Live data from Hacker News

Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

nullcathedral.com

71–80 of 81 posts

Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

#71
post #67

Earlier quoted context omitted.

Which is completely stupid since images in an email should never change.

I know of an invoicing system that updates the image when it's paid. Seems pretty useful to me. And yes, that means that an image with an amount is publicly accessible, so what, there's no information about the invoice in there as that's in the text of the email.

Bet they send a separate mail when you paid though, in which case updating the picture is not much more than a means for them to hide errors.

I subscribed to the daily headlines from a newspaper, they delivered them as a remote picture in the mail. Only it was always the same remote picture each day, just updated. So if you didn't open the mail each day too bad: you snooze you loose, those past headlines are gone.

Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

#72

Earlier quoted context omitted.

Which is completely stupid since images in an email should never change.

Why shouldn't they? There's plenty of scenarios where you might want to swap images after a period of time has elapsed, or to fix a mistake.

It's counter to the principle of what e-mail is. It's supposed to be static. Just because you can doesn't mean you should.

Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

#73
post #72

Earlier quoted context omitted.

Why shouldn't they? There's plenty of scenarios where you might want to swap images after a period of time has elapsed, or to fix a mistake.

It's counter to the principle of what e-mail is. It's supposed to be static. Just because you can doesn't mean you should.

> It's supposed to be static.

Says who? It's not in the original RFC as far as I'm aware.

Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

#74

Earlier quoted context omitted.

Which is completely stupid since images in an email should never change.

Why shouldn't they? There's plenty of scenarios where you might want to swap images after a period of time has elapsed, or to fix a mistake.

specifically to prevent this kind of tracking

Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

#75
post #20

I often think the best way to defeat email open tracking would be for a mainstream email client to prefetch every image when a non-spam email is received and cache it for 72 hours or so. Every email gets flagged as “opened,” so the flag is meaningless, and recipients can see the images without triggering a tracker.

That is still signal that the email address is valid. I'd prefer something like the server immediately sending a SMTP 550 5.1.1 (unknown recipient error), for anything that's immediately recognized as spam (or marked as spam in the past by the user). That gives no signal at all and might even persuade some scammers to remove your email address from their list.

I hereby remind you of a bet you lost: https://news.ycombinator.com/item?id=39186555 :)

my contact info is in my profile to arrange settlement

Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

#76
post #72

Earlier quoted context omitted.

It's counter to the principle of what e-mail is. It's supposed to be static. Just because you can doesn't mean you should.

> It's supposed to be static. Says who? It's not in the original RFC as far as I'm aware.

I'm pretty sure the original RFC (RFC 821) does not include remote resources and it was written far before HTML or HTTP was invented.

It was text delivered over SMTP.

Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

#77
post #60

Earlier quoted context omitted.

Did everyone get flagged then thanks to Barracuda? You’d think they’d realize there’s a problem if there’s a 100% fail rate. Edit: also, to be fair, you basically told them you had opted out of the test, so it’s not completely ridiculous for them to ask you to do the training instead.

to be fair someone started using computers and has x worthelss security certificates but yes he will teach me how to use computer/Internet...okidoki... I just move to trash all their tests as it's just spam.

The test is whether you can successfully identify phishing attempts bu approximating what they look like in the wild. Bypassing the test entirely means there's no data on whether you're susceptible to this, and just because someone knows there's a header and how to bypass something doesn't mean they aren't also the kind of person to be distracted and click on stuff they shouldn't.

This method of test passing wasn't okay when Volkswagen did it, and it's not appropriate for employees at a company that asks them to take the test, for the exact same reason.

Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

#78
post #12

I often think the best way to defeat email open tracking would be for a mainstream email client to prefetch every image when a non-spam email is received and cache it for 72 hours or so. Every email gets flagged as “opened,” so the flag is meaningless, and recipients can see the images without triggering a tracker.

I worked for a short time for an American company. They had periodic phishing test from Mitnick. The links in those emails was not to be clicked as it would trigger a mandatory training. The emails also had a header saying they were a phishing test, so I deleted all those emails in a filter. The company also ran a mail filter called Baracuda or something similar that followed links in emails to see if they were malic…

Ughhh yeah, KnowBe4. Real crap service with emails so obviously bait that a security worker would try them just to see what happens.

The cool thing though is when people post the link on Yammer asking if it's safe, then you can screw them by clicking on it and they have to do the course hehehh

But yeah bad service

Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

#79
post #51
post #12

Earlier quoted context omitted.

I worked for a short time for an American company. They had periodic phishing test from Mitnick. The links in those emails was not to be clicked as it would trigger a mandatory training. The emails also had a header saying they were a phishing test, so I deleted all those emails in a filter. The company also ran a mail filter called Baracuda or something similar that followed links in emails to see if they were malic…

Hmm, mixed feelings. Sure you are being clever, but (and I don't know the state of art science wrt effectivity of these fake phishing emails), you are defying a measure that was taken by management to try to make the company safer. Sure it may feel, and even be, a waste of time. But you are also putting yourself above the rules in a way. Your assumption is that these programs will actually NOT make the company safer,…

[deleted]

Re: Roundcube Webmail: SVG feImage bypasses image blocking to track email opens

#80
post #68
post #51

Earlier quoted context omitted.

Hmm, mixed feelings. Sure you are being clever, but (and I don't know the state of art science wrt effectivity of these fake phishing emails), you are defying a measure that was taken by management to try to make the company safer. Sure it may feel, and even be, a waste of time. But you are also putting yourself above the rules in a way. Your assumption is that these programs will actually NOT make the company safer,…

> you are defying a measure that was taken by management to try to make the company safer. > are you 100% free to cheat on cyber security measures? Why do you think that implementing an email filter like that is "defying a measure" or "cheating"? What value do you think there would be in individually, manually, reviewing each such email, if you've already identified the pattern they all follow and their purpose? You'…

Are you being willfully obtuse? Suppose that management wanted to see if you could visually identify faulty parts on an assembly line - wrong finish, dirty, etc - , and that all deliberately faulty test parts had a red sticker on the bottom. If you just flipped every part over until you found red stickers would you be equally annoying refusing to identify why what you did you as wrong and stupid? The goal wasn't reading email headers.
Post reply on HN