<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/rss-style.xsl" type="text/xsl"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	    xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	     xmlns:dc="http://purl.org/dc/elements/1.1/"
	   xmlns:atom="http://www.w3.org/2005/Atom"
	     xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	  xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>
<channel>
	<title>email &#8211; Terence Eden’s Blog</title>
	<atom:link href="https://shkspr.mobi/blog/tag/email/feed/" rel="self" type="application/rss+xml" />
	<link>https://shkspr.mobi/blog</link>
	<description>Regular nonsense about tech and its effects 🙃</description>
	<lastBuildDate>Mon, 12 Jan 2026 10:27:17 +0000</lastBuildDate>
	<language>en-GB</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://shkspr.mobi/blog/wp-content/uploads/2023/07/cropped-avatar-32x32.jpeg</url>
	<title>email &#8211; Terence Eden’s Blog</title>
	<link>https://shkspr.mobi/blog</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title><![CDATA[It is time to ban email]]></title>
		<link>https://shkspr.mobi/blog/2025/01/it-is-time-to-ban-email/</link>
					<comments>https://shkspr.mobi/blog/2025/01/it-is-time-to-ban-email/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Sun, 12 Jan 2025 12:34:03 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[email]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=54385</guid>

					<description><![CDATA[I think everyone reading this post has accidentally messed up when sending an email, right?  I noticed this story recently:  The Metropolitan Police has apologised to victims of the Westminster &#34;honeytrap&#34; scandal after it accidentally sent an email which named all of them.  …  the sender, a detective sergeant in the Met’s Diplomatic and Parliamentary Protection unit, included the recipients’ name…]]></description>
										<content:encoded><![CDATA[<p>I think everyone reading this post has accidentally messed up when sending an email, right?</p>

<p>I noticed this story recently:</p>

<blockquote><p>The Metropolitan Police has apologised to victims of the Westminster "honeytrap" scandal after it accidentally sent an email which named all of them.</p>

<p>…</p>

<p>the sender, a detective sergeant in the Met’s Diplomatic and Parliamentary Protection unit, included the recipients’ names in the CC section of the email, rather than BCC, which would have concealed their identities.</p>

<p><a href="https://www.bbc.co.uk/news/articles/cp8x33nv420o">Met Police apologises to honeytrap victims over email</a></p></blockquote>

<p>It's a nightmare that I'm sure we've all had. Back in 2016, a similar issue occurred at a medical clinic:</p>

<blockquote><p>A London HIV clinic that leaked data on 781 of its patients has been fined £180,000.</p>

<p>56 Dean Street, based in London's Soho, sent an email newsletter with all patient email addresses in the 'To' field, rather than the 'Bcc' field.</p>

<p><a href="https://www.wired.com/story/56-dean-street-fine-data-protection-hiv/">London HIV clinic fined £180,000 for 'serious' data breach</a></p></blockquote>

<p>It's worth reading <a href="https://web.archive.org/web/20170908140120/https://ico.org.uk/media/action-weve-taken/mpns/1624124/mpn-chelsea-and-westminster-hospital-nhs-foundation-trust.pdf">The Information Commissioner's Office report into the issue</a>.</p>

<p>The use of BCC harks back to <a href="https://datatracker.ietf.org/doc/html/rfc680#appendix-C">RFC 680</a> which was published in April 1975.</p>

<blockquote><p>BCC: This field contains the identity of the tertiary receivers of the message.  This field should not be made available to the primary and secondary receivers, but it may be recorded to provide information for access control.</p></blockquote>

<p>So BCC has been standard on email systems for at least <strong>fifty fucking years</strong> and is still a source of confusion.</p>

<p>Interestingly, the 1975 standard doesn't mention <em>what</em> CC or BCC stand for. It is just assumed these are acronyms with which everyone is <i lang="fr">au fait</i>.  Perhaps not surprising since <a href="https://www.merriam-webster.com/wordplay/meaning-history-cc-and-bcc-email">they were in common usage since the mid-twentieth century</a></p>

<p>When was the last time you used carbon paper to make a copy? Have you ever dictated to your secretary who a memorandum should be blind-copied to?</p>

<p>Email and its tooling are unsuitable to the modern world. Search any social network at any time of the year and you'll find people kvetching about its inadequacies.</p>

<blockquote class="bluesky-embed" data-bluesky-uri="at://did:plc:en7czkhogfoggztn3newgk3u/app.bsky.feed.post/3lcohv5fujc23" data-bluesky-cid="bafyreicsd57doacpazhjrf5e4w64xejc2dy6y65t5wi27uipa7huxct7pm"><p lang="en">Friendly reminder to use literally anything other than email if you need to have a conversation between multiple people that you have any hope in following.</p>— <a href="https://bsky.app/profile/did:plc:en7czkhogfoggztn3newgk3u?ref_src=embed">Emily (@emilyshepherd.me)</a> <a href="https://bsky.app/profile/did:plc:en7czkhogfoggztn3newgk3u/post/3lcohv5fujc23?ref_src=embed">2024-12-07T00:46:28.290Z</a></blockquote>

<script async="" src="https://embed.bsky.app/static/embed.js" charset="utf-8"></script>

<p>This isn't a new sport, of course. Twenty years ago, people were complaining about how bad email was:</p>

<blockquote><p>Email is getting out of hand and people use it in suboptimal ways. They write back and forth, sending documents over and over again, with the end result that nobody knows whether they are working on the correct version of a document and everyone has lost track of where they stand and what the last resolution was on a particular issue on a particular discussion point.</p>

<p>[…]</p>

<p>It's becoming counterproductive and it's not an appropriate medium for many types of communication, so we need to find a way of replacing email.</p>

<p><a href="https://suw.charman-anderson.com/wp-content/uploads/2013/07/Dark_Blogs_01_European_Pharma_Group.pdf">Dark Blogs: The Use of Blogs in Business</a> 2005</p></blockquote>

<p>That was written when blogs were in their ascendency. Nowadays, most modern organisations use collaborative documents. A single living document which can be continually updated or commented on. Of course, discussion <em>about</em> the document still often takes place over email or instant messaging or - heaven forbid! - in person.</p>

<p>This, of course, leads to another issue.</p>

<blockquote class="social-embed" id="social-embed-113638797375286510" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://fediscience.org/@ElenLeFoll" class="social-embed-user" itemprop="url"><img class="social-embed-avatar" src="https://fediscience.org/system/accounts/avatars/109/269/828/517/371/720/original/d27efa67f4eaaa20.jpeg" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">@ElenLeFoll@fediscience.org</p>Elen Le Foll 🇫🇷 🇬🇧 🇩🇪</div></a><img class="social-embed-logo" alt="Mastodon" src="data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' aria-label='Mastodon' role='img' viewBox='0 0 512 512' fill='%23fff'%3E%3Cpath d='m0 0H512V512H0'/%3E%3ClinearGradient id='a' y2='1'%3E%3Cstop offset='0' stop-color='%236364ff'/%3E%3Cstop offset='1' stop-color='%23563acc'/%3E%3C/linearGradient%3E%3Cpath fill='url(%23a)' d='M317 381q-124 28-123-39 69 15 149 2 67-13 72-80 3-101-3-116-19-49-72-58-98-10-162 0-56 10-75 58-12 31-3 147 3 32 9 53 13 46 70 69 83 23 138-9'/%3E%3Cpath d='M360 293h-36v-93q-1-26-29-23-20 3-20 34v47h-36v-47q0-31-20-34-30-3-30 28v88h-36v-91q1-51 44-60 33-5 51 21l9 15 9-15q16-26 51-21 43 9 43 60'/%3E%3C/svg%3E"></header><section class="social-embed-text" itemprop="articleBody"><p>I am only now realising that some (many?) undergrads do not understand the concept of sending a file via e-mail because they are so used to files being saved in clouds. It's the first time I've had to explain that, if I send you a file, then you now *own* that file and, if you modify it and then (accidentally) delete it, your version of that file is gone (or in the trash, if you're lucky). <a href="https://fediscience.org/tags/GettingOld" class="mention hashtag" rel="tag">#<span>GettingOld</span></a></p><div class="social-embed-media-grid"></div></section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://fediscience.org/@ElenLeFoll/113638797375286510"><span aria-label="58 likes" class="social-embed-meta">❤️ 58</span><span aria-label="6 replies" class="social-embed-meta">💬 6</span><span aria-label="35 reposts" class="social-embed-meta">🔁 35</span><time datetime="2024-12-12T08:00:38.466Z" itemprop="datePublished">08:00 - Thu 12 December 2024</time></a></footer></blockquote>

<p>Perhaps we're on the cusp of obliterating email? Will the youth of today see sending an email as ridiculously old-fashioned as a paper telegram or a landline?</p>

<p>There are, I'll admit, some advantages to email. The most prominent being that the receiver can <em>permanently</em> store a copy.  Notwithstanding inept attempts to recall an email (which often highlights its sensitivity) an email delivered is an email stored. That is undoubtedly useful for the recipient.</p>

<p>But it is hard to escape the conclusion that email is an analogue process in a digital world.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=54385&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2025/01/it-is-time-to-ban-email/feed/</wfw:commentRss>
			<slash:comments>22</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Using phpList for a blog's newsletter]]></title>
		<link>https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/</link>
					<comments>https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Thu, 31 Oct 2024 12:34:36 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[HowTo]]></category>
		<category><![CDATA[newsletter]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[rss]]></category>
		<category><![CDATA[WordPress]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=53583</guid>

					<description><![CDATA[Some people like to receive this blog via email. I previously used JetPack to send out subscriber messages - but it became increasingly clear that Automattic isn&#039;t a good steward of such things.  I couldn&#039;t find any services which would let me send a few thousand subscribers a few emails per week, at zero cost.  So, redecentralise!  I installed phpList which is an open source email campaign tool. …]]></description>
										<content:encoded><![CDATA[<p>Some people like to receive this blog via email. I previously used JetPack to send out subscriber messages - but it became increasingly clear that Automattic isn't a good steward of such things.  I couldn't find any services which would let me send a few thousand subscribers a few emails per week, at zero cost.</p>

<p>So, redecentralise!</p>

<p>I installed <a href="https://www.phplist.org/">phpList</a> which is an open source email campaign tool.  My webhost - <a href="https://krystal.io/">Krystal</a> - had a one-click install option. But, phpList isn't quite one-click for sending out a regular blog newsletter.  <a href="https://discuss.phplist.org/t/daily-rss-problems-there-are-no-feed-items-that-will-be-included-in-the-first-campaign/9835/">I found the set-up to be quite confusing</a>, so here are the steps I took to turn an RSS feed into an Email Newsletter for free.</p>

<h2 id="install-the-plugins"><a href="https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#install-the-plugins">Install the plugins</a></h2>

<ol>
<li>Navigate to Config → Manage plugins</li>
<li>Enable "CommonPlugin"</li>
<li>Add the <a href="https://resources.phplist.com/plugin/rssfeed">RSS Feed Plugin</a> using the Plugin package URL <code>https://github.com/bramley/phplist-plugin-rssfeed/archive/master.zip</code></li>
</ol>

<h2 id="configure-the-rss-feed-plugin"><a href="https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#configure-the-rss-feed-plugin">Configure the RSS Feed Plugin</a></h2>

<ol>
<li>Navigate to Config → Settings</li>
<li>Scroll down to the RSS Settings</li>
<li>Set both Minimum <em>and</em> Maximum number of items to 1<br><img src="https://shkspr.mobi/blog/wp-content/uploads/2024/10/rsssettings-fs8.png" alt="RSS Settings Screen." width="888" height="450" class="aligncenter size-full wp-image-53584"><br>That will ensure you only send the latest RSS item as your newsletter.</li>
<li>Set "Use the item summary content (the description or summary element) instead of the content element" to "No". This will allow the full text of the RSS item to be sent.</li>
</ol>

<h2 id="edit-config-php"><a href="https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#edit-config-php">Edit <code>config.php</code></a></h2>

<p>For some reason, you need to manually edit this file in a text editor, rather than a GUI.</p>

<ol>
<li>Set <code>define('USE_REPETITION', 1);</code> - this allows the newsletter to be sent whenever there is a new RSS item.</li>
<li>Set <code>define('CLICKTRACK', 0);</code> - this removes tracking links from your emails. I don't care who opens my emails or what they click on.</li>
</ol>

<h2 id="add-the-campaign"><a href="https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#add-the-campaign">Add The Campaign</a></h2>

<ol>
<li>Go to  Campaigns → Send a campaign.</li>
<li>Start a new campaign.</li>
</ol>

<h3 id="tab-1"><a href="https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#tab-1">Tab 1</a></h3>

<ol>
<li>Campaign subject should be <code>[RSSITEM:TITLE]</code> - that will make the subject line the same as your <strong>post</strong>'s title</li>
<li>Compose message should be <code>[RSS]</code> - that will ensure the contents come from your RSS feed.</li>
</ol>

<h3 id="tab-2"><a href="https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#tab-2">Tab 2</a></h3>

<ol>
<li>Add your RSS feed's URl</li>
<li>Order items "Newest" first - to get the most recent item.</li>
<li>Add a custom HTML template. I used one from <a href="https://emailframe.work/">https://emailframe.work/</a></li>
</ol>

<pre><code class="language-html">&lt;div style="margin:0; padding:0; background-color:#F2F2F2;"&gt;
  &lt;h1&gt;&lt;a href="[URL]"&gt;[TITLE]&lt;/a&gt;&lt;/h1&gt;
  &lt;table width="100%" border="0" cellpadding="0" cellspacing="0" bgcolor="#F2F2F2"&gt;
      &lt;tr&gt;
          &lt;td valign="top"&gt;
              [CONTENT]
          &lt;/td&gt;
      &lt;/tr&gt;
  &lt;/table&gt;
&lt;/div&gt;
</code></pre>

<h3 id="tab-3"><a href="https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#tab-3">Tab 3</a></h3>

<ol>
<li>Send as HTML</li>
</ol>

<h3 id="tab-4"><a href="https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#tab-4">Tab 4</a></h3>

<ol>
<li>"Stop sending after" - choose the furthest date in the future possible.</li>
<li>"Repeat campaign every" - I chose "hour". That should check the RSS feed each hour.</li>
</ol>

<h3 id="tab-5"><a href="https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#tab-5">Tab 5</a></h3>

<ol>
<li>"Lists" - pick the email list you want to send from.</li>
</ol>

<h3 id="tab-6"><a href="https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#tab-6">Tab 6</a></h3>

<ol>
<li>You should be finished! It will tell you if there are any errors.</li>
<li>Place the campaign in the queue for processing.</li>
</ol>

<h2 id="wordpress-sign-up-form"><a href="https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#wordpress-sign-up-form">WordPress Sign Up Form</a></h2>

<p>You can either redirect users to your phpList subscription page, or put a form directly on your site.</p>

<pre><code class="language-html">&lt;form method="post" action="/YourSubscribePage/?p=subscribe&amp;id=1" name="subscribeform"&gt;
    &lt;label for="email"&gt;Email address:&lt;/label&gt;
    &lt;input type="email" name="email" required="required" placeholder="" size="40" id="email"&gt;
    &lt;input type="hidden" name="htmlemail" value="1"&gt;
    &lt;input type="hidden" name="list[2]" value="signup"&gt;
    &lt;input type="hidden" name="listname[2]" value="newsletter"&gt;
    &lt;div style="display:none"&gt;
        &lt;input type="text" name="VerificationCodeX" value="" size="20"&gt;
    &lt;/div&gt;
    &lt;input type="submit" name="subscribe" value="Subscribe"&gt;
&lt;/form&gt;
</code></pre>

<p>Adjust the hidden parameters based on your list.</p>

<p>If in doubt, go to Config →  Subscribe pages, and generate a new subscribe page. Then copy the form from that.</p>

<h2 id="cron-jobs"><a href="https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#cron-jobs">Cron Jobs</a></h2>

<p>You need two cron jobs set up.</p>

<h3 id="update-the-rss-feed"><a href="https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#update-the-rss-feed">Update the RSS feed</a></h3>

<p>I run this every hour:</p>

<p><code>/usr/bin/php /path/to/YourSubscribePage/admin/index.php -p get -m RssFeedPlugin -c /path/to/YourSubscribePage/config/config.php</code></p>

<h3 id="process-the-queue"><a href="https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#process-the-queue">Process the Queue</a></h3>

<p>I run this a few minutes after the RSS feed is updated</p>

<p><code>/usr/bin/php -q /path/to/YourSubscribePage/admin/index.php -p processqueue -c /path/to/YourSubscribePage/config/config.php &gt;/dev/null</code></p>

<h2 id="and-then"><a href="https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/#and-then">And then...</a></h2>

<p>That <em>should</em> be it.  There are lots of options which you can fiddle around with. But the above should be enough to get your first newsletter out.</p>

<p>Huge thanks to <a href="https://dcameron.me.uk/">Duncan Cameron</a> for graciously answering my noddy questions and helping me out with the config.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=53583&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2024/10/using-phplist-for-a-blogs-newsletter/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[The IAB loves tracking users. But it hates users tracking them.]]></title>
		<link>https://shkspr.mobi/blog/2023/01/the-iab-loves-tracking-users-but-it-hates-users-tracking-them/</link>
					<comments>https://shkspr.mobi/blog/2023/01/the-iab-loves-tracking-users-but-it-hates-users-tracking-them/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Mon, 16 Jan 2023 12:34:28 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[advertising]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[privacy]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=44683</guid>

					<description><![CDATA[The Interactive Advertising Bureau (IAB) is a standards development group for the advertising industry. Their members love tracking users. They want to know where you are, who you&#039;re with, what you&#039;re buying, and what you think. All so they can convince you to spend slightly more on toothpaste.  Or change your political opinions. Either way, they are your adversaries.  The IAB&#039;s tech lab is…]]></description>
										<content:encoded><![CDATA[<p>The Interactive Advertising Bureau (IAB) is a standards development group for the advertising industry. Their members <em>love</em> tracking users. They want to know where you are, who you're with, what you're buying, and what you think. All so they can convince you to spend slightly more on toothpaste.  Or change your political opinions. Either way, they are your adversaries.</p>

<p>The IAB's tech lab is working on a system called <a href="https://github.com/IABTechLab/uid2docs">UID2</a>. It's a more advanced way to track you no matter what you do and no matter what steps you take to avoid it.</p>

<blockquote><p>UID2 is a framework that enables deterministic identity for advertising opportunities on the open internet for many participants across the advertising ecosystem. The UID2 framework enables logged-in experiences from publisher websites, mobile apps, and Connected TV (CTV) apps to monetize through programmatic workflows.</p></blockquote>

<p>Basically, they tie your email address to everything you do. Signed in to watch a TV show? Better sell that info to the advertisers so when you sign in to a different site they can send you targetted messages. Yuck.</p>

<p>One of the ways privacy conscious users normally avoid this is by subtly altering their email addresses for each service they use.  For example, GMail ignores any dots in your username. So if you are <code>Han.Solo@gmail.com</code> you can also use <code>H.ansolo@gmail.com</code> or <code>ha.ns.ol.o@gmail.com</code>.  A user might sign up to a service and use a specifically "dotted" email address.  If they later start receiving spam to that address, they know the service has leaked or sold their info.</p>

<p>You can go one step further and use <a href="https://www.fastmail.help/hc/en-us/articles/360060591053-Plus-addressing-and-subdomain-addressing">plus addressing</a>.  For example <code>han.solo+amazon@gmail.com</code> and <code>han.solo+github@gmail.com</code>. They both will appear in your normal inbox, but are unique for every service you use. Again, this is great for making sure that someone hasn't sold your email address to spammers.</p>

<p>The IAB <em>hates</em> this.</p>

<p>As part of the <a href="https://github.com/IABTechLab/uid2docs/blob/main/docs/getting-started/gs-normalization-encoding.md">UID2 API</a> they specifically describe how an advertiser must "normalise" their users' email addresses.</p>

<p>This means <code>h.a.n.solo+iab@gmail.com</code> becomes plain old <code>hansolo@gmail.com</code></p>

<p>I think this is pretty shitty behaviour. If someone has <em>deliberately</em> set their email address in this form it is because the user <em>does not want</em> their identities to be commingled.</p>

<p>Last year, I <a href="https://github.com/IABTechLab/uid2docs/pull/16">asked them to respect users' privacy and reverse this change</a>.  They finally responded:</p>

<blockquote><p>Thank you for your input, we thought long about this update and ultimately as it stands today it is not a change we would like to add.</p></blockquote>

<p>So, there you have it. If you want to take even the smallest step to preserve your privacy - tough. 
If you want to track which IAB members are using your data - tough.
If you want to track users even if they don't want to be tracked - the IAB is happy to help.</p>

<p>If you want to opt out of this - and you trust the IAB to handle your data safely - you can submit your email address and phone number to <a href="https://transparentadvertising.org/"></a><a href="https://transparentadvertising.org/">https://transparentadvertising.org/</a>.</p>

<p>Personally, I recommend installing the <a href="https://ublockorigin.com/">uBlock advert blocker</a> on all devices which support it.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=44683&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2023/01/the-iab-loves-tracking-users-but-it-hates-users-tracking-them/feed/</wfw:commentRss>
			<slash:comments>20</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[if ( gender == "female" && married == True && age >=30 ) { hasChildren = True; }]]></title>
		<link>https://shkspr.mobi/blog/2021/05/if-gender-female/</link>
					<comments>https://shkspr.mobi/blog/2021/05/if-gender-female/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Wed, 12 May 2021 11:21:11 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[badvertising]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[marketing]]></category>
		<category><![CDATA[rail]]></category>
		<category><![CDATA[spam]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=38952</guid>

					<description><![CDATA[Marketing really is crap. Recently, SE Railways sent this piece of email drivel to my wife:   We don&#039;t have any kids, thankfully - and are not having any in the future. My wife was literally recovering from a sterilisation procedure when the email arrived. So it seemed a bit weird that they&#039;d send her a message like that.  My wife has never booked a child&#039;s fare. She&#039;s done nothing to indicate to …]]></description>
										<content:encoded><![CDATA[<p>Marketing really is crap. Recently, SE Railways sent this piece of email drivel to my wife:
<img src="https://shkspr.mobi/blog/wp-content/uploads/2021/05/travel-savy.png" alt="Email promting parents to get their kids travel savvy." width="270" height="455" class="aligncenter size-full wp-image-38953"></p>

<p>We don't have any kids, <a href="https://shkspr.mobi/blog/2019/11/do-you-have-kids-thankfully-no/">thankfully</a> - and are not having any in the future. My wife was literally <a href="https://web.archive.org/web/20210426113238/https://mymisanthropicmusings.org.uk/getting-my-tubes-tied/">recovering from a sterilisation procedure</a> when the email arrived. So it seemed a bit weird that they'd send her a message like that.</p>

<p>My wife has never booked a child's fare. She's done nothing to indicate to them that she has spawned. They know that she's married and female, because she set her title to "Mrs". They got her date of birth from the ID checks they carried out - we think.</p>

<p>As far as we can tell, they've unilaterally decided that all married women of a certain age must have kids. Or, perhaps, they just lazily sent the message to all women?</p>

<p>So, she spoke to them, to ask why this specific piece of guff had been sent to her.  All they'd say was the rather nebulous statement that the emails was a "targeted email sent to a number of passengers [...] When passengers use our services we're able to use this data to help us target communications effectively."</p>

<p>Not really answering the question. But they decided to bung us £20 of M&amp;S vouchers for the "upset".</p>

<p>Even the most modest of interactions with a company will be data-mined for trivial details in the vague hope of getting you to spend more money.</p>

<p>Here are a few tips if you want to avoid getting microtargetted like this:</p>

<ul>
<li>Consider using a gender neutral title like Mx - or earn yourself a doctorate.</li>
<li>Use an initial rather than a first name. <a href="https://www.ons.gov.uk/peoplepopulationandcommunity/birthsdeathsandmarriages/livebirths/articles/babynamessince1904howhasyoursperformed/2016-09-02">Names <em>can</em> be used to determine likely age</a>.</li>
<li>Don't answer any demographic questions which aren't necessary to the provision of the service, or have a legal/regulatory basis.</li>
<li>You generally can't unsubscribe from service emails, but you can close your account once you've finished your transaction. Digital hygiene is essential!</li>
</ul>

<p>Of course, if you complain about a mistargeted email, that's another data-point they have about you!</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=38952&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2021/05/if-gender-female/feed/</wfw:commentRss>
			<slash:comments>17</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[GDPR and common sense]]></title>
		<link>https://shkspr.mobi/blog/2020/03/gdpr-and-common-sense/</link>
					<comments>https://shkspr.mobi/blog/2020/03/gdpr-and-common-sense/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Mon, 16 Mar 2020 07:43:35 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[gdpr]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=33955</guid>

					<description><![CDATA[Every so often, I get a glimpse into the thought processes of someone who has a very different view of the world to me.  I don&#039;t deal with people&#039;s personal information often. So I was surprised to receive an email with a multi-megabyte spreadsheet called &#34;Pay and Bonuses 2020&#34;. The email contained this doozy of a sentence:  “Due to GDPR the attached file is password protected, I will send the p…]]></description>
										<content:encoded><![CDATA[<p>Every so often, I get a glimpse into the thought processes of someone who has a very different view of the world to me.</p>

<p>I don't deal with people's personal information often. So I was surprised to receive an email with a multi-megabyte spreadsheet called "Pay and Bonuses 2020". The email contained this <em>doozy</em> of a sentence:</p>

<blockquote><p>“Due to GDPR the attached file is password protected, I will send the password in a separate email”</p></blockquote>

<p>I shit you not.</p>

<p>I checked the sender. They didn't work for my organisation, or any related organisation. We had exchanged emails before, so I suspect email autocomplete had got a bit confused and autofilled "Terence Eden" rather than "Tegan Jovanka" or something.</p>

<p>Two minutes after receiving the email - and before I'd had a chance to inform the sender of their mistake - I received another email.</p>

<blockquote><p>The password is "03022020" - no quotes</p></blockquote>

<p>Yup, today's date. Fiendishly difficult to crack...</p>

<h2 id="what-are-you-trying-to-prevent"><a href="https://shkspr.mobi/blog/2020/03/gdpr-and-common-sense/#what-are-you-trying-to-prevent">What are you trying to prevent?</a></h2>

<p>I'm trying to understand the thought process going on here.  I <em>think</em> it's based on some faulty comparison to the regular post service.  If someone randomly snatches an email, they are unlikely to also randomly get the password.</p>

<p>But that's not the threat we're facing here. If someone is listening to the network - they'll have both emails. If someone gets access to my inbox - they'll have both emails. If you've sent the email to the wrong person - they'll have both emails.</p>

<p>The only thing this prevents is someone accidentally forwarding a single email.</p>

<h2 id="how-to-solve-this"><a href="https://shkspr.mobi/blog/2020/03/gdpr-and-common-sense/#how-to-solve-this">How to solve this?</a></h2>

<p>Sending an encrypted document through email is fine.</p>

<p>But the password should be sent through an <em>independent</em> channel - preferably one you can authenticate.</p>

<p>In this case, here's the process I would recommend:</p>

<ol>
<li>Send the document via email</li>
<li>Call the <em>intended</em> recipient</li>
<li>Verify you're speaking to the right person</li>
<li>Confirm that they have received the email</li>
<li>Tell them the password</li>
</ol>

<p>Hopefully they'll store it somewhere secure, rather than write it on a Post-It note.</p>

<p>There are alternatives, of course.</p>

<ul>
<li>Send a link and have someone sign in with the correct credentials.</li>
<li>Call the recipient and tell them how to access the document.</li>
<li>Text them the password</li>
<li>I'm sure you can think of more.</li>
</ul>

<p>But, please, whatever you do - think about the threats you are trying to defend against.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=33955&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2020/03/gdpr-and-common-sense/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Stop adding email tracking links to phone numbers!]]></title>
		<link>https://shkspr.mobi/blog/2020/02/stop-adding-email-tracking-links-to-phone-numbers/</link>
					<comments>https://shkspr.mobi/blog/2020/02/stop-adding-email-tracking-links-to-phone-numbers/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Thu, 20 Feb 2020 12:55:36 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[.tel]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[HTML]]></category>
		<category><![CDATA[marketing]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=33907</guid>

					<description><![CDATA[My Chinese takeaway delivery was late. Very late. I flipped open the confirmation email sent by Just-Eat to double-check I had all the details correct.  At the bottom was a &#34;click to call&#34; link. Hurrah!  I clicked dial, and this is what filled my screen:    An absurdly long phone number.  Bemused, I went to inspect the link I&#039;d clicked. This is what it showed:    The tel: URl scheme is brilliant. …]]></description>
										<content:encoded><![CDATA[<p>My Chinese takeaway delivery was late. Very late. I flipped open the confirmation email sent by Just-Eat to double-check I had all the details correct.  At the bottom was a "click to call" link. Hurrah!</p>

<p>I clicked dial, and this is what filled my screen:</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2020/01/Phone-Screen.jpeg" alt="Phone dialler with a very long phone number." width="679" height="206" class="aligncenter size-full wp-image-33908">

<p>An absurdly long phone number.  Bemused, I went to inspect the link I'd clicked. This is what it showed:</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2020/01/Tel-URl.jpeg" alt="Gmail showing the tel URl scheme of a link with extra tracking information in it." width="548" height="680" class="aligncenter size-full wp-image-33909">

<p>The <a href="https://tools.ietf.org/html/rfc3966"><code>tel:</code> URl scheme</a> is <em>brilliant</em>.  You can write something like:</p>

<pre><code class="language-_">&lt;a href="tel:07700 900123"&gt;Call Me!&lt;/a&gt;
</code></pre>

<p>And when you click on <a href="tel:07700 900123">Call Me!</a> your phone dialler will pick up the phone number and offer to place the call. Nifty!</p>

<p>In this case, the crappy marketing system is adding <a href="https://en.wikipedia.org/wiki/UTM_parameters">Urchin Tracking Module parameters</a> to every link. Including the phone numbers.</p>

<pre><code class="language-_">tel:02083178830?utm_medium=ecrm
&amp;utm_source=email
&amp;utm_campaign=TRAN
&amp;utm_content=UK_TRAN_01_0_ORDER-CONFIRMATION_E_V01
&amp;campaign=TRAN
&amp;adgroup=UK_TRAN_01_0_ORDER-CONFIRMATION_E_V01
&amp;utm_term=restaurant_phone_3_3
</code></pre>

<p>To be clear - this is <em>useless</em>.  The user clicks on the phone number, the device passes the URl directly to the phone dialler. An HTTP request is never made and those parameters are never sent to a server.</p>

