Live data from Hacker News

The only safe email is text-only email

theconversation.com

91–100 of 123 posts

Re: The only safe email is text-only email

#91
post #31

This might be true, but I think that ship has sailed. Email for 99% of internet users is html. Thinking that some large fraction of news letters, outlook emails will ever be plaintext is just naive. I use html emails in outlook simply because I don't want my emails within the corporation to appear differnet from anyone elses. I certainly don't want to return something that looks different from what the sender wrote,.…

I'm not sure the ship has sailed. If HSBC switched to only mailing out text-only emails with URLs written out in full, after a while HSBC users would get used to only receiving text correspondence from their bank. I think that would be a step towards reducing phishing attempts, though certainly not a complete answer.

Disclosure: I work for a fintech company that utilizes HTML emails almost exclusively for customer communications.

I think one thing that is not being considered is that for most customers, branding and the consistency thereof are key indicators of trustworthiness - especially when dealing with financial information. HN users are rare creatures, they have technical context the average end user does not have. The rise of phishing has lead users to pay a great amount of attention to subtle hints of impropriety, like being taken from one sort of visual experience to a vastly different one. We saw vast improvement across all meaningful metrics when we switched from plain text to HTML emails that utilized branding consistent with our website.

As with everything that humans deal with, there are tradeoffs here. And I'm extremely concerned that this position taken to it's logical extreme would lead to the web being transformed into something that is "safer" but much less useful and dynamic. One outcome of this could be the slow death of the open web in favor of siloed networks and platforms serving actually functional content in "safe" ways.

Re: The only safe email is text-only email

#92

There's a certain zen to going back to basics and using plaintext. It's always my default choice whenever I'm given the option. I'd argue in most cases you really don't need any fancy styles and markup. Although upon writing this I'm now wondering if unstyled HTML might provide improved accessibility over plaintext. What are people's experiences on the matter? Although I respect that some people may find greater valu…

If nothing else, styling emails serves an economic purpose through facilitating signaling. The more a company expects that consumers will value it in the long run the more incentive it has to signal that fact, and a signal is only as good as it is expensive in appearance to the people being signaled to. In this case, things like a marketing email or simply the follow-up email to signing up to some service provide tha…

As a recipient of those emails -- not really. Clients block remote content by default and there's almost never a reason to load them, especially when they're used for tracking. Those 'pretty' emails will almost always look like a soup of image placeholders interspersed with text.

Re: The only safe email is text-only email

#93
post #87

Earlier quoted context omitted.

As I said, Gmail is opaque with regard to its spam detection. As for your help offer, thank you, but I'm good. It's usually other people who want to contact me, I rarely send the first message ever.

Hmm well, I've found it to be pretty straightforward, I'm curious why this is happening to you though and there must be a solution... I mean.. If you get a solid result from dkimvalidator but google is still shitlisting you then I'd definitely consider moving to another host/dc/isp at least. Depending on your size, it might be best just to make this someone else's problem (if you can) -- like google, o365, etc..

The real problem is Google is opaque in dropping such mail in recipients spam folder. Hotmail can sometimes be annoying in this regard too. As far as I've managed neither does the sane thing and add a header that report on how they've divided that "this mail is spam" - so the recipient doesn't have anything to go on either, other than hoping "mark this as bot spam/add to address book/send email/reply to address" help Google/Ms treat it as "not spam".

Maybe it's worse for non-English mail (maybe the statistical models are biased against "not English" even for people whom don't have English as a native language).

But I'm quite convinced google's (and to a lesser extent Hotmail/ms') "magic" spamfiltering is subtly (but annoyingly) broken.

Re: The only safe email is text-only email

#94
post #90

Earlier quoted context omitted.

Hmm well, I've found it to be pretty straightforward, I'm curious why this is happening to you though and there must be a solution... I mean.. If you get a solid result from dkimvalidator but google is still shitlisting you then I'd definitely consider moving to another host/dc/isp at least. Depending on your size, it might be best just to make this someone else's problem (if you can) -- like google, o365, etc..

I'm definitely not giving to somebody else my /var/log/mail.log, IMAP/Mutt access, sieve rules, nor ad hoc dedicated aliases for every website account I create. And on top of that, I would land on some US-based server for ease of illegal spying and my mail would be harvested for some advertising crap, all to solve something that is not a problem for me. Not happening.

Yep, that's the reason I host my own email also.

I'm working on a guide for setting this stuff up; still WIP [1] -- feedback appreciated!

1: https://medium.com/@cyberpunk_networks/nsa-proof-your-email-...

Re: The only safe email is text-only email

#95
post #27

Earlier quoted context omitted.

> The real URL will appear in the browser address bar anyway before the user gets the chance to disclose any information Which is already too late for anyone compromised by a drive-by download attack.

The threat model here is phishing, not drive-by downloads. Browsers have a much greater ability to mitigate those. Also, a drive-by download email doesn't have to impersonate any particular sender, it just has to look like something that a user might want to click on.

> The threat model here is phishing, not drive-by downloads.

I think you missed my point. What if it isn't a phishing attack? Or even, what if it isn't just a phishing attack?

Your suggestion leaves users vulnerable by encouraging them to open suspicious looking links on the off chance it is, at most, a phishing attack.

> Browsers have a much greater ability to mitigate those.

Except when they don't. For what it's worth, I've also seen mobiles fall victim to drive-by download attacks.

> Also, a drive-by download email doesn't have to impersonate any particular sender, it just has to look like something that a user might want to click on.

E-mail worms are spread by the trust relationship between people known to each other (ie a user opening an attachment because it's from a recipient they know). I don't see why drive-by download attacks couldn't exploit the same human condition (ie "Hey bob, check out this link. It's awesome").

In fact I have seen that kind of malware in the wild, now I think about it.

Re: The only safe email is text-only email

#99
post #62
post #56

Earlier quoted context omitted.

I feel like I'm making this comment once a week on HN but I host my own email and I haven't had any major issue so far with "big email". The main caveat is that you will have a very hard time getting your email accepted if it comes from a home connection IP range instead of some host provider but if you do have a dedicated server and follow the guidelines (SMTPS, DKIM, SPF etc...) it just works, at least in my experi…

Hosting one's own e-mail server is a totally opaque random crapshot. You may not have any trouble, but some other dude or gal will get their e-mail marked as spam without any way to tell what exactly is wrong and what to change.

Maybe https://www.mail-tester.com/ would help. Also https://mxtoolbox.com/diagnostic.aspx .

If neither of these tools highlight any issues it's pretty strange indeed.

Re: The only safe email is text-only email

#100
post #53

Earlier quoted context omitted.

I'm still waiting for people like that to automatically email back a CAPTCHA to the sender, if the sender is unknown, and not on a whitelist yet.

The proof of work approach is better.

How much work would you propose is sufficient that grandma doesn't mind but spammers will be severely hampered in their sending and in a manner that doesn't require the receiver to store too much state?
Post reply on HN