Re: [EAI] Thinking about requirements / downgrade
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [EAI] Thinking about requirements / downgrade



> My worry is about what happens if the recipient tries to decode the
> left-hand side as if it was a Punycoded name when it is not. Unless one
> can tell the difference between those domains that use Punycoded LHS and
> those that do not, a recipient will apply the Punycode decoding to
> left-hand sides indiscriminately. This can lead to similar effects as
> the "Bush hid the facts" bug (see
> http://en.wikipedia.org/wiki/Bush_hid_the_facts for details).

Yup.

But I think it's worth the improvement for behavior in the 99.999% case.  Maybe we could get statistics for how many account names actually look like this.  Also we could pick something really wierd (like the q.-_.z or something).
 
IDN had the same issue, but seems to have succeeded (at least in that respect.)

I don't think we can improve the "other" fallback mechanism sufficiently to be interesting.  We've pretty much proven that pairing of addresses only works in limited scenarios and breaks pretty quickly when deviating from the simple scenarios.

-Shawn

Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.