<p>Now, in fairness, perhaps my Android dialler should probably be smart enough to recognise the cruft at the end of a phone number and discard it. This is <a href="https://automattic.com/postels-law/">Postel's Law</a> in action.</p>

<p>Except... My reading of the RFC says that the dialler is handling things correctly.</p>

<blockquote><p>If the reserved characters "+", ";", "=", and "?" are used as delimiters between components of the "tel" URI, they MUST NOT be percent encoded.  These characters MUST be percent encoded if they appear in tel URI parameter values.</p></blockquote>

<p>For example, if I wanted to dial <code>+447...</code> I should use <code>tel:%2B447...</code></p>

<p>The dialler sees the unencoded <code>?</code> and treats it as a delimiter. It then sees <code>utm</code> and assumes the letters are part of the phone number.  Just like you can dial <code>1-800-FLOWERS</code>, you can write <code>tel:1-800-FLOWERS</code> and have it go through to <code>1-800-356-9377</code>.</p>

<p><code>utm medium</code> on a telephone keypad is <code>886633486</code> - which is exactly what appeared on my phone screen.</p>

<p>So, if you're writing link tracking software, please make sure only to add parameter to URls where it makes sense.</p>

<p>In the time it took me to write this post, my meal got delivered and it was <em>delicious!</em></p>

<blockquote class="social-embed" id="social-embed-1219280859712368640" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/JustEatUK" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRlYBAABXRUJQVlA4IEoBAADwCACdASowADAAPrVSoU0nJKMiI4z44BaJaADDbUE7P/IfhL+Kt9WUzxcXdKNRjX4K1xTMyHrKQAi0/z/ADmlKTL4vcTwrnNvZUfHISv+HQAD+5zD/2s+S3o/kq/1v4qdl9tnebE2CxzBOwsq27D+I3fyhoPvsqymnZnBBDqP/v13khOJBodp5tzPsLFGREV4JcLpJoX5mJgClT/vQDyeMF2vwVK3NIzxEqBNHLytSNrI4TwYQRaaA14krEPFRtYbbFEFVR1H+LUPQCRBIiygBq4G+we8oKtYGcJxiPHemX77Nv+eJ2Pa8GUN+QBGvEXKlEj9DwCbMSIHAtUKUG5Bj0BChGNTCqaTkJt1tJ3gGgGObzgQaeUMcH5DIr/CLFHvb7rfOSS0FvoXVlgGIS4RRm0IJoBYImUAfZiGK6U08v55kT7f/A0fKAAA=" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Just Eat UK</p>@JustEatUK</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody"><small class="social-embed-reply"><a href="https://twitter.com/edent/status/1217895381989765123">Replying to @edent</a></small><a href="https://twitter.com/edent">@edent</a> Thanks for getting in touch and sharing this feedback with us Terence, we appreciate it and we'll be sure to bring this to our tech team's attention. ^EM</section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/JustEatUK/status/1219280859712368640"><span aria-label="1 likes" class="social-embed-meta">❤️ 1</span><span aria-label="1 replies" class="social-embed-meta">💬 1</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2020-01-20T15:29:44.000Z" itemprop="datePublished">15:29 - Mon 20 January 2020</time></a></footer></blockquote>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=33907&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2020/02/stop-adding-email-tracking-links-to-phone-numbers/feed/</wfw:commentRss>
			<slash:comments>6</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[How should couples handle joint email addresses?]]></title>
		<link>https://shkspr.mobi/blog/2019/10/how-should-couples-handle-joint-email-addresses/</link>
					<comments>https://shkspr.mobi/blog/2019/10/how-should-couples-handle-joint-email-addresses/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Tue, 22 Oct 2019 11:12:05 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[family]]></category>
		<category><![CDATA[ui]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=33039</guid>

					<description><![CDATA[For years, my email address was registered with our electricity supplier. I got the monthly bills sent to me.  My wife&#039;s email was used for the water supplier. This made sense when we were a young couple with separate finances - but now we&#039;re a smug an old married couple, with a joint bank account, it&#039;s a bit annoying.  We both want to see the bills, and we don&#039;t want to rely on the other…]]></description>
										<content:encoded><![CDATA[<p>For years, my email address was registered with our electricity supplier. I got the monthly bills sent to me.  My wife's email was used for the water supplier. This made sense when we were a young couple with separate finances - but now we're <del>a smug</del> an old married couple, with a joint bank account, it's a bit annoying.</p>

<p>We both want to see the bills, and we don't want to rely on the other forwarding us an email, or sticking the PDF into a shared folder.</p>

<blockquote class="social-embed" id="social-embed-1185954831472775169" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/edent" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRkgBAABXRUJQVlA4IDwBAACQCACdASowADAAPrVQn0ynJCKiJyto4BaJaQAIIsx4Au9dhDqVA1i1RoRTO7nbdyy03nM5FhvV62goUj37tuxqpfpPeTBZvrJ78w0qAAD+/hVyFHvYXIrMCjny0z7wqsB9/QE08xls/AQdXJFX0adG9lISsm6kV96J5FINBFXzHwfzMCr4N6r3z5/Aa/wfEoVGX3H976she3jyS8RqJv7Jw7bOxoTSPlu4gNbfXYZ9TnbdQ0MNnMObyaRQLIu556jIj03zfJrVgqRM8GPwRoWb1M9AfzFe6Mtg13uEIqrTHmiuBpH+bTVB5EEQ3uby0C//XOAPJOFv4QV8RZDPQd517Khyba8Jlr97j2kIBJD9K3mbOHSHiQDasj6Y3forATbIg4QZHxWnCeqqMkVYfUAivuL0L/68mMnagAAA" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Terence Eden is on Mastodon</p>@edent</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody">Couples of Twitter! How do you handle emails for "joint" things?<br><br>Like utility bills, hotel reservations, and other domestic accounts.<br><br>📊<hr class="social-embed-hr"><label for="poll_1_count">Email comes to only one: (240)</label><br><meter class="social-embed-meter" id="poll_1_count" min="0" max="100" low="33" high="66" value="76.9">240</meter><br><label for="poll_2_count">Joint email address: (46)</label><br><meter class="social-embed-meter" id="poll_2_count" min="0" max="100" low="33" high="66" value="14.7">46</meter><br><label for="poll_3_count">Something more complex: (26)</label><br><meter class="social-embed-meter" id="poll_3_count" min="0" max="100" low="33" high="66" value="8.3">26</meter><br></section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/edent/status/1185954831472775169"><span aria-label="3 likes" class="social-embed-meta">❤️ 3</span><span aria-label="10 replies" class="social-embed-meta">💬 10</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2019-10-20T16:24:00.000Z" itemprop="datePublished">16:24 - Sun 20 October 2019</time></a></footer></blockquote>

<p>Moving house gave us the opportunity to change all our joint billing accounts.  Here's our slightly convoluted setup.</p>

<ol>
<li>We bought a new domain name. As all good projects start.</li>
<li>I set up an auto-forward catch-all address.  So "anything <code>@example.xyz</code>" is immediately forwarded to my email and my wife's email.</li>
<li>We use <a href="https://bitwarden.com/">BitWarden password manager</a> - that lets us share passwords with each other.</li>
<li>One of us signs up to a new service as <code>servicename-2019@example.xyz</code>, generates and securely shares a new password, and we both receive the confirmation email.</li>
</ol>

<h2 id="why-are-we-doing-this"><a href="https://shkspr.mobi/blog/2019/10/how-should-couples-handle-joint-email-addresses/#why-are-we-doing-this">Why are we doing this?</a></h2>

<ul>
<li>One of us could die. It would be extremely annoying to be locked out of an account during a period of bereavement.</li>
<li>We're jointly responsible for most of these things. It seems silly to split accounts arbitrarily.</li>
<li>If my phone breaks while we're on holiday, my wife still has a copy of the hotel reservation.</li>
<li>Neither of us want <em>yet another</em> email account to check.</li>
</ul>

<h2 id="reasons-not-to-do-this"><a href="https://shkspr.mobi/blog/2019/10/how-should-couples-handle-joint-email-addresses/#reasons-not-to-do-this">Reasons not to do this</a></h2>

<ul>
<li>If the domain gets hacked / breaks / is blocked or disabled - we'll have lost access to everything.</li>
<li>We might get divorced. Decoupling things could be harder. Or one of us could lock the other out.</li>
<li>Surprises and presents are still done on our personal accounts.</li>
<li>Hard to send from a joint email without setting it up specifically.</li>
<li>It makes us look like one of those weird old couples who have a joint Facebook account.</li>
</ul>

<h2 id="what-other-people-do-a-k-a-market-research"><a href="https://shkspr.mobi/blog/2019/10/how-should-couples-handle-joint-email-addresses/#what-other-people-do-a-k-a-market-research">What other people do (A.K.A. Market Research)</a></h2>

<blockquote class="social-embed" id="social-embed-1185976316685967361" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/cjforms" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRpQBAABXRUJQVlA4IIgBAADwCACdASowADAAPrVWoEynJSMiJzgMkOAWiUAYMoFstz5ZYwTmqcj5TkAkaj1LEfuRbsA2QIEnFYi+f/5MpVJethj5HQzijT7vafsOa3ADgAD+9NLevJGi/wpmVhndxTqreJwlSWyVK12T5COmEshALSjUhzKONOFUtCsSYDuwf+hejdmxrwYAb+jMNXkYuK9lgqhg2/1pE8k+8uTxZZ061PaB0cUsD4qGwDr0ow7zqjlIuVFe9vKvV4GOmacr2fiC6GkoIrfViTWA260exrRuRVJNGAmyBdlK91FAuYeDB5HdFnN1ZUhJLU9G0J6i1iiqq+EOTZWzshcC14c+pbq53cdZ4AYYNaTZHgcmqdRXjHQ1F/DTRw9ixPYQUMsODK83pa4Pom/afVJwH+4Ff/IxfXhw8FYYfq3nyrFsecOWyzS05vPFqhLImHqsuqfSskBqkhmBKuWa7E3pKrVQ04tDSqLzEEhKI6dWdiSLBoJ9BBcTjEEh22HjVXqTZ3SwEJFq1TULksAAAA==" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Caroline Jarrett</p>@cjforms</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody"><small class="social-embed-reply"><a href="https://twitter.com/edent/status/1185954831472775169">Replying to @edent</a></small><a href="https://twitter.com/edent">@edent</a> I've answered for me, but my parents only have one email address so they go with 'joint email address'.</section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/cjforms/status/1185976316685967361"><span aria-label="0 likes" class="social-embed-meta">❤️ 0</span><span aria-label="1 replies" class="social-embed-meta">💬 1</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2019-10-20T17:49:22.000Z" itemprop="datePublished">17:49 - Sun 20 October 2019</time></a></footer></blockquote>

