> MUAs MUST first use the full email address provided by the user, and if that results in an authentication failure, SHOULD fall back to using the "local-part" extracted from the email address
a) This is not good enough, because it's guessing / try&error.
b) We also need to know the authentication method: Password or OAuth2 or CRAM MD5 or SCRAM or one of the other SASL mechanisms. Together with the 2 username forms, there are too many permutations (2 * 5 = 10, just for these 2 factors), and we cannot try them all.
c) The servers may block the user account after too many failed login attempts, so even one pass with all the permutations might lock the user out and make even the working (!) config fail as well. Which, together, makes guessing fairly futile.
We need both username form and authentication method, and we need to be certain about both of them.
Bug 342242 Comment 75 Edit History
Note: The actual edited comment in the bug view page will always show the original commenter’s name and original timestamp.
> MUAs MUST first use the full email address provided by the user, and if that results in an authentication failure, SHOULD fall back to using the "local-part" extracted from the email address
a) This is not good enough, because it's guessing / try&error.
b) We also need to know the authentication method: Password or OAuth2 or CRAM MD5 or SCRAM or one of the other SASL mechanisms. Together with the 2 username forms, there are too many permutations (2 * 5 = 10, just for these 2 factors), and we cannot try them all.
c) The servers may block the user account after too many failed login attempts, so even one pass with all the permutations might lock the user out and make even the working (!) config fail as well. Which, together, makes guessing fairly futile.
We need both username form and authentication method, and we need to be *certain* about both of them.