4 ms·
I didn't say that I trust mail clients. I said mail clients shouldn't accept arbitrary HTML markups and tags in emails. That's a serious problem that needed to
by cryptbe 13y ago
I didn't say that I trust mail clients. I said mail clients shouldn't accept arbitrary HTML markups and tags in emails. That's a serious problem that needed to be addressed, regardless of Google Scholar being exploited to send emails with arbitrary links or not.
- yinso 13y agoThe onus is still on Google - the rule of the web is that any clients that one allows connections from are fair games that one has to address.
- Nitramp 13y agoIf you were using an email client that executes arbitrary HTML, you'd be owned since a long time anyway. That'd like using a browser that doesn't have any cross domain security boundary - it's just not a realistic attack vector, these things don't exist - or do you know an email client that actually interprets JS?
- yinso 13y agoYou don't need to execute JS in order to phish, as the original link alludes to with the html comment trick. This particular comment thread was mostly about webmail clients. But to your specific question... take a look at the link for an incomplete list of email clients that runs JS http://en.wikipedia.org/wiki/Comparison_of_email_clients#Templates.2C_scripts_and_programming_languages http://en.wikipedia.org/wiki/Comparison_of_email_clients#Tem...