Re: [Bimi] Today's BoF

Dave Crocker <dhc@dcrocker.net> Mon, 01 April 2019 00:00 UTC

Return-Path: <dhc@dcrocker.net>
X-Original-To: bimi@ietfa.amsl.com
Delivered-To: bimi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4B11B1201A3 for <bimi@ietfa.amsl.com>; Sun, 31 Mar 2019 17:00:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.401
X-Spam-Level:
X-Spam-Status: No, score=-2.401 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_INVALID=0.1, DKIM_SIGNED=0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=fail (1024-bit key) reason="fail (message has been altered)" header.d=dcrocker.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4MWtAGc3WtPs for <bimi@ietfa.amsl.com>; Sun, 31 Mar 2019 17:00:10 -0700 (PDT)
Received: from simon.songbird.com (simon.songbird.com [72.52.113.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EB0F01201BE for <bimi@ietf.org>; Sun, 31 Mar 2019 17:00:09 -0700 (PDT)
Received: from [192.168.1.85] (108-226-162-63.lightspeed.sntcca.sbcglobal.net [108.226.162.63]) (authenticated bits=0) by simon.songbird.com (8.14.4/8.14.4/Debian-4.1ubuntu1.1) with ESMTP id x3101lK2005457 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NOT); Sun, 31 Mar 2019 17:01:48 -0700
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=dcrocker.net; s=default; t=1554076908; bh=oO7oV84QDv9J83rUsAugapzryyBfHSCmrvWxYWen72E=; h=Subject:To:Cc:References:From:Reply-To:Date:In-Reply-To:From; b=C5EXUVtXAS8B3r50wEKxK9xbOCL16viJkdpA+XAv9m9Px5j7RH3yBZQPAmpUnNh6U ohLQd21eDHTd5JEcDfWq0CSouddu1Gnj5wFlvUzp1XEJ6yCWKAQ260WRVKvIi00bd+ m3e3LJbyasO72QLlLt8uCI4ts1uKMzm70xZQLI5U=
To: Wei Chuang <weihaw=40google.com@dmarc.ietf.org>, John C Klensin <john-ietf@jck.com>
Cc: bimi@ietf.org
References: <309EBD4AD64BE436663E721D@PSB> <CAAFsWK3uhFfeEt34wRJRQen1YVK4uNo=nxJoaGc4m84Y1J+ctQ@mail.gmail.com>
From: Dave Crocker <dhc@dcrocker.net>
Reply-To: dcrocker@bbiw.net
Organization: Brandenburg InternetWorking
Message-ID: <f4544345-bf26-a6fa-8697-e3b9e2ed8a51@dcrocker.net>
Date: Sun, 31 Mar 2019 16:59:56 -0700
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.6.1
MIME-Version: 1.0
In-Reply-To: <CAAFsWK3uhFfeEt34wRJRQen1YVK4uNo=nxJoaGc4m84Y1J+ctQ@mail.gmail.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/bimi/NlxjU2ufbjIRInfmrjlEZ9wiYbw>
Subject: Re: [Bimi] Today's BoF
X-BeenThere: bimi@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Brand Indicators for Message Identification <bimi.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/bimi>, <mailto:bimi-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/bimi/>
List-Post: <mailto:bimi@ietf.org>
List-Help: <mailto:bimi-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/bimi>, <mailto:bimi-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 01 Apr 2019 00:00:12 -0000

On 3/31/2019 4:48 PM, Wei Chuang wrote:
> The BIMI proposal depends on different, domain based authentication 
> technologies that have been already deployed at scale.

The message-based domain-validation components are not the issue.

The use of certificate authorities is.  At scale they are problematic, 
in spite of the tendency to claim that their use for TLS says they aren't.

And their use for linkage between domain name and logo is, since there's 
no history at scale.

And any effort to use 'validated' logos at scale has no history, where 
the challenges in doing that have been well- and often-cited.

d/

-- 
Dave Crocker
Brandenburg InternetWorking
bbiw.net