Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ooh thanks for this :)

Got a "DNS Prefetch - Anchor" on Gmail



That one used to trigger on Thunderbird and Apple Mail. It was fixed after I submitted the relevant bug reports.


Could you link to the fix/bug report? My mozilla-ppa(deb) Thunderbird 10.0.2 leaks like the Titanic after the iceberg.

Gmail does much much better - a counter-intuitive result.


DNS pre-fetching was disabled in v3.0.2 - https://bugzilla.mozilla.org/show_bug.cgi?id=544745#c21

I am surprised that you're seeing leaks in Thunderbird 10.0.2. That is my own client of choice so I'm always keeping an eye on it after updates and I am not currently seeing any leaks... If you have remote images disabled, are you still seeing leaks? If so, which ones?


It was just a dns pre-fetch. (I never expected Thunderbird to do that.)

I disabled preFetch in the config editor and my ship's running dry again.


For me, Thunderbird had a dns-prefetch leak, but it's fixable via config.


Seems, the author has already documented this.

For those interested: https://grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_an...


So did I, it picked up a Google IP address. Anyone know how to close this? I have images turned off.


It seems to be the MTA (probably the spam filter), since it happens to me even without any client open, so there's probably no way to close it by your end.


If it happens without any client open, then it isn't really a problem is it?


Well, it doesn't happen if the address doesn't exist (I tested it too), so it can still be used by spammers to check for that.


If an address doesn't exist the message will simply bounce. Or am I missing something?


Yes, here is an example of an address that doesn't exist:

https://grepular.com/email_privacy_tester/lookup?code=gapz72...

If the address exists in Gmail, you get a response on "DNS Prefetch - Anchor", so it could be used to determine whether to send an email or not. I'm not a mail administrator but I can imagine how it might be useful to a spammer, e.g to stop mass bounce replies.


Erk.

webOS email client leaks data all over the place.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: