[Cryptography] Well Known Bad Idea: ask users to make security decisions, or If you *work* for Apple, please update your email software

John Levine johnl at iecc.com
Sun Oct 5 20:31:05 EDT 2025


  [[ definitely not worth posting to the list ]]

It appears that Henry Baker <hbaker1 at pipeline.com> said:
>Apple: I have to actually click on the "display name" to get the full email address to show
>(on MacOS); I have no idea how to get the email address to show in iPhoneOS -- I usually
>have to display the entire email message in "raw ascii format" (with all headers), which is one
>hell of a lot uglier than a simple email address.  This is 100X too far beyond the capabilities
>of many/most family members, as well as beyond the capabilities of 95% of the Apple
>user base.

I understand that you personally really really want to see the email address rather than
the display name.  For me, I occasionally tap twice to see the address but it's rarely
an issue.

But why should anyone else care?  Please don't claim it has some essential security benefit
since people who have done actual research know that it doesn't.

R's,
John


More information about the cryptography mailing list