Re: [Idna-update] emoji and security

"Asmus Freytag (c)" <asmusf@ix.netcom.com> Wed, 14 March 2018 15:38 UTC

Return-Path: <asmusf@ix.netcom.com>
X-Original-To: idna-update@ietfa.amsl.com
Delivered-To: idna-update@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DB4D71200B9 for <idna-update@ietfa.amsl.com>; Wed, 14 Mar 2018 08:38:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.821
X-Spam-Level:
X-Spam-Status: No, score=-0.821 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ix.netcom.com; domainkeys=pass (2048-bit key) header.from=asmusf@ix.netcom.com header.d=ix.netcom.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id b_evYzxxQozE for <idna-update@ietfa.amsl.com>; Wed, 14 Mar 2018 08:38:33 -0700 (PDT)
Received: from elasmtp-dupuy.atl.sa.earthlink.net (elasmtp-dupuy.atl.sa.earthlink.net [209.86.89.62]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7A6F2126C19 for <idna-update@ietf.org>; Wed, 14 Mar 2018 08:38:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ix.netcom.com; s=dk12062016; t=1521041913; bh=99X1iW6hbG+ehl5H26BVXl/XLekKcle2//om tMrEuvk=; h=Received:Subject:To:Cc:References:From:Message-ID:Date: User-Agent:MIME-Version:In-Reply-To:Content-Type: Content-Transfer-Encoding:Content-Language:X-ELNK-Trace: X-Originating-IP; b=bQYyUDMcYjf2WVFBfxwsyBxDTN6ZRxM6ak+Bq10cqdRecO HAuTYtIY81qIR4qdKrGj/4zLvdQRZsM0DwZ0KVo4vGONAlgIVSCu1JaWcSEYI9eTH89 hMD6N8buI7UUT4AZVollS2gfCu0lsII6SjHMaeH/wk/R0btHD5y+BDQjNHby7pFN5bw fPaFOM1S8sdFYkbXTN43QsX/AmeyfKSvy5abMiOsboGKTSTMpuTrrS4Jlch2HgL2BZL QMqYl+47603tuXdytzEX+LEGjt4lryqxFT1ynssuzdwIpWsYNKTq4TO6aT16Yzlryrg eXr7Qv0pKYr5BpYY/fiS8EULGOWA==
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=dk12062016; d=ix.netcom.com; b=Ew8AiVeBVHQR99FQFvzx2F7FHK3y0deX8wn6pqllb3TIhWiweDJJO9010TWb3dpdwg0n6onTCmUX+RkmVARYESw8NgdaS97jrfsqrQBP3zttaVlyYXoN9hlkb3DgoJKNLN9zIprXOgHUL09ivtCx2c/EeIfUcgIlquiBxVOZI8qV8vtYr++8Gk/KnoA5/O7SuEjxm7CbWxlQfMZ9dkHef3c2Q92wTo2ok7Fzvfm7eLNOuljKe26avV3zR0XqldGsoPebF2pRTx9WB52rgs2FFgebAVOOKd+2oOUUtOgvXBZA4dU8vKcz3rj3E9YxcYGNvJ/AFRuy+SvlzI6vVK7e4g==; h=Received:Subject:To:Cc:References:From:Message-ID:Date:User-Agent:MIME-Version:In-Reply-To:Content-Type:Content-Transfer-Encoding:Content-Language:X-ELNK-Trace:X-Originating-IP;
Received: from [71.35.186.204] (helo=[192.168.0.5]) by elasmtp-dupuy.atl.sa.earthlink.net with esmtpa (Exim 4) (envelope-from <asmusf@ix.netcom.com>) id 1ew8U3-000Ems-Dy; Wed, 14 Mar 2018 11:38:31 -0400
To: =?UTF-8?B?UGF0cmlrIEbDpGx0c3Ryw7Zt?= <paf@frobbit.se>
Cc: idna-update@ietf.org
References: <533bb471-da9b-64d0-76aa-a8a1251d256b@ix.netcom.com> <DM5PR1901MB219712F39A6297F9A147312DA2D30@DM5PR1901MB2197.namprd19.prod.outlook.com> <20180313202505.ztersmy2z5xuxlvp@mx4.yitter.info> <DM5PR1901MB2197A704B3233E5236EB703AA2D20@DM5PR1901MB2197.namprd19.prod.outlook.com> <ac2e51de-a9ad-c8ee-96b0-5b50a0e225c4@ix.netcom.com> <34EF799D-892E-48C5-93AE-AE71A8821F56@frobbit.se>
From: "Asmus Freytag (c)" <asmusf@ix.netcom.com>
Message-ID: <41524b3a-a196-7920-ea1a-2387a63e969c@ix.netcom.com>
Date: Wed, 14 Mar 2018 08:38:35 -0700
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.6.0
MIME-Version: 1.0
In-Reply-To: <34EF799D-892E-48C5-93AE-AE71A8821F56@frobbit.se>
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit
Content-Language: en-US
X-ELNK-Trace: 464f085de979d7246f36dc87813833b2c1627926350bb93ffc7db339077ee5be45f9ce73fd3619ad350badd9bab72f9c350badd9bab72f9c350badd9bab72f9c
X-Originating-IP: 71.35.186.204
Archived-At: <https://mailarchive.ietf.org/arch/msg/idna-update/MXyq7rWb359YXKVeLNz46n9rZxw>
Subject: Re: [Idna-update] emoji and security
X-BeenThere: idna-update@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "Internationalized Domain Names in Applications \(IDNA\) implementation and update discussions" <idna-update.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/idna-update>, <mailto:idna-update-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/idna-update/>
List-Post: <mailto:idna-update@ietf.org>
List-Help: <mailto:idna-update-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/idna-update>, <mailto:idna-update-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 14 Mar 2018 15:38:36 -0000

On 3/14/2018 4:04 AM, Patrik Fältström wrote:
> On 13 Mar 2018, at 20:09, Asmus Freytag wrote:
>
>> The design of IDNA2008 reflects two or three conflicting thrusts:
>>
>> 1) it was intended to be updatable to newer versions by simply applying the properties, with using an exception list as a fail-safe.
> Not really. The normative rules in the IDNA2008 standard where to be applied to the Unicode Versions so that derived property values where calculated, and this independent of the Unicode Version. There are no properties that are applied.

Thanks for providing the details; my summary of the process was a bit 
too abridged.
>
>> 2) it was intended to avoid clear-cut cases of dual encoding (via normalization)
>> 3) it was intended to be usable on all levels of the tree - therefore it could not be maximally restrictive
>     Patrik