{"id":19418,"date":"2022-06-23T06:30:09","date_gmt":"2022-06-23T14:30:09","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/06\/23\/news-13151\/"},"modified":"2022-06-23T06:30:09","modified_gmt":"2022-06-23T14:30:09","slug":"news-13151","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/06\/23\/news-13151\/","title":{"rendered":"Apple says it\u2019s time your business ran BIMI"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2018\/02\/email_password_hack_data_breach_phishing_thinkstock_856957034-100750737-large.3x2.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Thu, 23 Jun 2022 06:41:00 -0700<\/strong><\/p>\n<p>Apple will add another obstacle against successful phishing attacks in <a href=\"https:\/\/www.computerworld.com\/article\/3663035\/wwdc-22-what-apples-big-plans-mean-for-business.html\">iOS 16, iPadOS 16, and macOS Ventura<\/a>, which will show a company\u2019s official logo to help recipients recognize genuine from fake emails.<\/p>\n<p>Apple\u2019s forthcoming operating systems will support Brand Indicators for Message Identification (BIMI). This is a specification to enable the use of brand-controlled logos within emails and will be a way to tell recipients that an email genuinely comes from the company concerned. Google <a href=\"https:\/\/cloud.google.com\/blog\/products\/g-suite\/gsuite-security-updates-for-gmail-meet-chat-and-admin\" rel=\"noopener nofollow\" target=\"_blank\">has supported BIMI since 2021<\/a>.<\/p>\n<p>BIMI requires that companies authenticate their email using DMARC. Described by the IETF in more detail <a href=\"https:\/\/tools.ietf.org\/html\/rfc7489\" rel=\"nofollow noopener\" target=\"_blank\">in a March 2015 document<\/a>, DMARC helps mail administrators\u00a0prevent hackers and other attackers from spoofing their organization and domain.\u00a0<\/p>\n<p>The feature won\u2019t provide complete peace of mind.<\/p>\n<p>But what BIMI does provide is a visual way to assess trust when receiving a message, helping protect us against phishing and ransomware exploits by making it far more challenging for criminals to impersonate brand names in emails.<\/p>\n<p>That\u2019s important in the pluralistic sense \u2014 we\u2019ve all experienced attempts at malware infection buried in emails that purport to come from big brands.<\/p>\n<p>It may also help protect enterprise communications by making it more challenging to successfully launch phishing and targeted attempts against companies or supply chain partners.<\/p>\n<p>This is particularly important given that ransomware attackers are currently targeting smaller firms as larger entities put better protection in place \u2014 and that manufacturing firms often rely on outmoded security practices. That is why the relatively recent US <a href=\"https:\/\/www.cisa.gov\/critical-infrastructure-sectors\" rel=\"noopener nofollow\" target=\"_blank\">Cybersecurity &amp; Infrastructure Security Agency<\/a> has designated manufacturing as one of the critical US sectors that need better security protection.<\/p>\n<p>The main use is B2C marketing, of course. Marketers will make extensive use of BIMI as they attempt to persuade customers to open email marketing campaigns.<\/p>\n<p>The magic marketing sauce of combining a trusted brand with relevant content will remain essential to success. It is worth taking note of a <a href=\"https:\/\/go.redsift.com\/red-sift-and-entrust-partnership.html\" rel=\"nofollow noopener\" target=\"_blank\">recent study <\/a>that suggests consumers are more likely to open emails that display a logo beside the email, and that this kind of branding also improves brand recognition over time.<\/p>\n<p>BIMI lets brands verify the authenticity of emails they send. Once verified, the system can show the company logo in a relevant position within a supporting email client. BIMI is a text file that is kept on the sender\u2019s server, which ISPs handling end-user traffic can then check to verify authenticity.<\/p>\n<p>That integration between BIMI, DMARC, and the email client makes it challenging for spammers to figure out how to show their spoof logo in the same spot. The effect is that customers can see if an email is genuine and can delete those that aren\u2019t without ever opening the offending message, further reducing the risk of accidentally running malicious code.<\/p>\n<p>Apple\u2019s decision to support BIMI in Mail echoes industry acceptance of the standard.\u00a0 Google, Yahoo! Mail, AOL, Verizon, and Microsoft all support it. Apple\u2019s addition means the standard has achieved critical mass.<\/p>\n<p>This isn\u2019t the only attempt to lock down the internet experience taking place across Apple\u2019s platforms in its next OS updates. Its decision to <a href=\"https:\/\/www.computerworld.com\/article\/3663430\/wwdc-apple-cloudflare-fastly-plot-the-end-of-captcha.html\">standardize an alternative to CAPTCHA<\/a> will reduce friction online (and help protect user IP addresses). Its support for next generation authentication in the form of passkeys will be seen as a major step toward <a href=\"https:\/\/www.applemust.com\/apple-google-and-microsoft-want-fido-to-kill-passwords\/\" rel=\"noopener nofollow\" target=\"_blank\">replacing password protection<\/a> with more effective biometric account\/service security. Apple continues to invest in privacy, with better protection against cross-site scripting on the way and <a href=\"https:\/\/www.computerworld.com\/article\/3663681\/how-apple-improved-enterprise-deployments-at-wwdc.html\">improvements in endpoint security<\/a> also on the horizon as <a href=\"https:\/\/www.computerworld.com\/article\/3663052\/wwdc22-apple-brings-declarative-device-management-to-the-mac.html\">declarative device management comes to the Mac<\/a>.<\/p>\n<p><em>Please follow me on\u00a0<\/em><a href=\"https:\/\/twitter.com\/jonnyevans_cw\" rel=\"nofollow noopener\" target=\"_blank\"><em>Twitter<\/em><\/a><em>, or join me in the\u00a0<a href=\"https:\/\/mewe.com\/join\/appleholics_bar_and_grill\" rel=\"nofollow noopener\" target=\"_blank\">AppleHolic\u2019s bar &amp; grill<\/a>\u00a0and\u00a0<\/em><a href=\"https:\/\/mewe.com\/join\/apple_discussions\" rel=\"nofollow noopener\" target=\"_blank\"><em>Apple Discussions<\/em><\/a><em>\u00a0groups on MeWe.<\/em><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3665088\/apple-says-its-time-your-business-ran-bimi.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2018\/02\/email_password_hack_data_breach_phishing_thinkstock_856957034-100750737-large.3x2.jpg?auto=webp&amp;quality=85,70\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Thu, 23 Jun 2022 06:41:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>Apple will add another obstacle against successful phishing attacks in <a href=\"https:\/\/www.computerworld.com\/article\/3663035\/wwdc-22-what-apples-big-plans-mean-for-business.html\">iOS 16, iPadOS 16, and macOS Ventura<\/a>, which will show a company\u2019s official logo to help recipients recognize genuine from fake emails.<\/p>\n<h2><strong>Brand Indicators for Message Identification<\/strong><\/h2>\n<p>Apple\u2019s forthcoming operating systems will support Brand Indicators for Message Identification (BIMI). This is a specification to enable the use of brand-controlled logos within emails and will be a way to tell recipients that an email genuinely comes from the company concerned. Google <a href=\"https:\/\/cloud.google.com\/blog\/products\/g-suite\/gsuite-security-updates-for-gmail-meet-chat-and-admin\" rel=\"noopener nofollow\" target=\"_blank\">has supported BIMI since 2021<\/a>.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3665088\/apple-says-its-time-your-business-ran-bimi.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[2211,13942,10480,10403,714],"class_list":["post-19418","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-apple","tag-email-clients","tag-ios","tag-macos","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19418","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19418"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19418\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19418"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19418"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19418"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}