> One of the best methods to protect against these attacks is strict isolation. If you isolate the email message using sandboxed iframes you restrict the ability to break out of trusted boundaries. If you are not using sandboxed iframes, always be careful when allowing custom attributes and check for HTML/CSS gadgets. Use a strict allow list of characters when validating keywords and names to avoid mutation when using the CSSOM.
iframes should be the first layer of any defense-in-depth against user-submitted content.
But the remote server doesn't see the hash? This casts doubt into the content, since the attack was clearly not tested. Am I missing something?
It's a pretty interesting post though, but hardly surprising - touching and rendering untrusted content is always risky.
You can get away with not giving your phone only with google and outlook but you will need recovery addresses. For those I am using proton mail, they don't require anything and for those I have the recovery key saved somewhere.
Also you will get error messages in thunderbird from outlook that it doesn't work... but it does work !
I did all that in anger but if I had to do it again I would just use one of those super cheap provider where you pay 1$ a month or even by usage and use TB with that.
Hey mail, fastmail, they all look great but I don't even pay that much to my bank or any other services so no way I am spending 5 euros or more a month for email
Haven't tried it yet though, done some reading but don't know enough to be sure their proposed paradigm is valid.
HTML email is just something that people semi-randomly do. It should be rejected/ignored if you are at all concerned about privacy and/or security.
This is actively harmful advice that could easily get someone fired.
Yeah no shit.
But when most of the articles submitted here don't work without JavaScript, this comment seems really irrelevant.
I guess my question would be why does something so benign and common aggravate you so much? That feels like an exhausting way to live.
- The page will load noticeably faster (and likely be faster in a number of other ways).
- The semantics are more predictable (buttons, links, scrolling, text selection, find-in-page, etc. all behave the same as on other websites).
- The page will work in Tor Browser's "maximum security" setting.
- The page is more likely to work better in screen readers or with other less-commonly used web browsing tools.
- The page is more likely to work in older browser versions.
- It used to be that a JS-free page had lighter CPU usage, though newer CSS features and browser setTimeout/setInterval throttling have changed the balance somewhat.
- The page does not require running untrusted/proprietary code on your computer (the browser sandbox is a small comfort).
From what I can see, they're doing so codeblocks have proper highlighting but also can be copied & pasted. It's a reasonable choice.
They're not lazy. They even have long, accurate alt tag descriptions for all their images.
If I would guess, they have an inherent desire to see their work viewed in exactly the way it was intended, so they deliberately refuse progressive enhancement when it's a matter of reader choice. The visually impaired who have no choice are accommodated. Anti-JS readers are not.
Most importantly, enabling JS makes it much easier to spy on users, so I automatically assume that the website tries to spy on my and feel attacked.
I agree it's not healthy, and I didn't care about privacy that much in the past. I guess this may be caused by my work experience.
Oh that's all, is it?
Why don't we give up on HTML in emails and just use markdown instead? It is readable and writable by humans and doesn't have insane security problems.
It seems to be our AI overlords' preferred communication format too so it would future proof email for the aipocalypse.
This would, alas, make the the people sending you marketing emails very unhappy. Maybe they could attach a PDF instead, I'm sure that would be safe.
/s