Re: New draft, new idea

Grant Baillie <[email protected]> Thu, 5 Feb 2004 10:28:27 -0800
Newsgroups gmane.ietf.imaa
Message-ID <[email protected]>
On 05 Feb 2004, at 9:47 AM, Paul Hoffman / IMC wrote:

>
> At 9:23 AM -0800 2/5/04, Grant Baillie wrote:
>> (1) What's to stop me from sending you a mail from some email 
>> address, using address-map: to change its display value to 
>> "[email protected]", and asking you to reply with your credit 
>> card #? It seems that there's a potential for a new kind of social 
>> engineering attack here, unless MUAs are quite careful about how 
>> mapped addresses are displayed.
>
> The display name is only for the mailbox, so you have to already be 
> able to receive mail at the same domain name in order to spoof. In 
> your example, the sender has to be able to receive mail at 
> your-bank.com in order for this ruse to work.

Oh, right. Still, I think there are possibilities for abuse (eg, 
spoofing upper management inside a company, or other users in large 
domains).

>> I think there's more to it than just maintaining a mapping in the 
>> client's local address book: Formats like vcard (and LDAP, I think) 
>> would need to have some kind of standardized "display email address" 
>> field to remain interoperable.
>
> Why a "display email address" field? Why not just a second email 
> address that has internationalized characters in the mailbox part?

Hmmm.... I guess that would work. MUAs would just have to be careful 
about using the (a?) non-internationalized address in the envelope / 
headers.

--Grant