#htmlmail — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #htmlmail, aggregated by home.social.
-
Schwachstelle in Thunderbird Mail
Vorsicht! Das sollte nicht passieren
Mehr dazu bei https://www.heise.de/news/Thunderbird-HTML-Mails-koennen-Zugangsdaten-verraten-Update-verfuegbar-10441439.html
a-fsa.de/d/3HB
Link zu dieser Seite: https://www.aktion-freiheitstattangst.org/de/articles/9184-20250613-schwachstelle-in-thunderbird-mail.html
Link im Tor-Netzwerk: http://a6pdp5vmmw4zm5tifrc3qo2pyz7mvnk4zzimpesnckvzinubzmioddad.onion/de/articles/9184-20250613-schwachstelle-in-thunderbird-mail.html
Tags: #HTMLMail #Schwachstelle #Risiko #OpenSource #Windows #Microsoft #SMB #ServerMessageBlock #Thunderbird #Transparenz #Linux #Arbeitnehmerdatenschutz #Verbraucherdatenschutz #Verschlüsselung #Verhaltensänderung -
"It looks like your email client might not support HTML formatted email.
Try opening this email in another email client."Or, how about you just put the content of the email in the text part as well, instead of suggesting I switch to different software just to read your message?
Emails like this get deleted, unread.
-
"This is an HTML email, please update your email client to view."
No! Please update your email generation system to send plain text email. Putting aside the risks of opening HTML in email apps, where browser security isn't protecting users from the most common HTML-based attacks, HTML email is the digital equivalent of packaging products in 3 layers of plastic when 1 layer of cardboard would do. It's a waste of bandwidth and energy.
-
@micahflee given that #EFail only worked with #HTMLMail turned on, the whole things seems to me like a storm in a teacup. I mean, nobody who use PGP and cares about security lets their mail client run HTML code, right? Right?
https://www.coactivate.org/projects/disintermedia/blog/2018/04/12/get-your-html-email-off-my-lawn/ -
"This is an HTML email, please update your email client to view."
No! Please update your email generation system to send plain text email. Putting aside the risks of opening HTML in email apps, where browser security isn't protecting users from the most common HTML-based attacks, HTML email is the digital equivalent of packaging products in 3 layers of plastic when 1 layer of cardboard would do. It's a waste of bandwidth and energy.