Re: New draft, new idea

Paul Hoffman / IMC <[email protected]> Thu, 5 Feb 2004 09:47:18 -0800
Newsgroups gmane.ietf.imaa
Message-ID <p06020442bc4830c88e06@[63.202.92.155]>
At 9:23 AM -0800 2/5/04, Grant Baillie wrote:
>(1) What's to stop me from sending you a mail from some email 
>address, using address-map: to change its display value to 
>"[email protected]", and asking you to reply with your credit 
>card #? It seems that there's a potential for a new kind of social 
>engineering attack here, unless MUAs are quite careful about how 
>mapped addresses are displayed.

The display name is only for the mailbox, so you have to already be 
able to receive mail at the same domain name in order to spoof. In 
your example, the sender has to be able to receive mail at 
your-bank.com in order for this ruse to work.

>I think there's more to it than just maintaining a mapping in the 
>client's local address book: Formats like vcard (and LDAP, I think) 
>would need to have some kind of standardized "display email address" 
>field to remain interoperable.

Why a "display email address" field? Why not just a second email 
address that has internationalized characters in the mailbox part?

>(3) There are implications for IMAP clients that fetch the ENVELOPE 
>message attribute to show message summary information: They wouldn't 
>be able to display addresses properly without issuing an extra 
>header fetch.

Good point.

--Paul Hoffman, Director
--Internet Mail Consortium