Coder Social home page Coder Social logo

Comments (9)

dcpurton avatar dcpurton commented on June 2, 2024 1

Editing the message body is a "feature" of MS Exchange...

from neomutt.

scottkosty avatar scottkosty commented on June 2, 2024 1

The mail provider fixed the bug in a few minutes after my report, though, so they were nice. :-)

Wow, it's nice to hear stories like this :)

Indeed, my university moved to MS Exchange, and it is an edit of the message body. In any case, thanks for your issues on protecting headers and signatures. I hope to use PGP increasingly more.

from neomutt.

alejandro-colomar avatar alejandro-colomar commented on June 2, 2024

I wonder why (some) lists inject a signature, instead of adding a header field. By adding a header field, they wouldn't be destructive to the message, and wouldn't cause problems like this one.

They could do something like:

Mailing-List-Archives: <http://lists.lyx.org/mailman/listinfo/lyx-devel>
Mailing-List: lyx-devel mailing list <[email protected]>

(I completely made up those header field names.)

from neomutt.

scottkosty avatar scottkosty commented on June 2, 2024

That would indeed make a lot of sense! My university also injections messages, like prepending "[External Email]". In theory they would argue it makes it more secure, but I would disagree. I suppose it depends on the user.

from neomutt.

alejandro-colomar avatar alejandro-colomar commented on June 2, 2024

Does your university add "[External Email]" to the body or to the Subject? If it's done on the subject, I hope they do it only on the unprotected subject. If they don't edit the protected subject, the signature should remain valid.

However, they may have a bug, and replace also the protected Subject. Yesterday, I had to report a bug to my mail provider, which seemed to be injecting a header before any From header field, and since mutt(1) has a bug by which it protects the From header field (among others), my mail provider was injecting a header field in the protected header, and thus invalidating my signature (for some reason, either my provider or mutt(1) only reproduce this bug sometimes, so my signature remained valid most of the cases). The mail provider fixed the bug in a few minutes after my report, though, so they were nice. :-)

Anyway, you could report a security bug (especially to the mailing list). Maybe they fix it.

from neomutt.

alejandro-colomar avatar alejandro-colomar commented on June 2, 2024

The mail provider fixed the bug in a few minutes after my report, though, so they were nice. :-)

Wow, it's nice to hear stories like this :)

It's migadu, in case you might be interested: https://migadu.com/.
I can only say good things about them. :)

Indeed, my university moved to MS Exchange, and it is an edit of the message body.

Heh, if it's recent, maybe you can push with bug reports that it's trashing security. They'll probably ignore them, but there might be a chance.

In any case, thanks for your issues on protecting headers and signatures. I hope to use PGP increasingly more.

Thanks! :-}

from neomutt.

scottkosty avatar scottkosty commented on June 2, 2024

It's migadu, in case you might be interested: https://migadu.com/.
I can only say good things about them. :)

Actually I am interested. Thanks! I'll check them out.

from neomutt.

alejandro-colomar avatar alejandro-colomar commented on June 2, 2024

I've found a few headers that are used by mailing lists:

List-Archive, List-Help, List-ID, List-Owner, List-Post, List-Subscribe, List-Unsubscribe, List-Unsubscribe-Post.

Please ask that mailing list to use these instead of editing the mail body.

See https://www.iana.org/assignments/message-headers/message-headers.xhtml

from neomutt.

scottkosty avatar scottkosty commented on June 2, 2024

Thanks, I will look into those. It would be nice if they can use better practices. Even without the signature issue, it is annoying that the message is edited.

from neomutt.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.