4 ms·
A good example of why HTML emails need to be downgraded to plain text in financial companies, and links stripped and checked before it's shown.
by docker_up 7y ago
A good example of why HTML emails need to be downgraded to plain text in financial companies, and links stripped and checked before it's shown.
- inetknght 7y agoNow if only every company and their mother would stop using third parties for links. I don't care if you track that I clicked on your link. I care that your link doesn't appear to go to the same site your reply-to email would go.
- deleted 7y ago[deleted]
- tgragnato 7y ago> I care that your link doesn't appear to go to the same site your reply-to email would go. From one of the last emails I read this evening: "we would like to inform you that there is a form on our website" [me]: The form is not on your website, only the link to it. You're right, but it's much more simple to disallow links, people don't really understand the difference on a website, emails are another additional complication.
- inetknght 7y agoHow would you recover accounts if links weren't permitted?
- tgragnato 7y agoI'm late to this, but... 1. while developing -> send tokens for copy/paste if a user has chosen text-only emails 2. while administering -> institute the policy of having to ask one of the administrators, if it happens too often you have worse problems in any case
- sparkling 7y agoThe sad reality today is that a truly plain text email looks "phishy" to most end users today, as the result of 15+ years of facny HTML mails.
- gruez 7y agoNot really. The exploit involved getting the victim to click a link to the attacker's page, so plain text emails wouldn't prevent anything. >attackers would send a spear-phishing email luring victims to a web page, where, if they used Firefox, the page would download and run an info-stealer
- docker_up 7y agoYou can strip the links and replace them with a man-in-the-middle link so that you couldn't just directly click on the link.
- tedunangst 7y agoAnd then what? You show them the original link and they click it again?
- docker_up 7y agothere's a million different things you can do. You can simply strip out all links. You can strip out links and only allow white-listed links, etc. Once the site has been vetted then it could be allowed to be clicked on. Or you can just have a big javascript alert box that said "Remember, you are clicking on a link that is unvetted and it could steal your credentials. Be careful." I don't know, be creative. Anything that will wake people up and stop them from just blindly clicking on things. For a financial institution like Coinbase where a hacker could compromise the security of the entire company, it doesn't seem completely unreasonable.
- hermitdev 7y agoI work in finance, and we do something like this. HTML is not scrubbed, but all links are sanitized/scanned/vetted before we can visit them. Kind of annoying, because it can 5-10 minutes after receiving an email with a link in it before it's cleared. Considering I work in market data and a lot of vendors send out out important notices about delays, holidays, etc as a brief blurb and then a link to more detailed info, it gets annoying. But, I understand why its done, and it's important to do so. Understanding doesn't make it any less annoying, though.
- robertAngst 7y agoI am 100% on board with this solution. Email does not benefit much from format when doing communication. Marketing and sales is a different story.
- stef25 7y agoMicrosoft has the option to run all links in incoming mail through their system. Whether or not that would have caught a FF zero day on the target site is another question. Where I work this was implemented after people started getting (spear) phishing mails.