Re: New draft, new idea

Paul Hoffman / IMC <[email protected]> Thu, 5 Feb 2004 13:19:37 -0800
Newsgroups gmane.ietf.imaa
Message-ID <p0602044dbc486135c90d@[63.202.92.155]>
At 2:45 PM -0500 2/5/04, Martin Duerst wrote:
>We already have display names that can be in
>any language/script we want.

Display names are *not* mailbox names. Further, there is no 
interoperability between display names unless all MUAs looking at the 
message can display characters from the named character set.

>  There are user agents that when they find a
>display name, they almost completely isolate the user from the actual address
>(MS Outlook Express is the one I know).

And look how well that works. :-) Seriously, that functionality is 
one of the major causes of mail sent to the wrong people, because 
someone picked out an email "name" from their address book.

>  And display names travel much
>closer to the actual address, so the chance that the association gets
>lost is clearly lower.

That would only be true if the display names were universally 
displayable. They're not. In fact, it is the small minority that are 
encoded with UTF-anything.

>With this proposal, people in China or Japan or India,... will still
>have to use ASCII addresses on their business cards, letterheads,...
>even for language-internal communication. In that sense, the proposal
>provides significantly less functionality even than the IMAA draft.

True. It has less functionality, and fewer problems. This group needs 
to determine where on those axes we want to be.

>I can also not see how the 'alternate' (internationalized) addresses
>could get used in other places such as URIs/IRIs,...

If the IRI spec ever got finished, we might be able to tell. :-) 
There is no effect on URIs: they remain as they are now. This spec is 
for MUAs displaying names only.

>Although by using base64, code can be reused, the raw base64 means
>that for 'middleware' that analyses/filters/... mails, new code
>may have to be written.

Could you elaborate? The Base64 appears in a new header. Why would 
middleware care about it?

>Security issues should not just mention digital signatures, but
>should also say that unless such certificates are checked every
>time the email address is used, it can lead to problems because
>an email address will look like something but may actually be
>something completely different.

The Security Considerations section talks only about certificates, 
not about signatures. I don't see the effect on digital signatures; 
could you elaborate?

At 2:57 PM -0500 2/5/04, Martin Duerst wrote:
>>Not at all. The display name has no connection to the mailbox name 
>>anywhere other than in the MUA. Therefore, two people at ccil.org 
>>could say the display name for their two different mailboxes is 
>>"Jose'". The display is local to the MUA reading the message.
>
>Well, in theory, this is true. However, as far as I understand, the
>Address-map headers and therefore these mappings travel from one
>MUA to another.

Correct.

>  So conflicts would inevitably arise, either by having
>the MUA keep two mappings with the same display LHS but different
>ascii addresses (which would sooner or later have the wrong thing
>sent to the wrong mailbox because the user cannot distinguish
>these two), or by the MUA saying "You've got mail. By the way,
>there is an Address-map header for =Jose'@example.com= different
>from the one I already have, should I overwrite the mapping?".

Also correct. IMAA had definitive, one-to-one mappings. This proposal 
has non-definitive, make-them-up-as-you-go mappings.

--Paul Hoffman, Director
--Internet Mail Consortium