[media-types] [IANA #1443809] application/vnd.vnd.zo ho-document.writer registration request

"David Dong via RT" <[email protected]>
Newsgroups gmane.ietf.types
Message-ID <[email protected]>
Hi Darrel (filling in for Amanda),

The requester has accepted the replacement text suggested.

Can the vnd.vnd.zoho-document.writer and vnd.zoho.spreadsheetml.sheet registration requests now be approved, with this change?

Thank you.

Best regards,

David Dong
IANA Services Sr. Specialist

On Sun Mar 15 03:39:51 2026, [email protected] wrote:
> Hi Amanda,
> 
> Sorry for the slow response on these.
> 
> The clarification from Zoho is helpful - the intent is clear, but I
> don't think appending it to the existing text is the right approach.
> The problem is the original paragraph itself:
> 
> > "Recipients need to understand that they are at the 'mercy' of the
> > sender, when receiving this type of data, since data will be executed
> > on their system, and the security of their machines can be violated."
> 
> This reads as a warning against ever accepting content of this type.
> For comparison, the application/vnd.openxmlformats-
> officedocument.wordprocessingml.document registration, which faces
> essentially the same risks, handles it like this:
> 
> > "An OOXML document of this subtype may contain executable contents
> > other than macros or Active-X controls... However, such executable
> > contents are beyond [the spec]. Such executable contents are not
> > invoked by MS Office and similar office suites."
> 
> I'd suggest Zoho replace the alarming paragraph with something along
> the lines of:
> 
> > "A document of this subtype may contain executable content, since the
> > underlying ZIP container allows such content. However, such
> > executable content is not invoked by [Zoho Writer / Zoho Sheet]."
> 
> This is factually equivalent to what Zoho clarified, but I think more
> appropriate for a registration template. The same change should apply
> to both registrations.
> 
> Darrel
> ________________________________
> From: Amanda Baber via RT <[email protected]>
> Sent: Wednesday, March 11, 2026 4:49 PM
> Cc: [email protected] <[email protected]>; Darrel Miller
> <[email protected]>
> Subject: [IANA #1443809] application/vnd.vnd.zoho-document.writer
> registration request
> 
> Hi Darrel,
> 
> Resending this response from February 25th. #1 of 2.
> 
> thanks,
> Amanda
> 
> On Wed Feb 25 01:43:24 2026, amanda.baber wrote:
> > Hi Darrel,
> >
> > Response from the requester:
> >
> > ===
> >
> > It is similar to the risks a docx file received from a sender. The
> > docx file can contain
> > any malware, but it will not be executed by the MS Word program.
> >
> > Similarly, the doc file received from a sender can contain any
> > malware, but it will
> > not be executed by the Zoho Writer program.
> >
> > Please get back to us for any clarifications in this regard.
> >
> > ===
> >
> > Does that work? Should those first two paragraphs be added to the
> > security considerations, if they confirm that this is their
> > intention?
> >
> > We'll remove the extra "vnd."
> >
> > thanks,
> > Amanda
> >
> > On Sat Feb 21 19:13:16 2026, [email protected] wrote:
> > > The name of this subtype is not valid due to the duplicate "vnd.".
> > > It
> > > should be vnd.zoho-document.writer.
> > >
> > >
> > > *
> > > Recipients need to understand that they are at the
> > > > "mercy" of the sender, when receiving this type of data, since
> > > > data
> > > > will be executed on their system, and the security of their
> > > > machines
> > > > can be violated.
> > >
> > >
> > > This comment is concerning. It would be good to get more clarity as
> > > to
> > > what the risks are here.  This statement is sufficiently alarmist
> > > that
> > > nobody should be accepting data with this media type.
> > >
> > > Darrel
> > > ________________________________
> > > From: Amanda Baber via RT <[email protected]>
> > > Sent: Wednesday, February 18, 2026 2:40 PM
> > > Cc: [email protected] <[email protected]>; Darrel Miller
> > > <[email protected]>
> > > Subject: [IANA #1443809] application/vnd.vnd.zoho-document.writer
> > > registration request
> > >
> > > Hi Darrel,
> > >
> > > Sending a reminder for this request from February 11th.
> > >
> > > thanks,
> > > Amanda
> > >
> > > On Wed Feb 11 19:02:45 2026, amanda.baber wrote:
> > > > Hi Darrel,
> > > >
> > > > Would you be able to review this new request for us by February
> > > > 25th?
> > > >
> > > > You approved a Zoho media type last month, but wrote, "While RFC
> > > > 6838
> > > > Section 4.4 (https://www.rfc editor.org/rfc/rfc6838.html#section-
> > > > 4.4)
> > > > does not require public specifications for vendor tree
> > > > registrations,
> > > > I recommend that Zoho consider publishing at least a basic format
> > > > specification for this media type given its intended COMMON
> > > > usage.
> > > > Public documentation would improve interoperability and
> > > > transparency
> > > > for recipients of .zshow files." That advice was passed on.
> > > >
> > > > thanks,
> > > > Amanda
> > > >
> > > > =====
> > > >
> > > > Name: Manivannan Subburaj
> > > >
> > > > Email: [email protected]
> > > >
> > > > Media type name: application
> > > >
> > > > Media subtype name: vnd.vnd.zoho-document.writer
> > > >
> > > > Required parameters: N/A
> > > >
> > > > Optional parameters: N/A
> > > >
> > > > Encoding considerations: binary
> > > >
> > > > This media type may require encoding on transports not capable of
> > > > handling binary.
> > > >
> > > > Security considerations: It is a ZIP package containing json
> > > > files,
> > > > image files.
> > > >
> > > > An zdoc document of this sub-type may contain executable content;
> > > > such
> > > > executable contents are not invoked by Zoho Writer.
> > > >
> > > > An zdoc document of this sub-type may contain personal
> > > > information,
> > > > but cannot be encrypted. It may include hyper-links to other
> > > > objects.
> > > > Implementors should pay special attention to security of
> > > > resolving
> > > > such external references.
> > > >
> > > > There are no mechanisms in zdoc document to verify the integrity
> > > > of
> > > > documents (e.g. digital signatures). Users have to rely on
> > > > external
> > > > applications, should such integrity verification be required.
> > > >
> > > > As with most application types this data is intended for
> > > > interpretation by a program that understands the data on the
> > > > recipient's system. Recipients need to understand that they are
> > > > at
> > > > the
> > > > "mercy" of the sender, when receiving this type of data, since
> > > > data
> > > > will be executed on their system, and the security of their
> > > > machines
> > > > can be violated.
> > > >
> > > > Interoperability considerations: None
> > > >
> > > > Published specification: None
> > > >
> > > > Applications which use this media: Zoho Writer
> > > >
> > > > Fragment identifier considerations: None
> > > >
> > > > Restrictions on usage: None
> > > >
> > > > Provisional registration? (standards tree only): No
> > > >
> > > > Additional information:
> > > >
> > > > 1. Deprecated alias names for this type: None
> > > > 2. Magic number(s): 50 4b 03 04 as in ZIP
> > > > 3. File extension(s): zdoc
> > > > 4. Macintosh file type code: No specified Macintosh file type
> > > > code(s)
> > > > for Zoho Writer.
> > > > 5. Object Identifiers: None
> > > >
> > > > General Comments:
> > > >
> > > > Person to contact for further information:
> > > >
> > > > 1. Name: Ganeshprabhu Rajendran
> > > > 2. Email: [email protected]
> > > >
> > > > Intended usage: COMMON
> > > >
> > > > Author/Change controller: [email protected]

_______________________________________________
media-types mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.