Re: rough sketch of a potential solution

Steve Hole <[email protected]> Mon, 17 Nov 2003 15:01:34 -0700
Newsgroups gmane.ietf.imaa
Message-ID <[email protected]>
On Mon, 17 Nov 2003 13:48:57 -0500 Keith Moore <[email protected]> wrote:

> Then (unless the mappings are signed by the domain) you permit a rogue 
> third-party to add additional headers that say "my.new.address@domain 
> is equivalent to the From address" and sign the message with 
> my.new.address@domain - making it appear that the (perhaps altered) 
> message was signed by the From address, when it wasn't.

Yes.   This is already an issue with existing implementations in my 
experience.    Most MUA have hard coded assumptions that there is a single
From address and the just do simple strcmp operations.   It really is an 
S/MIME processing and general MUA implementation issue, but, if possible, 
we don't want to make it any worse than it already is.   Or, if there is 
no way to not make it worse, provide some solid advice for how MUAs should
be doing this type of processing.

> I don't have any trouble at all arguing that this isn't a good policy.
> Basically, it sucks.  Who knows, maybe crap like this (error indications
> when there's really no error, or a mismatch between what people need and
> what S/MIME wants to impose) is part of the reason that S/MIME hasn't
> been widely adopted.

It certainly is a major contributing reason.
 
> People don't have any trouble grasping the idea that the person who
> notarizes a piece of paper isn't necessarily the same as the person or
> people who signed that piece of paper.  This concept is no more
> difficult.

Actually ... they do.   I was greatly surprised to find this out when we 
started doing large scale secure messaging roleouts.   Once again, this is
primarily an MUA processing issue, but I suspect that it has imaa 
implications.   Joe average user does NOT get the difference between the 
author of the content and the name on the letter -- even though there are 
many examples of this in the paper world.   Surprisingly, I have been told
that in the paper world people don't get it either and is one of the top 
reasons for insurance litigation.

The expectation is likely to be that the MUA should figure it out and make
sure that they match and then present it that way.   In any case, detailed
presentation rules (advice) will have to be made to make this successful.
 
> OTOH it's appears possible to develop an interim profile that allows use
> of S/MIME with this scheme.  Everyone who uses S/MIME would define his
> keys in  terms of his fallback address.  And unless/until a better
> interface were developed, MUAs that support S/MIME would need to display
> the sender's fallback address from signed mail (rather than the
> recipient's perferred form) as "who authored/signed the message".
> 
> The address mapping service could even be used to supply the S/MIME keys
> (along with certificates, of course) for recipients that accept
> encrypted mail.

This sounds reasonable.   There will be substantial implementation lag for
anything that forces change in MUA display policies.   In fact, MS has 
formally stated that Outlook Express will have no further feature work 
done on it and it is the single largest deployed desktop MUA.   This bodes
poorly for any kind of presentation display mapping making into the 
general Internet in a hurry.

Cheers.

---
Steve Hole
Chief Technology Officer - Billing and Payment Systems
ACI Worldwide
<mailto:[email protected]>
Phone: 780-424-4922