3 ms·
Wouldn't disabling HTML email take care of this?
by middleclick 8y ago
Wouldn't disabling HTML email take care of this?
- dbrgn 8y agoYes, but that's probably something most people won't do (with the prevalence of HTML email and no plaintext alternative). Also, it was a reply to the parent who stated "If you disable remote content, it can't be exploited on thunderbird". Ruling out the presence of an exfiltration channel is hard. It's better to prevent rendering of messages with invalid authentication code in the first place (and not rendering it and showing a warning).