<blockquote class="social-embed" id="social-embed-1185971319097188353" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/ThisIsCarrie" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRuQBAABXRUJQVlA4INgBAADwCQCdASowADAAPrVWpk2nJKOiI4oA4BaJYgC7Mz3OYT3Fijv4oXFuheVVQMl9OlQWQGDu8rJ3J8vV16rNTK3wmQyqC/7EbQlF/8X3MGlO2XDgwTz55hYAAPlF8hQJ5IulDodZgtNqUkvSNPolCpGwj/ER3Tgr/TJ6DSk3nipl8Q7gYud7xlFKCpdz7vJAHpdPnx6xkCXPktYzAlX1YTfNIjGhep7eHf/yjbk4vGsWFCNc4TByV5Ezf7WnN7z2RZMUP0dP3PPGTvToF6U7A2U1bHovZdKyhbb5AGRUgmfTGh11LM+qS6/IIJFA68igJrtBeSHxVCNMJ8dc53h8WGM95LzgE1OQef3XnRCHG8AFxFMGIVSfYX7v59RVbFomlwuekkb2+anMarX5OUxjUkbPuvctkrWh4jSlCL2KihnkepEiKvUTlOEVDCO0hVAegYIcH/flJjBzwMmutP/zyG2z6o1QVSsJwNN1fcGJ/QIg9d0L+iAECpYc2I6zRmMKHrRlZi1njRkOfIEQIIR15cWdaPg5Zpeq7kKyd1UXGYJdM44fiXnhyHVqd7lzJt8goRLHdje1B8y85nuU/1wMPPa7SlduIW4k71UQ4Hw6OB3mWw6JLbOO03QA" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Carrie Kleiner (Barclay)</p>@ThisIsCarrie</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody"><small class="social-embed-reply"><a href="https://twitter.com/edent/status/1185954831472775169">Replying to @edent</a></small><a href="https://twitter.com/edent">@edent</a> Cc or forwarding. But like many others we don’t always share bills-related emails, we just deal with them and mention it if it’s relevant or important.</section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/ThisIsCarrie/status/1185971319097188353"><span aria-label="1 likes" class="social-embed-meta">❤️ 1</span><span aria-label="0 replies" class="social-embed-meta">💬 0</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2019-10-20T17:29:31.000Z" itemprop="datePublished">17:29 - Sun 20 October 2019</time></a></footer></blockquote>

<blockquote class="social-embed" id="social-embed-1185961236502122496" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/Samathy_Barratt" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRjACAABXRUJQVlA4ICQCAABwCwCdASowADAAPrVOoEsnJCMhrjQLMOAWiUAYIe/gFogOlXyM/fjOriZdGmoumj56BfGGaFu2IrTvnbJqqgmsD0jZFF7qJ7chib/5nFhtdMTHXzRmgvOqfj6HdCgDyYlVeEMAAP7qYEXW0LHL7n1qdYTVMZZs/PfzvQMiz6qLmk+fwseFkLYN3goC7ECq/vmxB2hKxb+32I4wslYzm2oFuLjdjSZ9PZinIb5jH2SZhqHGqwZSSL5u3KvmAbdZIA/GFZlidor/s9ql7GsrCYRqHbOfe6n2d8B6gStshV7s3YzJpOZy8hLNC1WqZI4z9NWKXTcEdpZqA6N3kVigAV4enaO4w2+a9UsU2mnCoL6ghKQIgia05ziumog1d5AgyAnbPs3i9P3/67DJNqDT65w07k/MEJJ6VVHDryhd5lY5+0ZqhfwhzCYlYx0WiunktPgDdliApmKBwJWgQ1emtrUX7XgMNsZn7w72vnl5a7hLYdq6gj/HZGqU/RRg9OKaatYObrUN4Uai0YAL8wNR9VwajjXpz58SadLtIKeHfSnqWvu5Zp6YrO9Db7kgHRbOgk0BMFeMKBNm3YD5vF4YkSMnpikb97+1a62UftP9fmEbmkJoLZl2eQlKnTftN8t+zGnXhVC2AtYGiBzhlqhvRRaAVabTGrScO9UynYog+t0SMvJTbJTZ8bDpxRXeUjtGsRTNwGM9WFeGePc9akJ4GvZiLZAAAA==" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Samathy Barratt</p>@Samathy_Barratt</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody"><small class="social-embed-reply"><a href="https://twitter.com/edent/status/1185954831472775169">Replying to @edent</a></small><a href="https://twitter.com/edent">@edent</a> Comes to one address - if its a thing we both need to care about(Travel plans, mostly), the receiver forwards it to the other person.<br><br>We don't really consider bills emails to need the attention of both of us. We'd tell each other if an email does.</section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/Samathy_Barratt/status/1185961236502122496"><span aria-label="4 likes" class="social-embed-meta">❤️ 4</span><span aria-label="1 replies" class="social-embed-meta">💬 1</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2019-10-20T16:49:27.000Z" itemprop="datePublished">16:49 - Sun 20 October 2019</time></a></footer></blockquote>

<blockquote class="social-embed" id="social-embed-1185958985545011201" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/CarolSaysThings" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRi4CAABXRUJQVlA4ICICAAAQDACdASowADAAPrVQoU0nJKMiI4z44BaJYgCsMvaJUMk+TMX4C41o32W3pmbpRNtn39yqZ5vr6CkqlqqUQ8+zdayXqiJT2RuTw7+ll7wK1VkGUe1DOxM8dzc+j+OCMM5IKnjJXLeuanAA/vKbbnuF4xpRqWx2ZTFTZxkR12d8E7312mNyPWbqY4+7bdIBGM+n0eYpDC+8PHu0ikcjxEEt8g5pzn+sXXaKFhyh60Qa6GNHpancW5pkP+2Ri9P51hiVfeBVOxTmW734wp5/m9JvNFfJ52jLQ+2Uvxe+ndKVe/BdJg3efdNrgFMvfDjqG5kS+KYwsi+772BHkmFFEu1NjZbGAP1h7B/RG9jP3n3xjkIXrOXCOOEMGQ0De+GkIwx8rsKgUYpOSby3PGxqHV2rlAZ1xoiE9XB3LSI/+WZFMlDTnEKIRraHeGTRk4MXE0AX4YIopq3NgNEJGxur5LmvS8QE/pUxRiuvUGRF3AJlGjJ9q4OK6c5NLbp5wiEHgKJfV4ibLLqC1Y2NVs2TFuAj3ioEl1+QU/LLRyDemujGXCgncVs1bbF9iPKYMqrXJ0xMzV4jZ3YmOe2A8sDTmdiBIyfcv/fsr9zwMKR2bdsxdZI4uvMyy1vM91KLvThuhCaOF/Q6Fk1kuYhZjlSFf82GzeVMtgQKSTIii97NHvv5swFY5vfXidqHgxoFgn6ET1TsUqJr6EaRqJboK8buVmIAAAA=" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Carol ⭐️</p>@CarolSaysThings</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody"><small class="social-embed-reply"><a href="https://twitter.com/edent/status/1185954831472775169">Replying to @edent</a></small><a href="https://twitter.com/edent">@edent</a> Poorly is the unhelpful answer. Most bills/utilities go to my email, but for trips we split the admin. So Thom books the hotel, I do train etc.<br><br>Can’t think of how to make it better other than a joint email, as when we’ve given people both addresses, they still always email me.</section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/CarolSaysThings/status/1185958985545011201"><span aria-label="2 likes" class="social-embed-meta">❤️ 2</span><span aria-label="1 replies" class="social-embed-meta">💬 1</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2019-10-20T16:40:30.000Z" itemprop="datePublished">16:40 - Sun 20 October 2019</time></a></footer></blockquote>

<h2 id="how-do-you-handle-this"><a href="https://shkspr.mobi/blog/2019/10/how-should-couples-handle-joint-email-addresses/#how-do-you-handle-this">How do <em>you</em> handle this?</a></h2>

<p>Leave a comment in the box. One comment per couple, please :-)</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=33039&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2019/10/how-should-couples-handle-joint-email-addresses/feed/</wfw:commentRss>
			<slash:comments>9</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[How to rescue blocked files from Gmail]]></title>
		<link>https://shkspr.mobi/blog/2019/09/how-to-rescue-blocked-files-from-gmail/</link>
					<comments>https://shkspr.mobi/blog/2019/09/how-to-rescue-blocked-files-from-gmail/#respond</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Sat, 28 Sep 2019 13:35:40 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hack]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=32732</guid>

					<description><![CDATA[Six years ago, I developed Android apps (APKs) which I emailed to myself. When I try to download them from Gmail today, I get this rather annoying error.  Anti-virus warning – 1 attachment contains a virus or blocked file. Downloading this attachment is disabled.  Google, in its efforts to protect me from myself, have retroactively blocked certain filetypes from being downloaded.  If you try to f…]]></description>
										<content:encoded><![CDATA[<p>Six years ago, I developed Android apps (APKs) which I emailed to myself. When I try to download them from Gmail today, I get this rather annoying error.</p>

<blockquote><p>Anti-virus warning – 1 attachment contains a virus or blocked file. Downloading this attachment is disabled.</p></blockquote>

<p>Google, in its efforts to protect me from myself, have retroactively <a href="https://support.google.com/mail/answer/6590?hl=en-GB">blocked certain filetypes</a> from being downloaded.</p>

<p>If you try to forward the mail somewhere else, you get this error.</p>

<blockquote><p>For security reasons, Gmail does not allow you to use this type of file as it violates Google policy for executables and archives.</p></blockquote>

