Roundcube Webmail: SVG feImage bypasses image blocking to track email opens
21–30 of 81 posts
Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens
#22whatever happened to read receipts? I wouldn't mind allowing a sender who wants to know if I've opened their email, access to a read receipt about it.
Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens
#23I often think the best way to defeat email open tracking would be for a mainstream email client to prefetch every image when a non-spam email is received and cache it for 72 hours or so. Every email gets flagged as “opened,” so the flag is meaningless, and recipients can see the images without triggering a tracker.
Some of the big providers already do this, notably Apple and Gmail: https://www.litmus.com/blog/gmail-prefetching-images
Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens
#24Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens
#25I often think the best way to defeat email open tracking would be for a mainstream email client to prefetch every image when a non-spam email is received and cache it for 72 hours or so. Every email gets flagged as “opened,” so the flag is meaningless, and recipients can see the images without triggering a tracker.
That still provides “human” vs “bot” feedback to the sender. An automated system processing emails isn’t going to be fetching images or rendering attached SVGs.
Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens
#26I often think the best way to defeat email open tracking would be for a mainstream email client to prefetch every image when a non-spam email is received and cache it for 72 hours or so. Every email gets flagged as “opened,” so the flag is meaningless, and recipients can see the images without triggering a tracker.
I worked for a short time for an American company. They had periodic phishing test from Mitnick. The links in those emails was not to be clicked as it would trigger a mandatory training. The emails also had a header saying they were a phishing test, so I deleted all those emails in a filter. The company also ran a mail filter called Baracuda or something similar that followed links in emails to see if they were malic…
Edit: also, to be fair, you basically told them you had opted out of the test, so it’s not completely ridiculous for them to ask you to do the training instead.
Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens
#27I often think the best way to defeat email open tracking would be for a mainstream email client to prefetch every image when a non-spam email is received and cache it for 72 hours or so. Every email gets flagged as “opened,” so the flag is meaningless, and recipients can see the images without triggering a tracker.
Some of the big providers already do this, notably Apple and Gmail: https://www.litmus.com/blog/gmail-prefetching-images
Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens
#28I often think the best way to defeat email open tracking would be for a mainstream email client to prefetch every image when a non-spam email is received and cache it for 72 hours or so. Every email gets flagged as “opened,” so the flag is meaningless, and recipients can see the images without triggering a tracker.
Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens
#29You disclosed this the day roundcube was patched. Isn’t it usual to give us time to deploy updates before disclosing details?!
Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens
#30I often think the best way to defeat email open tracking would be for a mainstream email client to prefetch every image when a non-spam email is received and cache it for 72 hours or so. Every email gets flagged as “opened,” so the flag is meaningless, and recipients can see the images without triggering a tracker.
I worked for a short time for an American company. They had periodic phishing test from Mitnick. The links in those emails was not to be clicked as it would trigger a mandatory training. The emails also had a header saying they were a phishing test, so I deleted all those emails in a filter. The company also ran a mail filter called Baracuda or something similar that followed links in emails to see if they were malic…