Live data from Hacker News

Known Bad Email Clients

emailprivacytester.com

21–30 of 69 posts

Re: Known Bad Email Clients

#21
post #6

Evolution is the only client on Linux (that I’m aware of) that fully supports Microsoft exchange and Google out of the box without any plugins. I used thunderbird for a long time, however I got frustrated so many times after things broke after every update because essential plugins stopped working. Yes, you may say Evolution UI is old, but the software is rock solid and softwares in general are more than their GUI. I…

Thunderbird has reportedly added experimental Exchange support in 140. Though I haven't figured out how to enable and test it :)

Re: Known Bad Email Clients

#23
post #3

If only he made that much effort to get Chromium to fix the issue. The source of the problem is with a dependency of the email clients, not the email clients themselves. He is bothering small free software projects so that those small free software projects ask Chromium to fix the issue.

Just my opinion, but the dependency on Chromium is a problem in itself. You don't need a full-blown browser to render HTML email. The fact that it is no more viable for a client to ignore HTML nowadays is something unfortunate, to say the least. Real people only need Emoji support at best (or at worst), because nowadays every from your bank to your local security expert tells you "don't click on links in emails", and…

I use w3m to format HTML email for reading in emacs. It does a pretty good job with tables which are still used a lot in email formatting.

Re: Known Bad Email Clients

#24
post #15

Earlier quoted context omitted.

If only the developers of Evolution Mail made any effort to get the issue fixed in the 15 months they've known about it. It's unacceptable to sit on a privacy affecting bug like this for 15 months. This continously repeated bullshit that the source of the problem lies elsehwere is tiring. They're knowingly using a library with a security bug, and they're doing: 1. Nothing to get the devs of that library to fix it 2.…

They have done #1 and the library is WebKit and so #2 isn't happening. Not the least of which because of the lack of expertise to patch that code base but because it's dynamically linked and in most deployment scenarios they get the webkit provided by the distro. If Evolution even tried to vendor WebKit downstream packagers would patch it out so that it links to the system lib and gets security patches along with the…

...so strip the offending HTML before passing it to WebKit? What is this, kindergarten?

Re: Known Bad Email Clients

#25
post #15

Earlier quoted context omitted.

If only the developers of Evolution Mail made any effort to get the issue fixed in the 15 months they've known about it. It's unacceptable to sit on a privacy affecting bug like this for 15 months. This continously repeated bullshit that the source of the problem lies elsehwere is tiring. They're knowingly using a library with a security bug, and they're doing: 1. Nothing to get the devs of that library to fix it 2.…

They have done #1 and the library is WebKit and so #2 isn't happening. Not the least of which because of the lack of expertise to patch that code base but because it's dynamically linked and in most deployment scenarios they get the webkit provided by the distro. If Evolution even tried to vendor WebKit downstream packagers would patch it out so that it links to the system lib and gets security patches along with the…

They really haven't done number 1. A bug report was submitted, and then it has stalled for 15 months.

As of this point in time, nobody has explained to me why it would be a bad idea to add a "Do not rely on for privacy. More info" message next to the feature in Evolution Mail.

That is 100% true. Users of Evolution Mail should not rely on that feature for privacy. Because Evolution Mail has chosen to add known flawed software to their application.

And despite lacking the will or ability to fix that software, they are unwilling to take a different path to patch over the problem until it is fixed in the library, by sanitising the html and stripping problematic tags/attributes.

These are all their choices. And all of their choices lead to end users being exposed to a privacy risk, and unaware of it.

Re: Known Bad Email Clients

#26

Geary has been crashing with some regularity over the past few weeks anyway. Guess I’ll migrate to Thunderbird.

I have that problem. Too bad there is no html client that isn't a massive RAM hog.

seamonkey mail seems to work well for me

Re: Known Bad Email Clients

#27

I wasn't aware of Balsa or Geary, but it's interesting to note that the author has mentioned that they are affected by GNOME's culture. I also have found the GNOME devs to have issues with admitting any fault at all, security or otherwise, but I wasn't aware of them being linked to any email clients other than Evolution - which I have been using. What's a good app for Exchange on Linux? I could use the web app, which…

Not defending the GNOME devs as being perfect, but I'd suggest reading this from the start: https://gitlab.gnome.org/GNOME/evolution/-/issues/3095 and then deciding if the author is really being affected by a "toxic development culture" at GNOME.

Re: Known Bad Email Clients

#28

[flagged]

You forgot to say anything about the fact that they've been sitting on a privacy bug for 15 months and have done nothing to address it. You forgot to say anything about the multiple things that the bug report says they can do, to warn their users and patch over the problem on their side. You forgot to say anything about how those suggestions were met with arrogant clown and face-palm emojis.

You prefer to concentrate on the fact that I miss-directed my first bug report. You prefer to point at the fact that I requested submission to a bug bounty program, whilst ignoring the fact that I made effort to discover the issue and report it, without expecting a bounty.

It takes time and money to run https://www.emailprivacytester.com. I wont apologise for receiving the occasional bounty for doing it. Many email and webmail clients are more secure today than they would have been, thanks to my efforts.

Your comment exists only to generate drama.

Re: Known Bad Email Clients

#29

[flagged]

Evidently you did not read the linked issue very carefully as:

1. The issue still persists in the most recent upstream code of Evolution, having nothing to do with Debian or any other distribution

2. No patch is available to correct the security issue, and despite the puck passing it is not actually the responsibility of distro packagers to fix your own security bugs.

Re: Known Bad Email Clients

#30
post #3

If only he made that much effort to get Chromium to fix the issue. The source of the problem is with a dependency of the email clients, not the email clients themselves. He is bothering small free software projects so that those small free software projects ask Chromium to fix the issue.

I thought the Evolution issue was related to WebKit. Same for the other one (Geary). Does chromium also have the same issue? Regardless, it seems like these issues are all related to WebKitGTK, not Chromium.
Post reply on HN