Skip to content

Comment on Human study on AI spear phishing campaignsparent

Comments

A good start would be ditching HTML in email. Plain text is perfectly suitable for non-marketing emails (and marketing emails are just chaff at this point anyways).

I’ll die on this hill.

One word deserves so much blame for the current state of the internet: marketing

You can be perfectly spearphished by a plaintext email, sent by your “colleague”, mentioning some current issue at work, and asking to verify some ticket

or by your “friend” mentioning a highly personal issue that only you two were supposed to know, asking you to phone someone on their behalf

or by your “relative”, etc.

Security is eliminating attack vectors one at a time. HTML in email is a gigantic hole. We don’t throw up our hands and say “whelp this only solves 90% of issues. Guess we don’t bother.”

I’ll die on this hill.

Same. I found a setting in legacy outlook to force all e-mails to be in plain text. So every corporate email I reply to, converts the product owners html formatted emails into junk.

Gives me a little joy that the e-mail they worked so hard on gets mangled by my outlook replies :)

A good start would be ditching HTML in email.

How would that help? You can put links in plain text.

It's all about attack surface and HTMLs attack surface is huge. HTML in email is strictly unnecessary. Name another popular messaging tool that allows you to craft custom HTML messages. Text, Whatsapp, social posts, Snapchat, etc.

The only people who want to send HTML emails are marketers, advertisers, trackers, scammers, hackers, and that clueless manager who wants the cornflower blue background. (most of these actors are the same people, except for that last one).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.