|
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Privacy group warns of e-mail wiretap
(IDG) -- A newly identified snooping technology allows someone sending an e-mail to see what the recipient wrote when it is forwarded on to another user, an Internet privacy group announced Monday. It really is a wiretap and it's "very illegal and very easy to do," said Richard Smith, chief technology officer for the Privacy Foundation based in Denver, in a column he wrote for the non-profit educational and research organization. The vulnerability exists in mail that uses HTML (HyperText Markup Language). A few lines of JavaScript can be embedded in an e-mail message and allows the recipient's mail to be returned to the original sender. It only works, however, if the recipient's e-mail program is set to read JavaScript.
Smith learned about the email exploit while working on research on Web bugs, an invisible image embedded in a Web page or e-mail that quietly transmits a message back to a remote computer when viewed. He corresponded with Carl Voth, an engineer in British Columbia, who told him about the JavaScript vulnerability. Voth is believed to have discovered the flaw he calls the "reaper exploit" in October 1998.
Computer scientists from the Privacy Foundation have learned that the exploit only works when the recipient is using an HTML/JavaScript-enabled e-mail reader such as Microsoft Corp.'s Outlook, Outlook Express or version 6 of Netscape Communications Corp.'s Web browser package. Eudora, Qualcomm Inc.'s email software, and version 6 of America Online Inc.'s latest client software are not affected as JavaScript is turned off by default. Microsoft's Hotmail and other Web-based email systems automatically remove JavaScript programs from incoming e-mail messages and therefore are not vulnerable. Smith, in his column, worries that the exploit may be used often and people may try to gain access to information that they normally would not be privileged to see. For example, a user may send a resume via e-mail and then learn what the potential employer thinks about his or her qualifications, Smith writes. The Privacy Foundation has requested Microsoft and Netscape to turn off JavaScript code by default in all of their e-mail readers. Little use is seen for JavaScript in e-mail, only pitfalls such as viruses, e-mail spam and now the wiretapping problem, Smith said. RELATED STORIES:
Consortium proposes new privacy guidelines RELATED IDG.net STORIES:
How to batten down the hatches on Media Player, Outlook, Explorer RELATED SITES:
The Privacy Foundation |
Polls open in Israel election Former Chicago-area factory worker kills 4, self Attorneys lay out embassy bombing cases Bush meets with Canadian leader (MORE)
Oklahoma St. returns to court, beats Missouri Iowa State continues mastery of No. 5 Kansas Raptors hand Celtics first loss in seven games (MORE)
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Back to the top |
© 2001 Cable News Network. All Rights Reserved.
Terms under which this service is provided to you. Read our privacy guidelines. |