4 ms·
Doesn't gmail stop these attacks without needing to force plaintext only by simply disabling images by default?
by jeffreyg 15y ago
Doesn't gmail stop these attacks without needing to force plaintext only by simply disabling images by default?
- mike-cardwell 15y agoYes. There was a bug a few years back though where they would display attached SVG images. These images could actually contain javascript, which left it vulnerable to XSS.
- zzz90210 15y agoWhat about the bgsound attack?
- aptwebapps 15y agoWhy is zzz90210's post dead? Everyone knows about tracking via images. I never considered something like bgsound, probably a lot of other people did not as well. And it's the whole point of the article.
- jongraehl 15y agoThe highly-upvoted mail-bug testing site in comments says gmail isn't vulnerable to bgsound - https://grepular.com/email_privacy_tester/ https://grepular.com/email_privacy_tester/
- ars 15y agoHis post is dead because this comment he made: http://news.ycombinator.com/item?id=3662065 http://news.ycombinator.com/item?id=3662065 Took his karma negative, and once that happened his account was killed. As a new member you have to be careful about controversial statements until you build up a karma cushion.
- aptwebapps 15y agoI see, an indirect cause didn't occur to me.