|
|
||||||||||||||||||||||||||||||||||
Privacy group warns of e-mail wiretap
(IDG) -- A newly identified snooping technology allows someone sending an e-mail to see what the recipient wrote when it is forwarded on to another user, an Internet privacy group announced Monday. It really is a wiretap and it's "very illegal and very easy to do," said Richard Smith, chief technology officer for the Privacy Foundation based in Denver, in a column he wrote for the non-profit educational and research organization. The vulnerability exists in mail that uses HTML (HyperText Markup Language). A few lines of JavaScript can be embedded in an e-mail message and allows the recipient's mail to be returned to the original sender. It only works, however, if the recipient's e-mail program is set to read JavaScript.
Smith learned about the email exploit while working on research on Web bugs, an invisible image embedded in a Web page or e-mail that quietly transmits a message back to a remote computer when viewed. He corresponded with Carl Voth, an engineer in British Columbia, who told him about the JavaScript vulnerability. Voth is believed to have discovered the flaw he calls the "reaper exploit" in October 1998.
Computer scientists from the Privacy Foundation have learned that the exploit only works when the recipient is using an HTML/JavaScript-enabled e-mail reader such as Microsoft Corp.'s Outlook, Outlook Express or version 6 of Netscape Communications Corp.'s Web browser package. Eudora, Qualcomm Inc.'s email software, and version 6 of America Online Inc.'s latest client software are not affected as JavaScript is turned off by default. Microsoft's Hotmail and other Web-based email systems automatically remove JavaScript programs from incoming e-mail messages and therefore are not vulnerable. Smith, in his column, worries that the exploit may be used often and people may try to gain access to information that they normally would not be privileged to see. For example, a user may send a resume via e-mail and then learn what the potential employer thinks about his or her qualifications, Smith writes. The Privacy Foundation has requested Microsoft and Netscape to turn off JavaScript code by default in all of their e-mail readers. Little use is seen for JavaScript in e-mail, only pitfalls such as viruses, e-mail spam and now the wiretapping problem, Smith said. RELATED STORIES:
Consortium proposes new privacy guidelines RELATED IDG.net STORIES:
How to batten down the hatches on Media Player, Outlook, Explorer RELATED SITES:
The Privacy Foundation |
SCI-TECH
Study: Gadget sales flat Protest slams Dell's use of prison labor Steve Jobs keeps Apple in the limelight (MORE)
N. Y. plans to heal skyline Stocks rise on Case departure Lieberman's presidential announcement today New arrests may be linked to UK ricin scare (MORE)
Jordan says farewell for the third time Shaq could miss playoff game for child's birth Ex-USOC official says athletes bent drug rules (MORE)
|
||||||||||||||||||||||||||||||||||
| Back to the top |
© 2003 Cable News Network LP, LLLP.
A Time Warner Company. All Rights Reserved. Terms under which this service is provided to you. Read our privacy guidelines. Contact us. |