Hacker News new | ask | show | jobs
by ocdtrekkie 628 days ago
It certainly can. Most people interact with the same organizations time and time again, so any visual indicator something is different can be useful. If you're used to seeing a bank logo on every email from your bank... and then you get an email without that logo... it's just one more visual indicator something is off, and it's more obvious than say... looking at the full email address behind the display name.

BIMI (and EV certs) should not be considered "for all organizations", but probably something worthwhile for organizations that transact in a lot of money and a lot of personal data.

1 comments

Now consider getting same visual indicators for ALL legit emails not just big companies. Which case would have a bigger recall value?

For a malicious actor spoofing a combo of SPF + DKIM + DMARC + BIMI won’t be a trivial job.

I would argue that would make it worse. I don't think any given site or user needs a personal verified email icon. A big part of the goal here is to highlight legitimate trust. Real people don't need a cryptographic proof, what they want to see is "This is really from the official company Microsoft which you've heard of" and something M1cros0ft registered in a tax haven can't technically request to participate in.

This is what I feel us tech people have missed about what the old school lock icon used to at least sort of (inaccurately) express when HTTPS was rare and what EV intended to express (although the qualification criteria needs work there).

Not everyone should be eligible for an EV cert, not everyone should be eligible for BIMI/VMC. Some sort of scale and legitimacy and manual approval (think the old school Verified checkmark before Elon bought Twitter) that not everyone qualifies for.