Re: New "Old-" headers emerging from the horizon

Sam Varshavchik <[email protected]>
Newsgroups gmane.mail.imap.courier.general
Message-ID <[email protected]>
Bernd Wurst writes:

> Am 28.01.24 um 00:53 schrieb Sam Varshavchik:
>> But that will break the DKIM Signature.
>
> Why?
>
> DKIM specifies at each message, which header fields are part of the signed  
> data set. BIMI spec says, these two headers may never be part of a DKIM  
> signature.

The wording in the draft was confusing:

# If the original email message had a DKIM signature, it has already been 
# evaluated. Removing the BIMI-Location header at this point should not 
# invalidate the signature since it should not be included within it per this 
# spec.

I originally parsed it to mean that DKIM covers these headers so they can be  
removed after DKIM verification.

But the last sentence contradicts it.

> So it mustn't break DKIM if you leave them or remove them or rename them.
>
>
> I doubt that there will ever be end user MUAs to trust incoming BIMI- 
> Indicator headers. Would be an invitation for phishing. It's unrealistic  
> that a MUA can rely on all mail servers out there implementing this feature  
> set.

The whole point of these headers is for the MUA to blindly trust them when  
they read it from the server, and leave it up to the server to inject these  
headers upon successful validation via DNS lookups.

> The idea that all mail servers - including those that don't care anything  
> about BIMI brainf*** - should remove those silly headers is intrusive.

I think this where this is headed. I'll repeat what I wrote earlier. This is  
what's going to happen:

• More MUAs will trust these headers, if present, as per this spec. They  
will be automatically shown, if they're present.

• The hostile actors will start using them in phish mails, to make them look  
more authentication. Here's an E-mail from your bank, telling you that you  
need to reset your password. And it's got the bank's logo proudly next to  
it. This will work beautifully with mail servers ignoring the existing  
headers.

• When this blows up the fingers will be pointed at the ISPs: their mail  
servers are non-compliant with this latest super-duper spec. ISPs will be  
pressured in this manner to adjust their mail servers to strip off any  
existing fields.

• The next step will be to present ISPs as offering sub-standard service if  
they don't validate email brands. Your ISP sucks, Outlook doesn't show the  
spiffy logo from my bank or vendor, next to their mail.

_______________________________________________
courier-users mailing list
[email protected]
Unsubscribe: https://lists.sourceforge.net/lists/listinfo/courier-users
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYKAB0WIQRupkKLJP96aW75pIOKYPgoojZS4gUCZbecvAAKCRCKYPgoojZS
4uhbAQC4W1FagQe0YaMZPeDvDWDgfHEigBK3Rro7nRIZ03vJIwEAz0b/01UHhZjg
InbgwKI8yEfOYsmkMwcFxlzINaBgjgQ=
=WaaS
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.