[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Serious information leak in Ximian Evolution



On Sat, 2003-01-18 at 12:36, Csillag Kristóf wrote:
> Well, it is a little bit offtopic, but it's a serious issue,
> concerning the privacy of many of us, so I thought you might
> be interested.
> 
> Ximian Evolution
> Debian package version: 1.2.1-2
> 
> BCC Recipients ARE NOT HIDDEN from the other recipients of the message
> !!!!!!!

It is not the job of evolution to hide Bcc recipients, that is the job
of the SMTP-server being used.
Bcc recipient specification in evolution is just a nice way of
specifying addresses to be included in rcpt to: smtp commands, which are
not included in either the cc: or to: headers.

It is the job of the smtp-server to remove any bcc: headers in email
messages.

Oh, and for the record, I strongly suggest to reduce the number of
exclamation marks you use.
-- 
Søren O.                                            ,''`.
                                                   : :' :
GPG Public key: finger boll <at> db.debian.org     `. `'
GPG signed mail preferred.                           `-



Reply to: