Steffen Nurpmeso wrote in
 <20260107174539.0sEouyXz@steffen%sdaoden.eu>:
 |Richard Clayton wrote in
 | <[email protected]>:
 ..

You have not answered John Mears' question.

 ||z can now be found as a "recipe" under the r= and r.fieldname= tags

So i have read a bit of your draft -05, and stopped when stumbled
over the indeed mostly-inclusive approach of header fields.

For one i think that the "ignore 'X-'" stuff would possibly
benefit from a reference to RFC 6648, which is from 2012, as the
IETF at that time deprecated exactly those headers via "Best
Current Practice", and it seems problematic when within the
thousands of documents one has to read there are de-facto
counteracting proposals and methods, and silently so.

And i think that in hindsight to John Mears' problem the idea of
being "practically all inclusive" when creating header checksums
is asking for problems in real life.  Doing it that way means
that any mess stored in headers is part of the signature of a
domain, inclusive random headers created by users.
Wouldn't this mean that any hard cut of such headers will end up
requiring "T"rust to survive?

Given that collected RFC 5863 "organizational trust" can be
nothing but a volatile thing, any user could, and if by accident,
when playing around, out of boredom or juvenile horniness, like
creating a header with a base64ified image, for example porn (ok,
there is Wikipedia with lots of images, and all that, but..),
that is caught and hard cut by a spam checker, declassify the
reputation of the entire domain?
I think it is blue eyed aka improvidence aka a problem to cause
such trouble for domain keys, for both the domain, and the user.
(For example i have a Schopenhauer citation in my headers which
translates to something dreadful, and i seem to realize that in
certain US states you are in trouble with the police if you spit
out a -- yuck -- chewing gum, maybe rightely so, but/and if i
bring all that together, i would fear future trouble if i would
be you.  Or at least for the users of another IETF email thing.)

Anyhow, not and never for ACDC that way.  Not expecting an answer,
but maybe the above is worth considering.

Ciao,

--steffen
|
|Der Kragenbaer,                The moon bear,
|der holt sich munter           he cheerfully and one by one
|einen nach dem anderen runter  wa.ks himself off
|(By Robert Gernhardt)

_______________________________________________
Ietf-dkim mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to