4 ms·
The article addresses this, actually. Fetching any unsecured content is an attack vector. https://danq.me/2026/01/28/hsbc-dont-understand-email/#footnote-27343-
by chowells 8mo ago
The article addresses this, actually. Fetching any unsecured content is an attack vector. https://danq.me/2026/01/28/hsbc-dont-understand-email/#footnote-27343-7 https://danq.me/2026/01/28/hsbc-dont-understand-email/#footn...
- crazygringo 8mo agoIn this particular case, injecting content into the image to make someone read a false message doesn't seem possible. The pixel <img> tag has width and height set to one. This overrides whatever the image size is. No altered message will be readable.
- matthewmacleod 8mo agoThis is true up until the point that someone finds a security issue with an image parser that’s present in a browser engine, and suddenly you have an RCE.
- deleted 8mo ago[deleted]
- crazygringo 8mo agoIf you have access to an exploit and want to compromise someone with an image, you'd usually just send it to them directly via e-mail or SMS or AirDrop or whatever, or all of the above. And it'll even work if your image is linked in an email via HTTPS. Trying to MITM an existing tracker pixel when they're connected to public WiFi sounds like practically the hardest way to do it.
- samrus 8mo agoThe harder it is to do, the more the targets guard will be down In this case, sending your malicious image through a fake email might get flagged, or even not opened by someone whos been trained in infosec enough to be suspicious of these things. But a tracking pixel in an email that is verifiably from a trusted entity will be opened no problem. Type of thing that will look pretty slick if you read about it being used
- crazygringo 8mo agoIt's incredibly easy to get people to open emails. This isn't asking them to download an attached .zip or .exe file or follow a suspicious link, which is what people are trained against. This is just an embedded image.