Advertisement
Promo

Compliance Toolkit

New loophole makes email spying easy

Matthew Broersma ZDNet.co.uk

Published: 05 Feb 2001 13:28 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A newly-discovered email loophole could allow for widespread snooping of other people's online messages, adding to concerns over Internet privacy.

The loophole lets an unscrupulous individual essentially "bug" an email sent to any email client that can accept HTML messages with JavaScript, a simple programming language. Such clients include recent versions of Netscape Messenger, Microsoft Outlook and Qualcomm's Eudora.

The method, uncovered by US group the Privacy Foundation, requires only a few lines of JavaScript to be inserted into an email message. If the message is received by a JavaScript-enabled client, any reply containing the original message will be forwarded back to the original sender.

That means, for example, that someone could send a message to a colleague, and if the message is forwarded to others, each forwarded message or reply would be copied and sent to the original sender, according to the Privacy Foundation.

Even if a user turns off JavaScript, the "email wiretap" code would take effect when received by another user who had not turned off the feature. The Privacy Foundation is campaigning for email clients to be sold with JavaScript turned off as the default.

The group believes spying on others' conversations could become common using this loophole. "Most of us won't release a computer virus, but this is something people would use, particularly if a service started offering it," chief technology officer Richard M Smith told the New York Times. "It's just kind of human nature."

The Privacy Foundation plans to publicise its discovery Monday.

They can see you... Find out how and why in Surveillance, a ZDNet News Special.

Is your PC safe? Find out at the Hackers News Special

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the ZDNet News forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
58 out of 84 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:










Video icon

Video

Cloud Watch Special Report

Five cloud computing myths exploded

Five cloud computing myths exploded

Analysis The cloud is providing a fertile habitat for the marketeers and their exaggerated claims. We examine the hokum and debunk the five most frequently peddled misconceptions about the cloud

More Special Reports

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters