[DNSOP] Re: [art] Re: DNS-designated Public Key Author ities (DKA)
"John R Levine" <[email protected]>
| Newsgroups | gmane.ietf.dnsop,gmane.ietf.apps-discuss |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 8 Jun 2026, Paul Kyzivat wrote: >> and trying to register its variations. Instead if an attacker wants to >> attack a specific ID, say [email protected], the attacker can register >> [email protected], and a public key for it, then social engineering >> attacks are possible, > > IIUC, that isn't possible with gmail. It considers [email protected] to > be an alias for [email protected], and so wouldn't permit it to be > registered as a new account. I believe that he was describing a broken key server that tried to "normalize" email addresses and wrongly guessed that those were different, rather than working with Gmail and only letting you register one key since Gmail tells it if they're equivalent. Of course, say, [email protected]@outlook.com and [email protected] really would be different addresses. Yes they're similar but if they're different users, they're different. I happen to be at an ICANN meeting this week and they are deep in that swamp. My favorite was that unicom and unicorn were too similar, can only register one of them. R's, John _______________________________________________ DNSOP mailing list -- [email protected] To unsubscribe send an email to [email protected]