#2846: Security vulnerability in APOP authentication Comment (by brendan): From the BNR, 0-31 appears to be legal when quoted in the local part. As long as the current MD5 collision generators need characters above 127, I think this is OK. -- Ticket URL: <http://dev.mutt.org/trac/ticket/2846#comment:5>