20 ms·
The only safe email is text-only email
- coldouthere 9y agoReminds me of the ascii ribbon campaign against non-human readable formats in email. I switched to a text only email client a few months back. I really don't think I am missing anything. HTML content tends to be chaff/advertising.
- jasonkostempski 9y agoIn my experience, for personal email, text-only is a non-issue; for work stuff, it's not even an option.
- dvfjsdhgfv 9y agoCan you elaborate why? I sometimes abuse this option by including screenshots in the body of e-mail, but I could as well add it as an attachment. Other than that I see no reason to use HTML in e-mail conversations at work.
- dingaling 9y agoIntra-corporate e-mail is often used as an ad hoc document collaboration tool. "See my comments in blue", strikethroughs, inline diagrams, bullet points, big red font for emphasis. Of course that should all be done in a dedicated application, but who is going to provision and authorise users for that versus just adding Bob to the cc line and giving him implicit editing capabilities? The functional overloading of corporate e-mail is a user-driven reaction to the awfulness of most " collaborative' software.
- diggernet 9y agoI've always had my work email client set to text only. Never been a problem for me (unless you consider missing out on a lot of unnecessary smilies, fonts, and colors a problem).
- KGIII 9y agoI too am confused. The only time I've used HTML in email was when I used the web interface and plain text wasn't an option.
- lwhsiao 9y agoI recently switched to mutt and using plain-text email as well. So far there have been very few times that I've felt the need to jump back to the webmail to send something (e.g. inline images). Overall, I've thoroughly enjoyed the simplicity of plain text email using my text editor of choice.
- deleted 9y ago[deleted]
- thisrod 9y agoI was expecting to read about some brilliant new way to solve all of the normalisation problems with Unicode, and make plain text safe again. What a let down!
- cozzyd 9y agoAnnoyingly, the Gmail Android app sends things multipart, even though I'm not sure it's really possible to have any formatting (except maybe links?). I wish there wan option to send text only, it might even make a (small) difference for people with limited data.
- TheAceOfHearts 9y agoThere's a certain zen to going back to basics and using plaintext. It's always my default choice whenever I'm given the option. I'd argue in most cases you really don't need any fancy styles and markup. Although upon writing this I'm now wondering if unstyled HTML might provide improved accessibility over plaintext. What are people's experiences on the matter? Although I respect that some people may find greater value in carefully styled marketing emails, to me it just feels a bit overengineered at times. How many man-hours have been spent trying to get marketing emails to look the same across all major clients? Are slight variations really such a horrible thing? As we're on the subject, I'll add the following suggestion to gmail users: go to Settings and changing the Images option to "Ask before displaying external images". External images are regularly abused to track if the email has been viewed, which I consider creepy.
- savanaly 9y agoIf nothing else, styling emails serves an economic purpose through facilitating signaling. The more a company expects that consumers will value it in the long run the more incentive it has to signal that fact, and a signal is only as good as it is expensive in appearance to the people being signaled to. In this case, things like a marketing email or simply the follow-up email to signing up to some service provide that signal since the user can see how much effort was invested in making the communication look attractive.
- Spivak 9y agoAs a recipient of those emails -- not really. Clients block remote content by default and there's almost never a reason to load them, especially when they're used for tracking. Those 'pretty' emails will almost always look like a soup of image placeholders interspersed with text.
- andyjohnson0 9y ago> External images are regularly abused to track if the email has been viewed, which I consider creepy. My understanding was that external images are automatically fetched and cached on their servers by Google, so they can't be reliably used to track message views [1]. Has this changed? [1] https://gmail.googleblog.com/2013/12/images-now-showing.html https://gmail.googleblog.com/2013/12/images-now-showing.html
- ameliaquining 9y agoThis is silly. The authors establish that phishing is a serious problem (duh), and that this problem is caused by the absence of reliable authentication of messages (a worthwhile observation, albeit one that the industry is already aware of and doing its best to patch over), but they fail to establish that text-only email solves this problem in any meaningful way. Text-only emails can and will still contain links, which users will still click on. Misleading domain names will work just as well in the email body as they do in the address bar. Even if (as this article seems to imply should be done) mail clients don't make the links clickable, users will still copy-paste them. (Not to mention that the usability benefits of making links clickable are significant enough that mail clients won't forgo them just for a speculative hypothetical security benefit.) The authors seem to think that inserting a "speed bump" here will cause users to pay closer attention and not be fooled. This is not how humans work, especially very busy humans who get too much email and just want to get through it as quickly as possible. Also, the reference to JavaScript in email leads me to question whether the authors have any idea what they're talking about. Mail clients don't execute JavaScript.
