Re: Notification authentication in CPIM
[email protected] (John D. Ramsdell)
| Newsgroups | gmane.ietf.impp |
|---|---|
| Message-ID | <[email protected]> |
Graham Klyne <[email protected]> writes: > BTW, why the concern with covert channels? .... In secure applications, any unused and undisplayed free text headers are open for use as covert channels. For 'message/CPIM-PIDF' format messages, the solution is simple, define the profile so that each message contains exactly three headers, a 'From' header, a 'To' header', and a 'DateTime' header. This discussion reminds me to ask about 'Subject' headers in CPIM-MSGFMT. Where are they expected to be displayed? Most IM systems I've used display nothing but message content. Note that in secure applications, the content in every 'Subject' header must be displayed. The result would be visual clutter in a GUI. On the other hand, an application could simply reject messages with 'Subject' headers. In any event, what are they for, and what must every application do with them? The concern I just expressed about covert channels is probably valid for applications with security requirements that are stronger than those that need concern this working group. John [reminder: [email protected] for non-technical discussions, please]