3 ms·
How was that problematic? I don't see the issue, especially given that the author was on a VPN and using Firefox in Private Browsing mode while running DoNotTr
by throwaway4567 11y ago
How was that problematic? I don't see the issue, especially given that the author was on a VPN and using Firefox in Private Browsing mode while running DoNotTrackMe.
- ikeboy 11y agoMost email is sent unencrypted, so the NSA likely has a record of that email and can cross-reference it with the 23 account if needed. Even the header would probably be enough in this case, just to identify the particular masked email with the real email behind it.
- throwaway4567 11y ago> Even the header would probably be enough in this case, just to identify the particular masked email with the real email behind it. Are you implying that an HTTP header sent in the request to 23andme upon clicking the confirmation link would contain the forwarded email address of the user? Unless the user were on a web page that included their email account name in the URL (and thus visible in the REFERER header), I don't see how that would happen. And I don't think I've ever seen an email system that puts the account name in the URL.
- ikeboy 11y agoNo, the email header sent by abine when they forward the email from 23andme. That contains their real email address in plaintext, and might also contain the masked address; if not, a timing attack given the time of 23's emails and the time of the forwarded email might work. If the actual email is unencrypted, then the NSA gets everything for free.