- cozzyd 9y agoAt least with plain-text, it's a slightly harder to forge links. (i.e. you have to do http://www.megabank.com.phishingattempt.io http://www.megabank.com.phishingattempt.io instead of <a href="http://www.phishingattempt.io"><img http://www.phishingattempt.io"><img src="megabank.com/logo.png"></a> ) Speaking of JavaScript in e-mail, gmail doesn't allow you to send or receive .js files (even tarred up), which is somewhat inconvenient, and I'm not really sure what attack that prevents. Maybe there is a mail client out there that will happily execute attached js?
- ameliaquining 9y agoThe real URL will appear in the browser address bar anyway before the user gets the chance to disclose any information. I don't know exactly what proportion of users will notice a well-disguised phishing URL in the email body but not in the address bar, but I bet it's not that high. The attack prevented is simply having the user open the attachment, allowing the sender to execute arbitrary JavaScript on their machine in the file:// context. (Modern browsers have made the security consequences of this somewhat less dire than they once were, but it's still not something you want to do if you can help it.)
- stevekemp 9y agoBut even there you've got to be careful. For example if you're using GNU Emacs to read your email you could have been vulnerable to arbitrary code execution for the past few years: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=28350 https://debbugs.gnu.org/cgi/bugreport.cgi?bug=28350
- CyberShadow 9y agoThe vulnerability is in the handling of text/enriched parts - not quite text/plain.
- ams6110 9y agoI've always used plain text for email. Text is for email; HTML is for web pages.
- mnw21cam 9y agoYeah, I have used alpine for email since the year dot. I don't feel like I'm missing anything important.
- ElectronShak 9y agoI think this is entirely dependent on the context of that particular E-mail. Email has evolved quite a lot. A good example is a newsletter from say, Quora or Medium; Newsletters usually have links to a story or a news feed article. If this was done using plain text, the link would be one long mashup of characters, because they usually include an authentication token or something like that. In this case, using an html link or button is clearly the better option. HTML is like structured text for web pages.
- gkya 9y ago> A good example is a newsletter from say, Quora or Medium; Newsletters usually have links to a story or a news feed article. If this was done using plain text, the link would be one long mashup of characters, because they usually include an authentication token or something like that. In this case, using an html link or button is clearly the better option. Well, that's a yet more hostile thing that one has to put up with. I follow news through newsletters, and I'd prefer they were in plain text and with normal links. My reader knows how to wrap lines and make link-like things in plain text clickable. But unfortunately if I wanted to enforce that I'd have to avoid news...
- ElectronShak 9y agoYah,consequently. But last week someone posted a link here, a text only version of CNN, I looked it up, here it is; http://lite.cnn.io/en http://lite.cnn.io/en. We could have more of these soon, which is a good thing.
- stephenr 9y agoI've always thought native handling of markdown for email would be pretty cool. The MUA could strip out any HTML embedded in the actual markdown, render to HTML locally (for display) and you have nice formatting without the risks or cruft of email HTML. And of course if you choose to view in text only mode, you don't actually lose any semantic meaning.
- zwp 9y agoHuh, looks like text/markdown email is coming slowly: https://stackoverflow.com/a/25812177 https://stackoverflow.com/a/25812177 https://tools.ietf.org/html/rfc7763 https://tools.ietf.org/html/rfc7763 https://tools.ietf.org/html/rfc7764 https://tools.ietf.org/html/rfc7764 (March 2016) Previous HN discussion: https://news.ycombinator.com/item?id=13176743 https://news.ycombinator.com/item?id=13176743
- stephenr 9y agoThe RFC's are just about defining the Media Type 'text/markdown' aren't they? Just because they used to be called MIME types and were designed for email, I wouldn't treat those RFC's as being about email support specifically.
- zwp 9y agoSure, it could be used elsewhere. OTOH 7763 calls out email as a use case three times and in section 5 Examples "email attachment" is the only example.
- proactivesvcs 9y agoIn plain text, Thunderbird recognises * and / as bold and italic, which sometimes produces interesting results for badly-formatted multi-part emails.
- alkonaut 9y agoThis might be true, but I think that ship has sailed. Email for 99% of internet users is html. Thinking that some large fraction of news letters, outlook emails will ever be plaintext is just naive. I use html emails in outlook simply because I don't want my emails within the corporation to appear differnet from anyone elses. I certainly don't want to return something that looks different from what the sender wrote,. The mail client is a web browser. In many cases it's an actual web app in an actual web browser. The solution has to be to make them safer for the user. Maybe a subset of html can be whitelisted, maybe link targets should be rendered more clearly, maybe something else.
- dm319 9y agoI'm not sure the ship has sailed. If HSBC switched to only mailing out text-only emails with URLs written out in full, after a while HSBC users would get used to only receiving text correspondence from their bank. I think that would be a step towards reducing phishing attempts, though certainly not a complete answer.
