Also nobody really uses X-Face, it's irrelevant.
1. BIMI logos are in color.
oh yeah, and:
2. BIMI logos are inherently a tracking pixel so the sender can see when readers read the mail.
The next section also literally says "This document does not cover the different verification and reputation mechanisms available, but BIMI relies upon them to be in deployed in order to control abuse." It's not a standard meant for establishing trust, it does not mandate requiring a VMC.
Nobody really forces you to use HTTPS either, it's not a "monopolizing" standard if someone doesn't trust you without.
And again, if you have a way of establishing just as much trust without such a labour-intensive/expensive verification process, please do share.
As I said in the linked post, logo verification is not a problem which can be solved. Identical trademarks can legitimately be issued in different fields, and both still be valid. Let’s say you are a brick manufacturer, and have paid an arm and a leg to a VMC certificate authority (previously a HTTPS EV certificate authority) for your logo, a nice iconic square logo. Then someone else can simply come along, register a flower shop in another country, use a different VMC issuer and get an identical logo issued to them. They can now send e-mail invoices to your customers with your logo on it, legitimately obtained, and the BIMI system will have trained your customers to trust your logo.
Any fix for this you try to implement will make the system even less usable for its stated purpose, or more suited to only large players and unusable in practice for smaller operators.
What do you mean "no matter what the spec says", it is the spec we're talking about. It is what you argued against several times.
If you had started with saying "big providers' implementations of BIMI", then it wouldn't be wrong to say it's required but it's still not "monopolizing". Requiring you to prove your claims using a third unrelated party is simply not that.
> As I said in the linked post, logo verification is not a problem which can be solved. [...] and the BIMI system will have trained your customers to trust your logo.
There are caveats to each system. It does not mean the problem is not solvable to a large extent.
Secondly, it's pretty clear who to jail for the attack described. I'd say it's even a positive side of the system if that's the type of attacks we'd get.
> Any fix for this you try to implement will make the system even less usable for its stated purpose, or more suited to only large players and unusable in practice for smaller operators.
That's simply not true. The price of a VMC is really not that high for any business that doesn't only employ one man and his dog.
That’s just splitting hairs.
Yet, in practice, that is exactly what both Chrome and Firefox are trying to do.
It's also not just them, it's the vast majority of the internet community that agrees with that.
Standard are useless if majors providers apply a different de facto norm. That behavior has a name, it is called a cartel. And on some matters, that is punishable by law.
Nah, they really couldn't. Email is simply so much bigger than only Google or Microsoft.