Re: [EAI] Thinking about requirements / downgrade
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [EAI] Thinking about requirements / downgrade



Ernie Dainow wrote:

Harald Alvestrand wrote:
The overarching issue found with variants of this proposal previously rejected was:

Can we guarantee (for a sufficiently strong version of "guarantee") that there are no valid mailboxes that "just happen to look like" the Punycoded strings?
I'm not sure it is necessary for a standard to guarantee this. I think it is just the responsibility of email administration to avoid name collisions. Currently, when a new email address is requested, the email administrator for the domain on which the name is requested (or email admin software) will not grant the email address if
1. the address (local name) is assigned to someone else on the domain.
2. the address is already in use as an alias on another email account on the domain.
My worry is about what happens if the recipient tries to decode the left-hand side as if it was a Punycoded name when it is not. Unless one can tell the difference between those domains that use Punycoded LHS and those that do not, a recipient will apply the Punycode decoding to left-hand sides indiscriminately. This can lead to similar effects as the "Bush hid the facts" bug (see http://en.wikipedia.org/wiki/Bush_hid_the_facts for details).

                        Harald


Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.