<p>Here's how to circumvent their block.</p>

<ol>
<li>Open up the message.</li>
<li>Click on the <code>⋮</code> on the top right of the message</li>
<li>Select "Show Original" <img src="https://shkspr.mobi/blog/wp-content/uploads/2019/09/Show-original-fs8.png" alt="Show Original option in Gmail" width="307" height="417" class="aligncenter size-full wp-image-32733"></li>
<li>Select "Download original" <img src="https://shkspr.mobi/blog/wp-content/uploads/2019/09/Screenshot_2019-09-28-Original-message-fs8.png" alt="Gmail download screen." width="540" height="287" class="aligncenter size-full wp-image-32734"></li>
<li>This will download a file called <code>message.eml</code> (Or whatever the subject of your email was).</li>
<li>Install the <a href="https://linux.die.net/man/1/munpack"><code>munpack</code></a> tool using <code>sudo apt install mpack</code> (Or whatever arcane commands your OS uses).</li>
<li>Run <code>munpack message.eml</code></li>
<li><em>Ta-Da!</em> you will now see a message like 
<code>AttachmentName.apk (application/vnd.android.package-archive)</code>
the blocked file is now downloaded.</li>
</ol>

<p>I suppose it makes sense for your mail admin to block potentially harmful files. It's just annoying when I file I wrote myself, which I emailed myself, can't be retrieved by myself.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=32732&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2019/09/how-to-rescue-blocked-files-from-gmail/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Is LogMeIn leaking email addresses?]]></title>
		<link>https://shkspr.mobi/blog/2019/08/is-logmein-leaking-email-addresses/</link>
					<comments>https://shkspr.mobi/blog/2019/08/is-logmein-leaking-email-addresses/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Thu, 01 Aug 2019 11:12:12 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=32577</guid>

					<description><![CDATA[Like all security minded people, I use a unique email address for every service I sign up to.  This week, I noticed I had started receiving spam to an email address associated with my Join.me account.  Join.me is a screen sharing service now owned by LogMeIn.  I signed up for a trial of Join.me back in 2012(!) and as far as I&#039;m aware, never used it again.  Checking my records, this piece of spam…]]></description>
										<content:encoded><![CDATA[<p>Like all security minded people, I use a unique email address for every service I sign up to.  This week, I noticed I had started receiving spam to an email address associated with my <a href="https://join.me/">Join.me</a> account.  Join.me is a screen sharing service now owned by <a href="https://www.logmeininc.com/">LogMeIn</a>.</p>

<p>I signed up for a trial of Join.me back in 2012(!) and as far as I'm aware, never used it again.  Checking my records, this piece of spam is the first email I've received to that address in 7 years.  The email address in question does not appear in the <a href="https://haveibeenpwned.com/">Have I Been Pwned breach database</a>.</p>

<p>I <a href="https://twitter.com/edent/status/1156232905498210306">sent a snarky tweet</a> and was impressed when LogMeIn contacted me directly (my public contact details are on Twitter).</p>

<p>After giving them the details, they replied:</p>

<blockquote><p>We have completed our analysis and confirmed there is nothing suspicious in our environment.
Additionally, we have a proactive Digital Risk Protection in place to monitor our domains.</p></blockquote>

<p>Well, that's a good start. But it still doesn't explain where it came from.  They also said:</p>

<blockquote><p>We have identified that your email ID was part of several third party breaches (mostly related to marketing vendors).
Link to the finding - <a href="https://dehashed.com/search?query=em.nioj.2102@shkspr.mobi">https://dehashed.com/search?query=em.nioj.2102@shkspr.mobi</a></p></blockquote>

<p>I wasn't aware of the "Dehashed" service. It's sort of like HaveIBeenPwned but less accurate.  If you type in a <em>completely</em> new email address - it will report a false positive if any email on your domain has ever been compromised.  Try it yourself.</p>

<p>I reported that back to LogMeIn and am yet to get a response.</p>

<p>As far as I can tell, there are four possibilities.</p>

<ol>
<li>A spammer guessed my unique email address.</li>
<li>Join.me gave my email address to someone when I shared my screen with them. That user has leaked my address.</li>
<li>Join.me has been breached.</li>
<li>Join.me has sold my email address.</li>
</ol>

<p>I think it is unlikely that a spammer would be bothered to guess email addresses, and even less likely they'd guess which service I had an account with.</p>

<p>I don't remember actively using Join.Me, nor what their privacy policy was half-a-decade ago. It is possible they shared email addresses back then. But that would be an odd design decision.</p>

<p>So I'm left with the conclusion that - somehow - my email address has leaked directly from Join.Me.</p>

<p>LogMeIn <a href="https://krebsonsecurity.com/2012/12/logmein-docusign-investigate-breach-claims/">suffered a breach in 2012</a> - but didn't <a href="https://web.archive.org/web/20191218072102/https://blog.logmeininc.com/logmein-announces-deal-acquire-jive-communications/">acquire Join.me until 2018</a>.</p>

<p>All very curious. If you have received spam to a Join.me unique email address, <a href="https://www.logmein.com/support/contact-us">please let them know</a>.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=32577&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2019/08/is-logmein-leaking-email-addresses/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[102KB ought to be enough for any email]]></title>
		<link>https://shkspr.mobi/blog/2019/05/102kb-ought-to-be-enough-for-any-email/</link>
					<comments>https://shkspr.mobi/blog/2019/05/102kb-ought-to-be-enough-for-any-email/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Wed, 29 May 2019 11:19:00 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[bug]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[google]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=32211</guid>

					<description><![CDATA[Another day, another Gmail bug which won&#039;t get fixed.  The original Android phone - HTC Dream - had 192MB of RAM.  The latest Android phones tend to have 6GB.  A 32 times increase in a decade.  Laptops have also leapt forwards in speed and memory. Sadly, no one on the Gmail team has noticed.  It&#039;s 2019, and Gmail app users are still seeing the dreaded &#34;[Message Clipped]  View entire message&#34;…]]></description>
										<content:encoded><![CDATA[<p>Another day, another Gmail bug which won't get fixed.</p>

<p>The original Android phone - HTC Dream - had 192MB of RAM.  The latest Android phones tend to have 6GB.  A 32 times increase in a decade.  Laptops have also leapt forwards in speed and memory. Sadly, no one on the Gmail team has noticed.</p>

<p>It's 2019, and Gmail app users are still seeing the dreaded "[Message Clipped]  View entire message" error.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2019/05/Screenshot_20190528-204203__01.jpg" alt="The text of Romeo and Juliet - truncated. A &quot;View entire message&quot; link appears on screen." width="1080" height="649" class="aligncenter size-full wp-image-32222">

<p>It's just as bad on the web version of Gmail - even on Desktop Chrome.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2019/05/Screenshot_2019-05-28-Five-things-on-Friday-on-Sunday-298-terence-eden-shkspr-mobi-Shkspr-mobi-Mail.png" alt="A truncated message." width="454" height="233" class="aligncenter size-full wp-image-32215"></p>

<p>Google don't even do fancy AI magic to truncate these messages. You'd think they'd truncate at the end of a word. Or even in the middle of a word.  They don't.</p>

<p><img src="https://shkspr.mobi/blog/wp-content/uploads/2019/05/truncated-html.jpg" alt="Raw HTML in the middle of an email." width="1080" height="621" class="aligncenter size-full wp-image-32219">
Nope, just slam straight through that HTML. YOLO!</p>

<p>What causes this? For unknown reasons, Gmail truncates messages at 102KB. That's about half the storage space of a floppy disk.</p>

<p>I'm talking <span style="font-size:2em">🖬</span>, not <span style="font-size:1em">💾</span>!</p>

<p>This is annoying for people sending newsletters - even the mighty <a href="https://mailchimp.com/help/gmail-is-clipping-my-email/">MailChimp can do no more than offer some tips</a> to shrink your latest newsletter.</p>

<p>Worse still, marketing emails know that if they pad out their messages, they can <strong>hide the unsubscribe link!</strong></p>

<p><img src="https://shkspr.mobi/blog/wp-content/uploads/2019/05/Truncated-spam.jpg" alt="A message cut off just before the unsubscribe link." width="1080" height="805" class="aligncenter size-full wp-image-32218">
Oh, and as a bonus, if you click on "View entire message" - you get <a href="https://www.google.com/a/cpanel/gmail.com/images/logo.gif">the old version of Gmail and Google's logo</a>.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2019/05/logo.gif" alt="The old version of the Gmail logo." width="143" height="59" class="aligncenter size-full wp-image-32217">

<p>Google updated their logo in 2015. You'd think in the last <em>four years</em>, someone on the Gmail team would have received a long email and then filed a bug report. But no.</p>

<p>We can argue about whether emails should be chonkie-bois or not. But they are. People want full styling, images, and fancy features - not just ASCII text and the occasional <code>uuencode</code>d attachment. That's the world we're in now.</p>

<p>What can be done? There's literally no point me taking this up with Google. <a href="https://groups.google.com/forum/#!topic/gmail-users/OZkFhOYn5wU">People have been complaining about this</a> for <a href="https://groups.google.com/forum/#!searchin/gmail-users/message$20clipping|sort:date/gmail-users/KIKwhliQ-sU/c1E0ziF81dEJ">over a decade</a> and nothing has been done to fix it.</p>

<p>"User-focussed" my shiny metal arse.</p>

<p>So, here's a whinging blog post which - if I'm very lucky - <a href="https://shkspr.mobi/blog/2015/11/the-day-google-deleted-me/">won't make Google lock me out of my account again</a>.</p>

<p>Bill Gates probably didn't say <a href="https://quoteinvestigator.com/2011/09/08/640k-enough/">640KB ought to be enough for anyone</a> - but someone in the bowels of Google sure as hell believes 102KB ought to be enough for any email.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=32211&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2019/05/102kb-ought-to-be-enough-for-any-email/feed/</wfw:commentRss>
			<slash:comments>12</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[€100 Bug Bounty from Intigriti - please stop tracking your confirmation emails!]]></title>
		<link>https://shkspr.mobi/blog/2019/01/e100-bug-bounty-from-intigriti-please-stop-tracking-your-confirmation-emails/</link>
					<comments>https://shkspr.mobi/blog/2019/01/e100-bug-bounty-from-intigriti-please-stop-tracking-your-confirmation-emails/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Sat, 05 Jan 2019 12:06:26 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[Bug Bounty]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[hack]]></category>
		<category><![CDATA[Responsible Disclosure]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=30965</guid>

					<description><![CDATA[There&#039;s a new bug bounty provider in town! The Belgian company Intigriti.  This is a quick write-up of how I found a trivial bug in their own system.  The EU has announced that it is providing funding for bug bounties on critical open source projects.  They&#039;ve split the programme between HackerOne and Intigriti.  I signed up to Intigriti, and instantly received a confirmation email.    Can you…]]></description>
										<content:encoded><![CDATA[<p>There's a new bug bounty provider in town! The <a href="https://www.intigriti.com">Belgian company Intigriti</a>.  This is a quick write-up of how I found a trivial bug in their own system.</p>

