4 ms·
A lot of people simply don't understand what little integrity email actually has. People like to think that they can rely the sender address as an unspoofable
by intransigent 10y ago
A lot of people simply don't understand what little integrity email actually has.
People like to think that they can rely the sender address as an unspoofable source of truth, and do not understand that the message is just a text file, and you can make it say anything you want.
No one inspects the delivery servers or the message routing, and even that can be sufficiently obfuscated.
Using too-big-to-fail services like gmail, that attempt to provide analysis and alert you to suspicious patterns is nice, but it doesn't solve for the actual realities of handling email. Furthermore, if there were one email ring to rule them all, we'd be haunted by a more ominous problem.
Still, the level of confusion and misperception about common technology, and what is and is not possible, is clearly as big a problem on its own. It sucks that people are left with such superstitious paranoia, because they don't understand how naked they actually are.
- cyberpunk 10y agoWhat patterns? This doesn't have any obfuscation it's basic web for.... A long time now. What are email providers supposed to be solving here? The reality is as an individual it's up to you how your mail client behaves and what emails you decide open or not... The hidden reality of the email situation for on the sender side is that it's getting increasingly hard to even send mail as an avg entity instead of outsourcing the problem to google/aws/mailchimp/whoever and that's not an accident. As for your mail: almost every marketing/transactional/non-personal you've had over the last few years will have 'completely unique to you and that /specific/ message' urls for things like the images (if they're not inlined), tracking pixels, and especially the links you can follow from the mail which allows the marketers/esp's to see who has opened it, who clicked, who didn't and so on. If there's html/js allowed then we'll be watching which parts your mouse hovers over, how fast you scrolled, which parts you actually read and so on. Do a tcpdump while you read some mails from amazon or someone and see what you find when you move your mouse around. Hopefully that isn't news to anyone. This has been happening for ages. If a non-transactional mail is going to 100k people then for example the banner image at the top will have 100k urls the webserver will serve it which is how you track that stuff without cookies.. To explain further, mails more often than not today are viewed in a browser (even the 'fat' mail apps like mail.app or I presume outlook use 'embedded browsers/web views' which are the same) these all happily send the cookies you've got kicking around from your normal sessions for those domains on the images, which, are then matched up with whatever else you'll do on said site (or even better, if the tracking is coming from a diff domain and multiple sites use the same provider then we'll be tracking you across a lot of dofferent places (see: omniture, google, etc) -- generally a MSP/tracking provider can't give a client access to what a user in a given segment might be upto on sites that they don't own, but the SP certainly knows and the biggest one also controls a lot of the ads...). What's one email ring? edit: Email providers do have some protections too, though. SPF has been around for ages which if you're not the MX ip and don't have the record for the domain you're FROM'ing gets you on bumped up the process of making the shitlist on the big MX's at least (gmail, hotmail, whoever). Finally getting listed means they won't accept mails from that IP for 24 hours (I assume it's 24 hours simply because it'd be insane to sustain an actual blacklist longer than that on the scale things are today, and that stops people having to request removal after hacks or whatever.. Things are getting better with DKIM and DMARC too...
- intransigent 10y agoPatterns: The email message contents say the sender is joe@example.com but the originating mail server is owned by advertiser-d00dz.net and was routed through cdns and isps that example.com is not known to operate, based on a wide swath of reliable analytics from several million other messages previously processed and known to be legit example.com messages. Those are patterns that very large email providers know about. But if you are running your own mail server, and using squirrel mail, you, a lone individual cannot analyze mass traffic patterns. One Ring To Rule Them All: Everyone only uses gmail, and there is no other provider, resulting in monoculture, and we all get spied on, not just by the NSA, but The Corporation too, but at least there's no spam. That last guy that tried spamming was turned into soylent green. As for pixels, uh, images don't automatically load for all people. I haven't permitted a banner image to load in eons. I also don't visit links that I cannot understand, especially for domains I don't recognize, but that's because I know better. Yes, yes, cookies, web mail, javascript, event bubbling and capturing, hovering, ajax, json, oh noes. I get it. We get it. We all get it. But grandma does not.
- cyberpunk 10y agoGoogle's big, sure, but they're not the only show in town (comscore's yearly thing is pretty easy to google0. The patterns bit isn't really how this works. There are no real analytics being done on the messages coming in from example.com to check if it's from 'the same place as it normally is' in that manner. It would require enormous resources and that problem was solved by SPF way back in the 00's (or before). Your Example.com will usually delegate a subdomain (dns) to a big mailer (like mailchimp, sendgrid, j33t-haxx0rz.ru or whoever) if they're going to be doing a lot of mails. The delegate will create/maintain a load TXT record (that's SPF) which is really just a list of hostnames (like 'mailer1.foo_emailcompany.com') which then have sort of proved that they are authorized to send mail as foo.example.com. The mailservers at google or wherever which then recieve these will lookup the txt records for the sender as part of their spam scoring mech during the mail arrival, and will use it as part of the scoring mech (but not the complete one). Your big mail proivders will be using 1000's of IPs to do a single mailing at times, so there is really no other way this sort of thing can work. DKIM uses a similar approach but utilizes signing to get there.. edit: also, probably <1% of people don't/won't view images in their mails, which is sort of the point here regardless of what we personally do......