[DNSOP] Re: [art] Re: DNS-designated Public Key Author ities (DKA)

Paul Kyzivat <[email protected]>
Newsgroups gmane.ietf.dnsop,gmane.ietf.apps-discuss
Message-ID <[email protected]>
Bob,

> There is a less obvious effect of not normalizing: social engineering 
> attacks. An attacker wanting to attack [email protected] registers a key 
> for [email protected] as a decoy. Some number of users will query for 
> [email protected] when they intend [email protected], get the wrong key 
> and use it for encryption or signature verification. Since the attacker 
> has the private key for [email protected], the attacker can impersonate 
> [email protected] using the key for [email protected]. This is not a 
> cryptographic attack, but its effect on alice is the same.

It is folly to try to guess an email address. You will usually fail one 
way or another, because there is so much competition for "good" names. 
That's true even if the name is as unusual as mine. (I couldn't get 
[email protected] - it was already taken.)

For that reason providers assign names with disambiguating additions 
(such as Alice86 and Bob47.)

IMO, an email provider ideally SHOULD NOT assign very similar looking 
user names (e.g., "alice86" and "Alice86") to different, unaffiliated 
entities. That would prevent the attack you describe. That is different 
from having a single normalized format for all.

	Thanks,
	Paul

_______________________________________________
DNSOP mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.