- alkonaut 9y agoThat would require HSBC to value some kind of improved security so much that they'd accept not having the HSBC logo in the email. That's what I think is out of the question. You could maybe see banks having plaintext communication as an optional, but I doubt they'd make it default (allowing users to switch to html). Isn't this problem already solved with certificates online? Shouldn't this be solvable the same way? E.g. a bank sends an email containing a link to the content with some special attribute. The web browser displays the content if and only if the sender domain of the email (e.g. hsbc.com) is also the domain from which the content will be downloaded.
- breakintheweb 9y agoThey could still have the HSBC logo, it would just need to be in ascii....
- dm319 9y ago
- userbinator 9y agoI've noticed that "if it's not plaintext, it gets deleted without being read" seems to be a pretty common rule among Germans on the Internet, who also have a tendency to like specifying very exactly what they want of email to them. Here's a few examples: https://www-user.tu-chemnitz.de/~heha/email.en.htm https://www-user.tu-chemnitz.de/~heha/email.en.htm http://problemkaputt.de/email.htm http://problemkaputt.de/email.htm https://www.gaertner.de/~neitzel/email-to-mn.html https://www.gaertner.de/~neitzel/email-to-mn.html http://www.karo-electronics.de/448.html http://www.karo-electronics.de/448.html ...and of course there's this: http://arc.pasp.de/ http://arc.pasp.de/
- neals 9y agoThis is the most German thing I've seen since Octoberfest 2016. It seems weird to me to have to find out the preferred way of communication to this level of detail, I already loathe that one cient of mine that only uses Facebook messenger for all communication.
- Moru 9y agoThunderbird has settings for each of your contacts for this reason. You can set if they want HTML or text only mails.
- eveningcoffee 9y agoSecond link points out a problem I was afraid of existing - big providers just stump on personal email servers. >Hotmail is typically deleting all emails that I am sending. ... Monopolists like gmail.com won't accept any messages sent from my mail server.
- simias 9y agoI feel like I'm making this comment once a week on HN but I host my own email and I haven't had any major issue so far with "big email". The main caveat is that you will have a very hard time getting your email accepted if it comes from a home connection IP range instead of some host provider but if you do have a dedicated server and follow the guidelines (SMTPS, DKIM, SPF etc...) it just works, at least in my experience.
- decasteve 9y agoSome client software hides the From and Reply-To addresses, only showing the name by default. A friend's accountant got hit because the From had my friend's name, but the address itself was bogus but hidden, so he opened the attachment. So keep the main headers text-only as well (which most sane software does anyway).
- jghn 9y agoI never stopped using pine. Who knew that I was actually ahead of the game?
- yosito 9y agoI never click on any link in an email I didn't ask for. If I get a notification email from a party I have business with, I go to their website manually and check for messages.
- jasonmaydie 9y agowouldn't it be easier to have your email reader only render it in plain text?
- donohoe 9y agoIf you like this approach and are using Mail.app on OSX then I recommend the following: First... 1. In the menu, go: Mail > Preferences > Viewing. 2. Uncheck "Load remote content in messages". 3. Move to the "Composing" tab. 4. Select "Plain Text" for Message Format. 5. Uncheck "Use the same message format as the original message". Second... In Terminal, copy/paste this command to set plain-text preference to true: defaults write com.apple.mail PreferPlainText -bool true Its not perfect, but short of switching to another email client, its a step in the right direction.
- wheresvic1 9y agoI switched to using mutt with gmail and have never looked back. Mutt actually does a brilliant job of converting all html to plaintext. Here's the entry that I wrote about it (includes my mutt config): https://smalldata.tech/blog/2016/09/10/gmail-with-mutt https://smalldata.tech/blog/2016/09/10/gmail-with-mutt
- nom 9y agoE-Mail should've been replaced by something more suitable more than a decade ago. I sometimes wonder how long it's going to stay. My guess is: until the end of the internet.
- mmagin 9y agoEvery time I use some kind of graphical/web email client, I'm appalled by how hard it is for me to find the "show me all the headers" feature. In mutt when I have doubts about something I just hit "h". Admittedly this requires a level of knowledge that the average user may be missing. But I find it really helps inform my opinion of any borderline-suspicious emails.
- discreditable 9y agoI use plaintext mail heavily. My only complaint is clients that don't support format=flowed[1] wrap text weirdly and make it look bad. The biggest ones are Outlook and the Windows 10 Mail app, though some webmail handles it poorly too. It gets bad when conversations start accumulating nested quotes. I've found a quick tell if someone uses Outlook is if I send them a text/plain message, they'll send one back and there's no format=flowed. At that point I'll usually send them HTML mail. 1. https://joeclark.org/ffaq.html https://joeclark.org/ffaq.html
- paultopia 9y agoand to get there, we need email clients with usable UIs. Is there a way to make outlook or apple mail or the gmail web app grab the equivalent of `document.innerText` on every piece of email? Who can tell, without spending hours hunting through increasingly obscure menu forests?