Re: New draft, new idea
Grant Baillie <[email protected]> Thu, 5 Feb 2004 10:28:27 -0800
| Newsgroups | gmane.ietf.imaa |
|---|---|
| Message-ID | <[email protected]> |
On 05 Feb 2004, at 9:47 AM, Paul Hoffman / IMC wrote: > > At 9:23 AM -0800 2/5/04, Grant Baillie wrote: >> (1) What's to stop me from sending you a mail from some email >> address, using address-map: to change its display value to >> "[email protected]", and asking you to reply with your credit >> card #? It seems that there's a potential for a new kind of social >> engineering attack here, unless MUAs are quite careful about how >> mapped addresses are displayed. > > The display name is only for the mailbox, so you have to already be > able to receive mail at the same domain name in order to spoof. In > your example, the sender has to be able to receive mail at > your-bank.com in order for this ruse to work. Oh, right. Still, I think there are possibilities for abuse (eg, spoofing upper management inside a company, or other users in large domains). >> I think there's more to it than just maintaining a mapping in the >> client's local address book: Formats like vcard (and LDAP, I think) >> would need to have some kind of standardized "display email address" >> field to remain interoperable. > > Why a "display email address" field? Why not just a second email > address that has internationalized characters in the mailbox part? Hmmm.... I guess that would work. MUAs would just have to be careful about using the (a?) non-internationalized address in the envelope / headers. --Grant