Bugtraq mailing list archives
Re: [Full-disclosure] Mozilla Thunderbird : Multiple Information Disclosure Vulnerabilities
From: Daniel Veditz <dveditz () cruzio com>
Date: Thu, 02 Mar 2006 15:09:46 -0800
Nick Boyce wrote:
Hmmm. I didn't realise the "Show Images" setting got stored, and I don't think that's the best strategy from a privacy point of view.
It surprised me, too. The threat model was spammers trying to verify live addresses, and in that model loading a webbug multiple times is no worse than loading it once. Mail usage spying like the "ReadNotify" service was apparently not considered.
I take it you mean "stored for that one message",
Yes, just that one message.
Current thread:
- Re: [Full-disclosure] Mozilla Thunderbird : Multiple Information Disclosure Vulnerabilities Daniel Veditz (Mar 01)
- <Possible follow-ups>
- Re: [Full-disclosure] Mozilla Thunderbird : Multiple Information Disclosure Vulnerabilities Nick Boyce (Mar 01)
- Re: [Full-disclosure] Mozilla Thunderbird : Multiple Information Disclosure Vulnerabilities Daniel Veditz (Mar 07)
- RE: [Full-disclosure] Mozilla Thunderbird : Multiple Information Disclosure Vulnerabilities Jay Stapleton (Mar 02)