Re: New "Old-" headers emerging from the horizon
Sam Varshavchik <[email protected]>
| Newsgroups | gmane.mail.imap.courier.general |
|---|---|
| Message-ID | <[email protected]> |
Bernd Wurst writes: > Am 28.01.24 um 00:53 schrieb Sam Varshavchik: >> But that will break the DKIM Signature. > > Why? > > DKIM specifies at each message, which header fields are part of the signed > data set. BIMI spec says, these two headers may never be part of a DKIM > signature. The wording in the draft was confusing: # If the original email message had a DKIM signature, it has already been # evaluated. Removing the BIMI-Location header at this point should not # invalidate the signature since it should not be included within it per this # spec. I originally parsed it to mean that DKIM covers these headers so they can be removed after DKIM verification. But the last sentence contradicts it. > So it mustn't break DKIM if you leave them or remove them or rename them. > > > I doubt that there will ever be end user MUAs to trust incoming BIMI- > Indicator headers. Would be an invitation for phishing. It's unrealistic > that a MUA can rely on all mail servers out there implementing this feature > set. The whole point of these headers is for the MUA to blindly trust them when they read it from the server, and leave it up to the server to inject these headers upon successful validation via DNS lookups. > The idea that all mail servers - including those that don't care anything > about BIMI brainf*** - should remove those silly headers is intrusive. I think this where this is headed. I'll repeat what I wrote earlier. This is what's going to happen: • More MUAs will trust these headers, if present, as per this spec. They will be automatically shown, if they're present. • The hostile actors will start using them in phish mails, to make them look more authentication. Here's an E-mail from your bank, telling you that you need to reset your password. And it's got the bank's logo proudly next to it. This will work beautifully with mail servers ignoring the existing headers. • When this blows up the fingers will be pointed at the ISPs: their mail servers are non-compliant with this latest super-duper spec. ISPs will be pressured in this manner to adjust their mail servers to strip off any existing fields. • The next step will be to present ISPs as offering sub-standard service if they don't validate email brands. Your ISP sucks, Outlook doesn't show the spiffy logo from my bank or vendor, next to their mail. _______________________________________________ courier-users mailing list [email protected] Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users
signature.asc
(application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE----- iHUEABYKAB0WIQRupkKLJP96aW75pIOKYPgoojZS4gUCZbecvAAKCRCKYPgoojZS 4uhbAQC4W1FagQe0YaMZPeDvDWDgfHEigBK3Rro7nRIZ03vJIwEAz0b/01UHhZjg InbgwKI8yEfOYsmkMwcFxlzINaBgjgQ= =WaaS -----END PGP SIGNATURE-----