webOS Nation Forums >  Homebrew >  webOS Patches > [PATCH REQUEST] disable remote image loading in email
[PATCH REQUEST] disable remote image loading in email
  Reply
 
Thread Tools Display Modes
Old 03/18/2010, 01:27 PM   #1 (permalink)
Member
 
Posts: 150
The email client in 1.4 still provides no way to disable automatic loading of remote content (images, etc). This is a MAJOR privacy and security risk. I'd take a patch that did nothing but break loading of remote content in HTML email.

Automatic downloading/display of embedded content in email messages is a major vector for malware on desktop OS platforms. It's unimaginable for an email client in these times to not have an option to disable this.
vga4life is offline   Reply With Quote
Thanked By: shoe
Old 03/18/2010, 04:50 PM   #2 (permalink)
Member
 
Analog's Avatar
 
Posts: 148
Can we just disable HTML email altogether? I'd pay for a patch that makes the WebOS mail client emulate Claws-Mail.
Analog is offline   Reply With Quote
Thanked By: shoe
Old 04/26/2010, 09:25 AM   #3 (permalink)
Member
 
Grabber5.0's Avatar
 
Posts: 3,623
Bump. I have been getting more spam lately in my Yahoo account. Even though I have told my wife to avoid opening them, and instead swipe them away, I don't like confirming my email address to the spammers if she or I inadvertently open one by accidentally clicking on it when we go to swipe it. I would prefer they not load by default, with a button to load remote resources if you trust the email.
__________________
Matt Williams
*How to install .patch files on your device*
Developer of: SMS Auto Forward/Reply, GPS Viewer,
Keyring converters for CSV, eWallet, & CodeWallet
Touchpad patches:Keyring HD,ClassicNote HD, YouTube HD (for 2.1 app), Show email recipient addresses for contacts
Phone patches: Forums fixes and enhancements patch, Weather Channel fix
All-device patches: Update GlobalSign certs, Google Sync https fix, Yahoo contact sync fix

Grabber5.0 is offline   Reply With Quote
Thanked By: shoe
Old 06/29/2010, 04:43 PM   #4 (permalink)
Member
 
shoe's Avatar
 
Posts: 34
Bump. I was surprised that I only found this lonely thread about that issue. I would love to disable remote image loading for emails.
shoe is offline   Reply With Quote
Old 06/29/2010, 09:03 PM   #5 (permalink)
Member
 
Analog's Avatar
 
Posts: 148
...and once again, folks, this is a SECURITY ISSUE. YES, I AM SHOUTING. It's important. It's very easy to accidentally open an email while trying to swipe it away. If it's a spam email that you open inadvertently in this way and it loads the HTML, it's trivial for a spammer to have formatted in such a way as to know that you opened it and therefore are at a "good" address. And there's the malware issue.
Analog is offline   Reply With Quote
Thanked By: shoe
Old 10/20/2010, 03:27 AM   #6 (permalink)
Member
 
shoe's Avatar
 
Posts: 34
Has anyone seen if this is already a setting in WebOS 2.0?
shoe is offline   Reply With Quote
Old 10/21/2010, 11:01 AM   #7 (permalink)
Member
 
Posts: 150
Thanks for resurrecting this issue.

After seeing the pathetic Pre 2, I've gone and bought an Evo 4G. If it makes you feel any better, its stock email client ALSO lacks this fundamental feature.

I know iOS Mail has an option to disable remote image loading (but it's buggy and can be circumvented by malicious javascript includes) and supposedly WP7 does as well.
vga4life is offline   Reply With Quote
Old 10/21/2010, 11:26 AM   #8 (permalink)
Member
 
Posts: 316
Seconding this request.

A really simple solution would be to provide a text-only option for email. At a minimum, please let us send outbound email as plain text.
zParticle is offline   Reply With Quote
Thanked By: shoe
Old 03/03/2011, 04:29 PM   #9 (permalink)
Member
 
shoe's Avatar
 
Posts: 34
Can someone check if this already has been addressed by HP in WebOS 2.1?
shoe is offline   Reply With Quote
Old 03/03/2011, 06:03 PM   #10 (permalink)
Member
 
Grabber5.0's Avatar
 
Posts: 3,623
Does not look like it has.
__________________
Matt Williams
*How to install .patch files on your device*
Developer of: SMS Auto Forward/Reply, GPS Viewer,
Keyring converters for CSV, eWallet, & CodeWallet
Touchpad patches:Keyring HD,ClassicNote HD, YouTube HD (for 2.1 app), Show email recipient addresses for contacts
Phone patches: Forums fixes and enhancements patch, Weather Channel fix
All-device patches: Update GlobalSign certs, Google Sync https fix, Yahoo contact sync fix

Grabber5.0 is offline   Reply With Quote
Thanked By: shoe
Old 03/09/2011, 06:54 AM   #11 (permalink)
Member
 
shoe's Avatar
 
Posts: 34
Thanks for the fast feedback!

I am kind of speechless about this because I do not understand why HP does not address this major privacy and security issue.

I suppose that it is not possible to create a patch, is it?

Well, I will try to contact them over Twitter since my feedback using the hotline did not seem to get the attention.
shoe is offline   Reply With Quote
Reply

 

Thread Tools
Display Modes



 


Content Relevant URLs by vBSEO 3.6.0