Re: [EAI] RFC 5335

Randall Gellens <rg+ietf@randy.pensive.org> Wed, 20 April 2016 19:21 UTC

Return-Path: <rg+ietf@randy.pensive.org>
X-Original-To: ima@ietfa.amsl.com
Delivered-To: ima@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4DF0A12E3B3 for <ima@ietfa.amsl.com>; Wed, 20 Apr 2016 12:21:53 -0700 (PDT)
X-Quarantine-ID: <l_yXFDYDztHd>
X-Virus-Scanned: amavisd-new at amsl.com
X-Amavis-Alert: BAD HEADER SECTION, Duplicate header field: "MIME-Version"
X-Spam-Flag: NO
X-Spam-Score: -1.39
X-Spam-Level:
X-Spam-Status: No, score=-1.39 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.996, SUBJ_ALL_CAPS=1.506] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id l_yXFDYDztHd for <ima@ietfa.amsl.com>; Wed, 20 Apr 2016 12:21:52 -0700 (PDT)
Received: from turing.pensive.org (turing.pensive.org [99.111.97.161]) by ietfa.amsl.com (Postfix) with ESMTP id 1B35412E2E1 for <ima@ietf.org>; Wed, 20 Apr 2016 12:21:52 -0700 (PDT)
Received: from [10.79.2.241] (99.111.97.161) by turing.pensive.org with ESMTP (EIMS X 3.3.9); Wed, 20 Apr 2016 12:21:51 -0700
Mime-Version: 1.0
Message-Id: <p0624060bd33d863602be@[10.79.2.241]>
In-Reply-To: <01PZ8G9K8DGM00005M@mauve.mrochek.com>
References: <782609480-681267200@mail.monicals.com> <AECA29E7C05D83CE9736F93A@JcK-HP8200.jck.com> <01PZ8G9K8DGM00005M@mauve.mrochek.com>
X-Mailer: Eudora for Mac OS X
Date: Wed, 20 Apr 2016 12:21:46 -0700
To: ned+ima@mrochek.com, John C Klensin <john-ietf@jck.com>
From: Randall Gellens <rg+ietf@randy.pensive.org>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format="flowed"
X-Random-Sig-Tag: 1.0b28
X-Random-Sig-Tag: 1.0b28
X-Random-Sig-Tag: 1.0b28
X-Random-Sig-Tag: 1.0b28
Archived-At: <http://mailarchive.ietf.org/arch/msg/ima/Fuh4Eft1sF8vL2vdYwbKm-xSKk4>
Cc: Alan Ayres <adayres@monicals.com>, ima@ietf.org
Subject: Re: [EAI] RFC 5335
X-BeenThere: ima@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "EAI \(Email Address Internationalization\)" <ima.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ima>, <mailto:ima-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ima/>
List-Post: <mailto:ima@ietf.org>
List-Help: <mailto:ima-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ima>, <mailto:ima-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Apr 2016 19:21:53 -0000

At 11:18 AM -0700 4/20/16, ned+ima@mrochek.com wrote:

>  FWIW, I dug up the actual report, which is available for download here:
>
>  http://windowsitpro.com/isheriff/office-365-security
>
>  The relevant part of the report appears to be this paragraph:

Thanks for digging up the report an extracting the relevant bits, Ned.


>    ASCII characters have been exonerated and
>    exploited worldwide.

Any idea what this sentence means?  It seems contradictory to say 
that something has been both exonerated and exploited.  (There have 
been ASCII-based attacks in the past, such as certain control codes, 
the old source-routing ("%" and "!") characters, and embedded nulls, 
but none of those have to do with EAI, and as far as I know, all have 
been fixed in current versions of any even moderately used mail 
servers.)

-- 
Randall Gellens
Opinions are personal;    facts are suspect;    I speak for myself only
-------------- Randomly selected tag: ---------------
I pride myself on the fact that my work has no
socially  redeeming value.       --John Waters