<p>The <a href="https://juliareda.eu/2018/12/eu-fossa-bug-bounties/">EU has announced that it is providing funding for bug bounties on critical open source projects</a>.  They've split the programme between <a href="https://hackerone.com/edent">HackerOne</a> and <a href="https://app.intigriti.com/profile/edent">Intigriti</a>.</p>

<p>I signed up to Intigriti, and instantly received a confirmation email. 
<img src="https://shkspr.mobi/blog/wp-content/uploads/2018/12/Confirmation-Email.png" alt="Confirmation Email with a big button in the middle." width="540" height="391" class="aligncenter size-full wp-image-30966"></p>

<p>Can you guess where you go if you click the big "Activate Account" button?
<img src="https://shkspr.mobi/blog/wp-content/uploads/2018/12/Weird-confrimation-address.png" alt="Weird confrimation address." width="540" height="464" class="aligncenter size-full wp-image-30967"></p>

<p>I think that's the first time I've ever seen a <code>.lu</code> domain in the wild. Hardly surprising as there's <a href="http://research.domaintools.com/statistics/tld-counts/">fewer than 90,000 of them</a>.</p>

<p>This <em>looks</em> like a phishing URl.  It doesn't use http<strong>s</strong>, it's a random string of gibberish characters, and an obscure domain.</p>

<p>It is happens, the site is legitimate. <a href="http://wtf.omg.bbq.mjt.lu/">MailJet</a> - an email marketing firm - use it as a redirector.  I assume that Intigriti use them as a mailing service, and want to track every single click you make on their emails.</p>

<p>Why are their statistics more important than your privacy and security?</p>

<h2 id="why-is-this-bad"><a href="https://shkspr.mobi/blog/2019/01/e100-bug-bounty-from-intigriti-please-stop-tracking-your-confirmation-emails/#why-is-this-bad">Why is this bad?</a></h2>

<p>Links to http sites are not secure. That means your visit to that URl can be seen by your ISP and anyone else between you and your destination.</p>

<p>A user clicking on that insecure URl risks having their request intercepted. While an attacker can't log in using the data they've captured, they would be able to redirect the user and phish their details.</p>

<h2 id="why-use-a-3rd-party"><a href="https://shkspr.mobi/blog/2019/01/e100-bug-bounty-from-intigriti-please-stop-tracking-your-confirmation-emails/#why-use-a-3rd-party">Why use a 3rd party?</a></h2>

<p>Basically, if Mailjet gets hacked, or goes rogue, they can start phishing all of Intigriti's customers.</p>

<p>Thankfully, Intigriti had the good sense to not use this tracking on their password reset emails.  Indeed, I must commend them on their general security, and their swift responsiveness to this minor security issue.</p>

<p>This isn't the hack of the century - this is low-hanging fruit. I've reported identical issues to <a href="https://shkspr.mobi/blog/2018/11/responsible-disclosure-cloudflare-more-interested-in-tracking-than-security/">CloudFlare</a>, <a href="https://shkspr.mobi/blog/2018/04/udacity-bug-bounty-or-stop-tracking-every-link-in-your-emails/">Udacity</a>, and several others.</p>

<p><strong>PLEASE STOP TRACKING EVERY LINK IN YOUR EMAILS!</strong></p>

<p>Or, if you really have to - make sure your tracking server supports https, is controlled by you, and doesn't have a daft domain name.</p>

<h2 id="timeline"><a href="https://shkspr.mobi/blog/2019/01/e100-bug-bounty-from-intigriti-please-stop-tracking-your-confirmation-emails/#timeline">Timeline</a></h2>

<ul>
<li>2018-12-31 - responsibly disclosed.</li>
<li>A few hours later - confirmed fixed and bounty offered. Filled in my IBAN details.</li>
<li>2019-01-02 - £90 deposited in my account.</li>
<li>2019-01-04 - permission given to publish.</li>
</ul>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=30965&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2019/01/e100-bug-bounty-from-intigriti-please-stop-tracking-your-confirmation-emails/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[MailChimp leaks your email address]]></title>
		<link>https://shkspr.mobi/blog/2018/01/mailchimp-leaks-your-email-address/</link>
					<comments>https://shkspr.mobi/blog/2018/01/mailchimp-leaks-your-email-address/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Thu, 18 Jan 2018 11:59:48 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[HTML]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=28968</guid>

					<description><![CDATA[An annoying privacy violation from leading email newsletter company MailChimp. Responsibly disclosed on 2017-12-04.  When you click a link on a webpage or an email, your browser opens up that link and sends the newly visited webpage a Referer Header. (The misspelling is a historical artefact.)  This says &#34;Hello new site, I was referred here by this previous website.&#34;  This has some privacy…]]></description>
										<content:encoded><![CDATA[<p>An annoying privacy violation from leading email newsletter company <a href="https://mailchimp.com/">MailChimp</a>. Responsibly disclosed on 2017-12-04.</p>

<p>When you click a link on a webpage or an email, your browser opens up that link and sends the newly visited webpage a <a href="http://annaken.github.io/a-brief-history-of-the-referer-header">Referer Header</a>. (The misspelling is a historical artefact.)</p>

<p>This says "Hello new site, I was referred here by this previous website."  This has some privacy implications - the administrator of a web site can see which website you were on.  Usually this is fairly benign, but it can leak sensitive information, as I shall demonstrate.</p>

<p>On my website's referral logs, I noticed these links:</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2017/12/MailChimp-Referral-Logs.png" alt="MailChimp Referral Logs" width="610" height="244" class="aligncenter size-full wp-image-28969">

<p>They are caused by users receiving an email from a MailChip mailing list.  You'll notice each link is unique.  If you visit the links, you can see the newsletter that was sent out.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2017/12/HackerNews-Newsletter.png" alt="HackerNews Newsletter" width="702" height="401" class="aligncenter size-full wp-image-28970">

<p>That's not much of a privacy issue, unless the title was particularly salacious, but the next part is a problem.</p>

<p>The link goes to the web version of a <em>specific user's</em> copy of the email.  Which means, at the bottom, there are links to change their email address.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2017/12/End-of-newsletter-containing-links.png" alt="End of newsletter containing links" width="621" height="277" class="aligncenter size-full wp-image-28971">

<p>What happens if you visit the update email address link?</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2018/01/Change-email-address-page-with-obscured-email-address.png" alt="Change email address page with obscured email address" width="618" height="571" class="aligncenter size-full wp-image-28976">

<p>Foiled! Unless it is a <em>very</em> specific email, you won't be able to recover any information. <code>D*****.T****@w*********.gov</code> might be revealing, for example.</p>

<p>But it's when you visit the unsubscribe link at the bottom of the update email page that things go wrong:
<img src="https://shkspr.mobi/blog/wp-content/uploads/2017/12/Unsubscribe-link-showing-full-email-address.png" alt="Unsubscribe link showing full email address" width="626" height="317" class="aligncenter size-full wp-image-28973"></p>

<p>The user's full email address is visible.</p>

<p>(I've spoken with Dan and he graciously agreed to let me share a screenshot of his email. You should check out his website <a href="http://newlocalmedia.com/"></a><a href="http://newlocalmedia.com/">http://newlocalmedia.com/</a>)</p>

<p>So, there you have it. If you visit a link from a MailChimp newsletter, you risk having your email address and your reading habits broadcast to a site owner.</p>

<h2 id="a-fix"><a href="https://shkspr.mobi/blog/2018/01/mailchimp-leaks-your-email-address/#a-fix">A Fix</a></h2>

<p>MailChimp can easily fix this.  It's possible for a website to tell a browser not to send referrer information.  There are two main ways to do this.</p>

<p>Each <a href="https://www.w3.org/TR/html5/links.html#link-type-noreferrer">link can be explicitly set not to provide a referrer</a>: 
<code>&lt;a href="https://example.com/" rel="noreferrer"&gt;</code></p>

<p>Alternatively, <a href="https://www.w3.org/TR/referrer-policy/#referrer-policy-delivery-meta">the whole page can be set not to leak referral data</a>: 
<code>&lt;meta name="referrer" content="none"&gt;</code></p>

<h2 id="response-timeline"><a href="https://shkspr.mobi/blog/2018/01/mailchimp-leaks-your-email-address/#response-timeline">Response timeline</a></h2>

<ul>
<li>Monday 4th December - I emailed whitehat (at) mailchimp.com as <a href="https://twitter.com/marcprecipice/status/937657149592866816">recommended by a MailChimp engineer</a>. I informed them that I'd publish a month after notification.</li>
<li>Tuesday 5th December - Confirmation from MailChimp that they would correct this flaw.</li>
<li>Tuesday 3rd January - Asked for progress, due to the holidays they asked me to delay publication.</li>
<li>Thursday 18th January - Published this post.</li>
</ul>

