

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Allowing anything other than plain text in email bodies was a terrible mistake.by desro
- One thing I've found that purports to address (some of) these risks: https://mail.cock.li/cock-mail/
Haven't tried it yet though, done some reading but don't know enough to be sure their proposed paradigm is valid.
by branon - >When the user types this command Atlas will open some browser tabs and exfiltrate the victim's name from the current web page and send it to a remote server via the hash.
But the remote server doesn't see the hash? This casts doubt into the content, since the attack was clearly not tested. Am I missing something?
It's a pretty interesting post though, but hardly surprising - touching and rendering untrusted content is always risky.
- Email rendering is such a mess. It’s insane that the standard way to lay out an HTML email in 2026 is with tables.
If you look at https://www.caniemail.com/scoreboard/ there are even different results for the same client on desktop vs mobile.
It seems like browsers moved with the times and email got stuck in 2005.
by dabinat - I view email in Thunderbird and have uBlock installed. Sadly the CSS Exfil addon for Firefox does not exist for Thunderbird but I view emails in plain text either way. I suppose I "miss out" on backgrounds, themes, animated GIFs. For me personally plain text is the way to go. Am I the only one using an email client these days? I prefer the client so I can keep my emails off the server and manage my own backups.by Bender
- This website was pretty nasty to my browser history and pretty much kidnapped my tab on mobile safari.by Waterluvian
- The frustration with the Gmail triager is typical unfortunately. Google teams have outsourced almost all user issue triage to contractors and the actual engineers don't interact with the community or users. Hopefully some Googler sees this and can get the Gmail team to fix it. The image proxy is useless if emails can trivially work around it.by esprehn
- Reading the article, I kept thinking: "could you defeat this with an iframe?", and indeed:
> One of the best methods to protect against these attacks is strict isolation. If you isolate the email message using sandboxed iframes you restrict the ability to break out of trusted boundaries. If you are not using sandboxed iframes, always be careful when allowing custom attributes and check for HTML/CSS gadgets. Use a strict allow list of characters when validating keywords and names to avoid mutation when using the CSSOM.
iframes should be the first layer of any defense-in-depth against user-submitted content.
by PoignardAzur