1. nekrosoft13

  2. snowy owl

  3. +Nik Louch

  4. Steven P.

  5. hellowalkman

  • Posts

    • Sure would be cool, but would you sit at that desk? The 'floating' block of stone would weigh between 250-300tonnes (500,000 to 600,000pounds).
    • If you care about privacy stop using this popular Linux email client, sysadmin warns by David Uzondu When it comes to email clients, you have things like Outlook, which has been around forever, but if you're on Linux, there's a good chance you've heard about Evolution, even with its long history starting back in 2000. Some might call it the Outlook of Linux for being a complete open-source personal information manager, not just an email app, and for supporting protocols ranging from IMAP and POP to Microsoft Exchange. One of the main reasons people choose Evolution is for its security controls. It offers privacy features like displaying emails as plain text, GPG encryption, and the well-known "Load Remote Content" option, which you can find in the security preferences. This setting is supposed to stop marketers and spammers from knowing you opened their email by blocking tracking pixels. This trust might be misplaced. A system administrator from the UK by the name, Mike Cardwell has uncovered a serious flaw. According to him, if a malicious email contains an HTML tag like the following: Evolution performs a DNS request for trackingcode.attackersdomain.example.com the second you open the message. This happens even with remote content disabled. The sender can see that DNS request in their logs, revealing that you read their email and potentially leaking your location via your DNS resolver's IP address. This completely bypasses the privacy feature you thought was protecting you. Cardwell filed a bug report, and the response was dismissive. The Evolution development team, when contacted about the report, blamed WebKitGTK, the web rendering engine the application uses. The team closed his ticket, linking it to another one from April 2024 about a similar tag, which can expose a user's IP address directly. That ticket points to a WebKit bug from August 2023, and nothing shows it will be fixed soon. He even suggested a fix: Evolution could maintain a whitelist of safe HTML tags and just strip out sketchy ones before the email gets handed off to the browser engine. He argued this would be a solid defense-in-depth strategy, but this looks unlikely to be followed. Cardwell is now advising users who value their privacy to ditch Evolution and switch to something else. His point is that the developers do not seem to consider this privacy leak their responsibility. Because Evolution is the default client for GNOME, one of the most popular Linux desktop environments, it comes preinstalled on major distributions like Fedora, potentially affecting thousands of users without their knowledge.
    • Started seeing this yesterday too, it is still synching but only intermittently, to be honest if it manages a couple of times a week that's probably good enough. Very sensationalist headline though!
    • Windows Server Update Services (WSUS) is broken, and there is no workaround In a statement to Bleeping Computer, Microsoft acknowledged the problem and noted that it is working on a fix. That's mean there is no workaround yet, but there will be a fix ?
  • Recent Achievements

    • Contributor
      Case_f went up a rank
      Contributor
    • Week One Done
      9kitti earned a badge
      Week One Done
    • One Month Later
      petercotton23 earned a badge
      One Month Later
    • Week One Done
      petercotton23 earned a badge
      Week One Done
    • Dedicated
      djtaylor earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      467
    2. 2
      +FloatingFatMan
      165
    3. 3
      ATLien_0
      165
    4. 4
      Xenon
      108
    5. 5
      macoman
      89
  • Tell a friend

    Love Neowin? Tell a friend!