Fighting bloated email messages
Posted Aug 24, 2006 2:26 UTC (Thu) by
bignose (subscriber, #40)
Parent article:
Fighting image spam
The solution to this is the same as it's always been. Send and accept only email messages bodies that are plain text. Putting images, HTML pages, word documents, or any other junk in the message body is an invitation to abuse.
Note that this doesn't mean *attachments* are junk, if all parties involved want them. And things like OpenPGP signatures, that are small and aren't required for the message body to be read, don't detract from this either.
If we use MUAs that display only static, local, textual information in the message header and body, and *don't* treat the message as an executable program or network-retrieval script or image-display request, this sort of spam wouldn't exist: There'd be no point sending an attached image that purported to be the message body, because MUAs wouldn't interpret it that way.
If, on the other hand, we invite everyone to send us any old crap as a message body and attachments, and expect our MUA to unquestioningly display all the attachments it can get its hands on, this sort of spam can only flourish.
(
Log in to post comments)