[DNSOP] Re: [art] Re: DNS-designated Public Key Author ities (DKA)
Paul Kyzivat <[email protected]>
| Newsgroups | gmane.ietf.dnsop,gmane.ietf.apps-discuss |
|---|---|
| Message-ID | <[email protected]> |
Bob, > There is a less obvious effect of not normalizing: social engineering > attacks. An attacker wanting to attack [email protected] registers a key > for [email protected] as a decoy. Some number of users will query for > [email protected] when they intend [email protected], get the wrong key > and use it for encryption or signature verification. Since the attacker > has the private key for [email protected], the attacker can impersonate > [email protected] using the key for [email protected]. This is not a > cryptographic attack, but its effect on alice is the same. It is folly to try to guess an email address. You will usually fail one way or another, because there is so much competition for "good" names. That's true even if the name is as unusual as mine. (I couldn't get [email protected] - it was already taken.) For that reason providers assign names with disambiguating additions (such as Alice86 and Bob47.) IMO, an email provider ideally SHOULD NOT assign very similar looking user names (e.g., "alice86" and "Alice86") to different, unaffiliated entities. That would prevent the attack you describe. That is different from having a single normalized format for all. Thanks, Paul _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]