[Bimi] Re: Improvements on BIMI specification
Andrew C Aitchison <andrew@aitchison.me.uk> Mon, 27 January 2025 14:38 UTC
Return-Path: <andrew@aitchison.me.uk>
X-Original-To: bimi@ietfa.amsl.com
Delivered-To: bimi@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 107D5C15198F for <bimi@ietfa.amsl.com>; Mon, 27 Jan 2025 06:38:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=aitchison.me.uk
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3rjjCKUu3KmD for <bimi@ietfa.amsl.com>; Mon, 27 Jan 2025 06:38:53 -0800 (PST)
Received: from mx1.mythic-beasts.com (mx1.mythic-beasts.com [IPv6:2a00:1098:0:86:1000:0:2:1]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5169CC18DBA6 for <bimi@ietf.org>; Mon, 27 Jan 2025 06:38:53 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=aitchison.me.uk; s=mythic-beasts-k1; h=Subject:To:From:Date; bh=zBei4Hsaj0zXkFWF3nQMrOXXKSJvO0RHehchsW+MKew=; b=c1kHGO1ponQpRX6wrQWhNPHcmS KXSJZQANkgCdnRf2YPSh9cFxLNzokgp+lH3qCJ3tzyxIdlcmLm2kXAcQOT4rRoR8TGw19jaBvX35e 9JUhrltzufHPsjPOHIp7yjkQ72gJ2nZxwZoEejEFDTthhlEiuLP0ztjrJnB2iI2BgcTwxSJUdY/Y7 kQcA9DyPWSILznUyzB40mK/8MDDV0uimu9vcGhT+0V+5gb4FZSNZlXiBz5b9vi+Yol6wbisjeyKF5 vsH0TRyhbHAM4Mul8+LKtZ/ycKoLOtdkXlCabAfU0nWmenI/AVWMdRlUp5SbPPCT3N77weeJjbbhy tB4FBcGw==;
Received: by mailhub-cam-d.mythic-beasts.com with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from <andrew@aitchison.me.uk>) id 1tcQGJ-008RyJ-4o for bimi@ietf.org; Mon, 27 Jan 2025 14:38:51 +0000
Date: Mon, 27 Jan 2025 14:38:44 +0000
From: Andrew C Aitchison <andrew@aitchison.me.uk>
To: bimi@ietf.org
In-Reply-To: <dd2127b0bfb70f94f75c316af9aa9ddd@yocto.com>
Message-ID: <469a9e52-240b-7281-f98f-aa68cd268484@aitchison.me.uk>
References: <c09a997da763fb77365f9d26cd9df985@yocto.com> <8b580664-3c49-4486-bd3a-5152b712a129@zone.ee> <dd2127b0bfb70f94f75c316af9aa9ddd@yocto.com>
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="-1463807999-1452793283-1737988731=:710075"
X-BlackCat-Spam-Score: 9
Message-ID-Hash: UAVJ6S6ASJTMAX3UHFIY2F7R2O7QGJQ2
X-Message-ID-Hash: UAVJ6S6ASJTMAX3UHFIY2F7R2O7QGJQ2
X-MailFrom: andrew@aitchison.me.uk
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Bimi] Re: Improvements on BIMI specification
List-Id: Brand Indicators for Message Identification <bimi.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/bimi/VPIWX_bZc8gdu-HKtnghw-SFmVA>
List-Archive: <https://mailarchive.ietf.org/arch/browse/bimi>
List-Help: <mailto:bimi-request@ietf.org?subject=help>
List-Owner: <mailto:bimi-owner@ietf.org>
List-Post: <mailto:bimi@ietf.org>
List-Subscribe: <mailto:bimi-join@ietf.org>
List-Unsubscribe: <mailto:bimi-leave@ietf.org>
On Mon, 27 Jan 2025, Ben van Hartingsveldt | Yocto wrote:
> Taavi Eomäe schreef op 2025-01-27 13:45:
>> On 27/01/2025 15:07, Ben van Hartingsveldt | Yocto wrote:
>>> - Section 2:
> You want BIMI to work only on real emails from that company, indeed, not the
> spoofed ones. It seems that those 3 headers are now in the spec because the
> server is more knowledgable on what is fake and what is not, and only adding
> the headers to the mail when it validated the mail being authentic. I'm not
> against adding headers, but a simple "BIMI-Validated: 1" would do the same
> thing, I guess, without having breakable URLs within its headers. Also, there
> may be some already existing headers like "Authentication-Results" that can
> be used instead of introducing a new header like "BIMI-Validated".
BIMI cannot use exisiting headers for this, because they can be added by
any MTA that the message passes through.
7.8 says that BIMI-Location and BIMI-Indicator headers MUST be removed
upon reciept, otherwise the security of BIMI is compromised.
If an existing header such as Authentication-Results were used instead,
then removing it would destroy possibly needed information
(eg. it could break confirmation of DKIM signatures).
--
Andrew C. Aitchison Kendal, UK
andrew@aitchison.me.uk
- [Bimi] Improvements on BIMI specification Ben van Hartingsveldt | Yocto
- [Bimi] Re: Improvements on BIMI specification Andrew C Aitchison
- [Bimi] Re: Improvements on BIMI specification Taavi Eomäe
- [Bimi] Re: Improvements on BIMI specification Moises Dilisio
- [Bimi] Re: Improvements on BIMI specification Ben van Hartingsveldt | Yocto
- [Bimi] Re: Improvements on BIMI specification Taavi Eomäe
- [Bimi] Re: Improvements on BIMI specification Brotman, Alex
- [Bimi] Re: Improvements on BIMI specification Ben van Hartingsveldt | Yocto
- [Bimi] Re: Improvements on BIMI specification Brotman, Alex