Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Email Privacy is Lost
Scott Granneman, 2004-07-29

As if the common use of "web bugs" inside spam was not enough, companies are using new techniques to watch and track the private emails you read, forward, print, and more.

Comments Mode:
Email Privacy is Lost 2004-07-30
Clownface
Mozilla Thunderbird has three options for viewing messages: force to plain text, show original HTML and show simple HTML: I would expect the IFRAMEs not to be shown in simple HTML mode.

CF ...

[ more ]  [ reply ]
Email Privacy is Lost 2004-07-30
Anonymous (1 replies)
I am not web developper and I don't exactly how IFRAMES work, but if your e-mail client doesn't "allow messages to load external references from the Internet", how is the IFRAME going to invade your privacy ?

An external reference to the Internet should not be limited to an image or a webbug, it ...

[ more ]  [ reply ]
Email Privacy is Lost 2004-08-03
Damon McMahon <inst_karma@hotmail.com>
Not a web developer myself, either, but i imagine should get around network level defences. I think content filtering is the only reliable way to sort this one out....

[ more ]  [ reply ]
Email Privacy is Lost 2004-07-30
Anonymous (1 replies)
SMTP/POP etc are all plain text to begin with... Someone once said and i wish i remember who... "Email is as secure as a postcard written in pencil". Simply put, privacy and email dont go together. If you start using PGP and such then the point is valid....

[ more ]  [ reply ]
Email Privacy is Lost 2004-07-30
Anonymous (1 replies)
"Email : a postcard written in pencil"
by Larry Rogers
http://www.cert.org/homeusers/email_postcard.html...

[ more ]  [ reply ]
Email Privacy is Lost 2004-08-04
Anonymous
Postcard sure, but not when it is inside of a companie's network.......

[ more ]  [ reply ]
Email Privacy is Lost 2004-07-30
Matthew Murphy (1 replies)
Scott,

Just FYI, you *can* block e-mail from loading an IFRAME, even with HTML rendering, in Outlook Express and Outlook (all versions).

If you set Outlook (Express) to open e-mail in "Restricted Sites" (default in Outlook 2000 and later, and Outlook Express 6.0 SP1), frames are disabled autom...

[ more ]  [ reply ]
Email Privacy is Lost 2004-08-04
Anonymous (1 replies)
Until Microsoft delivers yet another security zone bug, anyway....

[ more ]  [ reply ]
Email Privacy is Lost 2004-08-11
Matthew Murphy
They've yet to deliver a security zone bug that works from the Restricted Sites Zone. That's because Restricted Sites blocks practically ALL active content (scripts, ActiveX, Java, frames, file downloads, ...).

As such, OE 6.0 SP1 / Outlook when properly updated will *NEVER* be vulnerable to usi...

[ more ]  [ reply ]
Email Privacy is Lost 2004-07-31
Anonymous
Somehow, I see the popularity of demime[1] incresing tenfold very soon. While designed primarily for mailing lists, even its author has realized demime's potential for normal, non-ML messages.

[1]http://scifi.squawk.com/demime.html...

[ more ]  [ reply ]
Email Privacy is Lost 2004-08-02
Anonymous
As I've been saying for years, html is for web sites and plain text is for email.

I use Mozilla Thunderbird and it is always set to force plain text. Web bugs, IFrame tricks, or simply garish background colors are all banished. There isn't anything you need to say that can't be said with plain ...

[ more ]  [ reply ]
Devil's advocate: Email Privacy is Lost 2004-08-02
BWC (1 replies)
While the potential for future abuse of IFrames technology is there in spades, I don't see anything in your laundry-list of features of the ReadNotify service that isn't offered by FedEx, UPS or the postal service in their delivery and tracking of packages and snail mail. Or do you think those track...

[ more ]  [ reply ]
Devil&#39;s advocate: Email Privacy is Lost 2004-08-04
Anonymous
Hi BWC,

one idea behind Scott's denying links to company websites could be not to raise their search engine positioning.

If you know Google (and also others by now) uses an algorithm relying on external linking to web pages this makes complete sense.

Eric...

[ more ]  [ reply ]
Email Privacy is Lost 2004-08-02
J.T.
Am I incorrect in assuming (at least for the time being) that in order for ReadNotify's services to work, at some point the message or iframe responses have to passed to ReadNotify's networks so that they can track the activity?

If not, then blocking all traffic to and from their ip addresses at ...

[ more ]  [ reply ]
Email Privacy is Lost 2004-08-03
Anonymous
Sylpheed + Dillo also do the trick (from a long time ago BTW).

Cheers
Jorge.-...

