Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Apple tops the $100B+ tech club
How to get the IRS' attention: Forge nearly $8 million in tax returns, steal identities
Microsoft details Windows 8 for ARM devices
Blogger exposes major Google Wallet security flaw
Web app lets enterprise set security, sharing for Google Apps users
Cloudscaling to offer OpenStack private cloud platform
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
Resume Makeover: How an Information Security Professional Can Target CSO Jobs
FBI unbolts Steve Jobs 1991 investigation file
Cisco boosted profit, sales in Q2 while cutting costs
Macs take on the enterprise
/

HTML e-mail open to 'wiretaps'

Today's breaking news
Send to a friendFeedback


An Internet privacy group warned last week that HTML e-mail can be rigged so that the sender can see whatever recipients write when forwarding the message to others.

This capability, likened by The Privacy Foundation to a wiretap, affects HTML e-mail programs that run JavaScript, a widely used scripting language for Web pages. These programs include Microsoft Outlook 2000, Outlook Express 5.0 and Netscape Messenger 6.0.

Users can protect themselves by shutting off JavaScript in their e-mail readers. But the embedded JavaScript "wiretap" in a message can still work if the message is forwarded to someone who has JavaScript turned on.

Richard Smith, CTO for the Denver privacy group, uncovered the vulnerability while conducting Web research. He credits programmer Carl Voth with first documenting the ability of JavaScript to intercept e-mail text in 1998.

The group has called for Microsoft and others to rework their programs so that JavaScript is off unless a user turns it on.

The complete report is available at The Privacy Foundation's Web site.

RELATED LINKS


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.