem: a browsable list of every verified educator in the country is also a ready-made target list for harassment.

    Query-Response, Not Browsable

    Version 5 replaces the browsable directory with query-response verification. A relying party submits a specific claimed identity — “is this person currently a teacher at this school?” — and receives a confirm or deny answer, rate-limited to prevent bulk scraping. This preserves the entire anti-phishing benefit of the original idea while removing the enumeration risk.

    Aliases That Can Be Replaced Without Losing Identity

    Institution-issued aliases follow role-based, human-readable patterns and can be rotated or reissued at any time without affecting the underlying identity anchor or its attestation history. A compromised or leaked alias can simply be retired and replaced — no loss of identity continuity, and a much smaller practical target for spear-phishing.

    A Non-Negotiable Security Baseline

    Every domain issued under the Contact Initiative — production or sandbox — is proposed to carry DNSSEC and registry lock to prevent hijacking, enforced SPF, DKIM, and DMARC with a reject policy to stop spoofed mail from delivering as genuine, and a published, cryptographically signed list of real Contact Initiative domains so relying parties can spot look-alikes.