[ more ]  [ reply ]
[COMMENT] Email Privacy is Lost 2004-08-03
Bob Radvanovsky
To reply, no, privacy isn't entirely lost. There are capabilities within the SMTP protocol that permit (for sake of better terms) "piggybacking" in which text-based steganography *may* be utilized. The proof-of-concept is tedious and slow, but I have written a whitepaper that *could* show how it c...

[ more ]  [ reply ]
What's wrong with text-only mail readers? 2004-08-04
Anonymous (1 replies)
People laugh at me for using Pine. I laugh last.
--Louis ...

[ more ]  [ reply ]
What&#39;s wrong with text-only mail readers? 2004-08-06
Anonymous
Nothing is wrong with them. Most people get scared though when they see a terminal with text, and prefer Outlook because they "know how it works".
Pine never gave me an email virus (read: outlook virus). An added advantage is being able to read one's email from anywhere, as long as SSH is available...

[ more ]  [ reply ]
Read/Delivery Receipts in Outlook/Exchange 2004-08-04
An Exchange admin (1 replies)
"Many other email programs have similar options available (unless you're using Outlook to check an account on an Exchange server, in which case you're hosed)."

This is true for Delivery Receipts, but not for Read Receipts, in Outlook 2003/Exchange 2003. You can set Outlook to accept, deny, or as...

[ more ]  [ reply ]
Read/Delivery Receipts in Outlook/Exchange 2004-08-04
TMullen
I sent Scott a message similar to this... But to be precise, the delivery receipt has nothing to do with the "recipient getting" the message. It has to do with it being delivered to the mailbox within the message store itself. The system admin message does say "delivered to the following recipien...

[ more ]  [ reply ]
Mozilla mail converts HTML to plain text 2004-08-04
Anonymous
Mozilla has an option for showing HTML as simplified plain text. That will probably do the trick. If the conversion is not good enough, I either read the source HTML code directly or reply to the sender asking for the message in a decent format....

[ more ]  [ reply ]
Email Privacy is Lost 2004-08-11
Anonymous
One possible method would be to use content filtering plugins/mechanisms which can search the email contents for HTML tags and move them into folders, so for instance if we have IFRAME tags, just move the message to junk/trash. This is already possible in many mail clients - Pegasus mail, Mozilla, ...

[ more ]  [ reply ]
Email Privacy is Lost 2005-12-14
Anonymous (1 replies)
I know I'm responding to something more than a year old, but hey...

My solution at work is nice. We're behind a proxy server, and I simply dont give thunderbird the proxy details. Since Firefox and Thunderbird are not incestuously married like Outlook and IE, Thunderbird cannot load anything rm...

[ more ]  [ reply ]
Re: Email Privacy is Lost 2006-10-08
Anonymous (1 replies)
Um - not to state the obvious, but, it's the person who *writes* the email who owns it, the contents therein, and would be the only person with any "privacy" stake in the message. What you choose to do with someone elses email you get is something they have a right to know - especially if it's one ...

[ more ]  [ reply ]
Re: Re: Email Privacy is Lost 2008-03-05
Anonymous
You send me an email, and it is mine to do with what I choose. Once it hits my inbox, your ownership and control over the contents is gone....

[ more ]  [ reply ]
Email Privacy is Lost... Does it really matter? 2006-01-11
Anonymous (1 replies)
Hey! Let's take this whole Privacy issue one step further!!!

Case scenario for the group...

The holiday season just passed so hopefully some of you can relate:

I go on Amazon.com, purchase a gift and send it via UPS to my friend across the country. According to UPS the gift SHOULD arrive 2 ...

[ more ]  [ reply ]
Re: Email Privacy is Lost... Does it really matter? YES! 2006-02-16
Anonymous
Are you serious? Sending a parcel is clearly not subject to the same abuse of an email and to have a parcel trackable it is an expensive service plus the reciever can still elect not to receive the parcel and sign for it thinking I do not know this sender "Freedom fighters of Zamboolia", perhaps its...

[ more ]  [ reply ]
Email Privacy is Lost 2006-11-25
CC
I can't be the only one who doesn't open mail from people I don't know......

[ more ]  [ reply ]
Email Privacy is Lost 2007-01-24
Anonymous
On the Mac I know of 2 programs (Mailsmith & Gyaz Mail) that render the text version of HTML messages as text & treat the HTML portion as an attachment. ("Proper" HTML mail actually contains the text twice) Most spammers are too lazy to create a proper mail so no text version appears, they are immed...

[ more ]  [ reply ]
Email Privacy is Lost 2008-04-14
G2Realtor
Scott, I appreciate your views and respect them. However... in this world of electronic signatures, eMail transmission of important documents, such as elements of a contract, it important that the sender be able to validate receipt of a post, particularly if the post has an important attachment... p...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus