Re: New draft, new idea
Paul Hoffman / IMC <[email protected]> Thu, 5 Feb 2004 09:47:18 -0800
| Newsgroups | gmane.ietf.imaa |
|---|---|
| Message-ID | <p06020442bc4830c88e06@[63.202.92.155]> |
At 9:23 AM -0800 2/5/04, Grant Baillie wrote: >(1) What's to stop me from sending you a mail from some email >address, using address-map: to change its display value to >"[email protected]", and asking you to reply with your credit >card #? It seems that there's a potential for a new kind of social >engineering attack here, unless MUAs are quite careful about how >mapped addresses are displayed. The display name is only for the mailbox, so you have to already be able to receive mail at the same domain name in order to spoof. In your example, the sender has to be able to receive mail at your-bank.com in order for this ruse to work. >I think there's more to it than just maintaining a mapping in the >client's local address book: Formats like vcard (and LDAP, I think) >would need to have some kind of standardized "display email address" >field to remain interoperable. Why a "display email address" field? Why not just a second email address that has internationalized characters in the mailbox part? >(3) There are implications for IMAP clients that fetch the ENVELOPE >message attribute to show message summary information: They wouldn't >be able to display addresses properly without issuing an extra >header fetch. Good point. --Paul Hoffman, Director --Internet Mail Consortium