Get the latest tech news

Evolution Mail Users Easily Trackable


Mike Cardwell's Tech Blog. Security, privacy, and technology

Evolution Mail’s “Load Remote Content” option, as a privacy protection feature doesn’t work. An attacker could look at the SNI header during the TLS negotiation to identify the unique reader of such an email, and it would grant them their IP address. This one links back to a webkit bug which was opened in August 2023, which also suggests there will be other such leaks, and which shows no sign of being dealt with.

Get the Android app

Or read this on Hacker News