<blockquote class="social-embed" id="social-embed-954001872897171457" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><blockquote class="social-embed" id="social-embed-953960182433935360" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/edent" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRkgBAABXRUJQVlA4IDwBAACQCACdASowADAAPrVQn0ynJCKiJyto4BaJaQAIIsx4Au9dhDqVA1i1RoRTO7nbdyy03nM5FhvV62goUj37tuxqpfpPeTBZvrJ78w0qAAD+/hVyFHvYXIrMCjny0z7wqsB9/QE08xls/AQdXJFX0adG9lISsm6kV96J5FINBFXzHwfzMCr4N6r3z5/Aa/wfEoVGX3H976she3jyS8RqJv7Jw7bOxoTSPlu4gNbfXYZ9TnbdQ0MNnMObyaRQLIu556jIj03zfJrVgqRM8GPwRoWb1M9AfzFe6Mtg13uEIqrTHmiuBpH+bTVB5EEQ3uby0C//XOAPJOFv4QV8RZDPQd517Khyba8Jlr97j2kIBJD9K3mbOHSHiQDasj6Y3forATbIg4QZHxWnCeqqMkVYfUAivuL0L/68mMnagAAA" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Terence Eden is on Mastodon</p>@edent</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody">MailChimp leaks your email address <a href="https://shkspr.mobi/blog/2018/01/mailchimp-leaks-your-email-address/">shkspr.mobi/blog/2018/01/m…</a> <a href="https://twitter.com/edent/status/953960182433935360/photo/1">pic.x.com/3bhb3bfpol</a><div class="social-embed-media-grid"><a href="https://pbs.twimg.com/media/DT0lusdVQAAut6o.jpg" class="social-embed-media-link"><img class="social-embed-media" alt="" src="data:image/webp;base64,UklGRmIrAABXRUJQVlA4IFYrAAAQ4wCdASpqAjsCPrVap0+nJSQjITKZSOAWiWlu4XaB1PnymRndvK8dcMWPIY8edNv/t6O6Ab3/6/+RO+X/6b2o/4D+6/tT+e/tT+O/Lf3r8tfVA/ivDj59/F/7j0J/kn2t/If378evmr+vf7fwZ+D/91/ffYF/Kv6P/of7v5D/8t/e+5M1X/G/7r/LewL7N/Sv+b913ovf1noN+Wf3f/k/4z4AP5B/TP9p/d/yS+QP9l4N/33/VewF/Sv75/5/877sv87/8P8//uvTL9Nf+3/Y/AT/QP7n6b///9z37of//3Yv2+////hEUkuivw+uFYCg3W3hWNLXcKxpa7hWJ6dHTR2dagvqwva5dyHFnfn2uXchxaWc0xiPSYTIpGFvP2QQhp1k4xWllO4pVmHwfzxbW+1y7kOLO/Ptcu5Diz0aJiMvVV6xoh7Yg+Z67c2F7XLuQ4s78+1y7kOLSzhDiPQ9BWeeSmONRGhf8Va6njgf0tE6hoovbPDTPak9acn4+0t49WUcjuCCiTzH0nunbuU8BjEEE/nwkgN4DJ8utKZfrygNLGFtzWQ2RCIKbqQio0/PkBxvdk+nDfeMnfIeEn/XT6UD7ZsDuClS/gWzRXKtR/1CYKzwGz1putOXtSfImsu6NVrXeDyk0gfixREDXc6NqUY+k0KLiZEhb3D3ZfyE63SmjTMpgtiC/b/kXd/S0dNG+i/i6TVP6zJTbe9OtR0nsFNcFAuDkavqjyECpZw+V1G1NbpPqKfdL+maDUvbsXjYi/7jzTQ5SMEc1XcbAYTEYLMqFTDXqF3480GIDFj+zUWgNbKntMI7NBIQ9VrBwrT4dGYpREWIMAimNaoCQwWsE2M59/JiTacrMVrUJHcwgQUBmxPSZbmsGNWHP53jNpfnWoL6sL2uZjcoddSpA9c8Ob1y8C9rl3IcWd+ga9bfa5dyHFnfn2uXchxZ359rsxaFA/ZNDTvKiv6wnrU1aB/kk0BZTGozNOYdB1DlRaOzjGgi+FaDlsvtcu5Dizvz7XLuQ4s9GsV2pvewJLXcKxpa7hWNLXcKxpa7hUIboeQu02IJH9ijONwDOKI1S8+ofGCnut4+tZ3BwD6DDlt/9Kk6mYpLNL1CZowKgzBHRCGqC+rC9rl3IcWd9vzdYFtYCAz2qmLHL+de++saWu4VjS13CsaWu4ViDf+qM8fpBoToy5heOEHMKpJXyn31sFPsA3R5euQDgHLC3mmcRpuX8699YAF+vMnmmH4788BzrDS5QycJJv4MWWv1D424H+jlv/5/UeRuYS9ATq9AQstmwBY9UO+KDkRKzT3x+Ci80gGgxWuDqmnHw61BfVhe1y7kOLPRou/wwqU9My10puX/+rgKDdbeFY0tdwrGlczAdXIGTsu0F9WF7XLuQ4s78+1y7kOVzfIXEB4PGEsDdbeFY0tdwrGlruFY0tdwrGlrR0ygyIhoyuK2qcXgtRghd60mVT4aDDt/iZST36hgXGWbtegx0x+tQX1YXtcu5Dizvz79JzhTIdNCcRxok3rgVcHkycF4U1lA+0wJ5iwrsEAn6zg+lAAAieCsn3drLuQ4s78+1y7kOLPAoCgZjvuCrJc7rp9Y0tdwrGlruFY0tdwrGhwYmwWnVetvtcu5Dizvz7XLuQ4s79AxF5P2elwFButvCsaWu4VjS13CsaWu4VjQfmPDQaV7nhYpzSDNTWAJqcCyT6Rp2uaXjG7GSaep2orIHrUZrDxkZ0T1Kx2UOX9G9BE9pQS212JeJ1pJ62jvMNbqq2Ykwd40F5DV5Ho26q5mrAwrZaPhkQcbL861BfVqR+WJ000O/94JYg0h8RdGZZ/6VbEJySd3szPKj9006GlB6EqbTFX12EB8vENUsUdBWbZm8NfRY0fXIGQ9GTklsMWleK2z5M3O9NchxZ359rmY1npuiVjLB02T8M65PwGS5dyHFnfn37CT/1M888cBcUGPb3DR3I+3I1/46C2lLM+iJDI0rnWjqkL3kNkADZrZ2Y5Ey4YnP7CECfCtlt9rl3IcWd+fa5d1J0Ddx6vDTYvVCsLclnfn2uXchxZ359rmY2rl3IcWd+fa5dyHFnfn2uXclbh9y7kOLO/Ptcu5Dizvz7XLuo+gxKmE7WHRx9ggPybGQKLLmaW41+BpF4EmH0vcu5Dizvz7XMxDrXtAsZPKRSZcnPIfuHH04uT36WJXlV9IIIUVQOMhVFdjXsFd/CRq5ojLA8dYMuCqMNtkAmMxLWbimTsiebWpBBwSuYFEnOF4FaX51qC+rC9rsyEGdN5YjsXvI0g6DxbWAF0gNa99mQFh+RykouvIjm+H1YXtcu5DizwJ35V62PCbvi0GYVPNZRj6NHLuQ4s78+1y7kOLPAoWqC+rC9rl3IcWd+fa5dyHFgs5NElKGhmN1t4VjS13CsaWu4VjS13CsaWu4MuIX/gAAP7/bQZhnCQgc+eO9HHoCC/QgPYAMV7gfOeLiowu3HGsN6PeZqfFlEHof/OvG+8qX9ohyei7W71Ma/wUjda3SbOAJzrHcIT8QzlpjfFXP/jfE6HWksloi8hrnbz/rLw0ZWs19Db49k5Dcd0JTNaggV69nCeEaq172L6dvswQt8YlnnfA1b8U3j/p6UurOHJ1qupPHx7XwmIJ8d2kbXYtmXrsU3TjER2CObLvqXG565SnlO/eC1QknNAgjECIecctUmJU6N1m753lNycxolfA+GxmD2DaoLbY7N4OI3oY7x3HiC4PrxLOhCOlNwvjLKlA8T0AJ95QuuTpBK/QCaAJ8WJik3KljfPmaSTWhnJF7L7p0d7IYT9zHLcQucpLuyaYmapOr+u6T/IVFB7O3oMzrixImOXkZ8SQLmQprKKHOp5PIi810CfNwAgiNYL8SvuTSfMsT6eFRFf6Bing0yWKv3gfIdIttrm2LMaNYyz0Qd4HVBpLf/z6MQm1dLSuZ9MSQUArwmDlbgJRAH30A5aYKewAFcre3G9Pcgi4lQ/A4ysTDNTkBUFXi58v7vjuQeG7Gj+sSz74JsfhImoUo86NCEEIwyIvF/YCR3VzXw1YMy8dJLevE5KppyPOu3RTSjHbU4D9F1XVwJlAk9+Gy0Pf+7gnITARx7IpY+OiRoHGnj7SgIUE80XHtgLMjWyT4VLaGbaD7okbuBvFW8jba007B0sLzO1GrfuyRsIzl3lT9SmoU+Crt/GFzQ8iLOFaZ3KL7zNwAj8X9Xs909s6CWKOAanNEAbcQIeAd6rR28DS0ZnO75wL03Z1hS2Qg2R0HVvmkOXfCE6z345rQG7g77Ls4w76yLyJKGMmmtDt/9NZVR+iu4V8d0/WieFLORAC15j6n2PLaGUhzqqeZygq8T3CFT+oZGj5U9JB2LyokZpIcsdf0BN5kv3zFV8mImck70XvoXcDbGhz3prVOZC4tOihnqF/2VYF3H0tTwCATyaquNVltwMbd+u2C/chkAacy613E/hMn+zXZ83qWQvXykLWUE9WEGu0vX6rD+DaUh7XiXPcYT2tMjHv2C6cdlBROGqrMNqia3RUo0gNVWnhDYzpnFkPv9f+SDxjwUD768CJ8rGsHAbdCypGRs3fbHDqUhnjFHV52218merJgf/ITIHr1ZpfAEO3bSUyZ0jTOWNcABbaxKv+ELNcnl6q+cjqvQ1xtD/C4YIsywPWzGmuzYrKKwYxyUZkWbIKeL8I7JhTymd38GtcsfBYXngjPl/9QwTWWgt02ytX4qy0Lnrh3Pw4y3rUTq3sop7qkYwFijrHFE291x5N/kSpbf7peN1impMbDetS/GhgEdGNrqt1lFPko+jSqsBbqrPYt4r4Y70/6d/N2mJQNoRaB+Sq+MRcpAxGK6RdCP3HHAIVVxE52jySgZM7w9m8q4zBiWYqW/IA2FeoMjfFr7Rs/Z3NFZstxLiHdE3Hn1Dio18WE7yGIojmlMyTAgbeupMOkeKHDBV7DQ0F5nFInMLBx2Bz7dlnqIsTZZow8mJLxqjGmwAuskSA4U9mmFlmK/9kLMn3/MjpLay3V9lzivZ+zTB1MKYu75UwrqZQhTjS+T9DlIhaodWxZDSJ0zJDEztBDFvgip3nbl9kwGpZW/m14CnSwW1BXWSYAzsj/4FIA5lKKMbl3xfX3qbAg6sX7+xtNa5SMk28WkRwF3ki69MrdYdFE1gWP6p2RfLnnxvssfb1WpWbOzKq99P9vFDNd24OrND9GVk2lgR6QwRIjUQKf6M3m2skOppLjbb7TVKq17cckzPdljMXFBhq8q71Fx9IRV5/rUzqcUv6ADS+fNeloeCbl0H47AX05wLwehff+TZbsXJ+1eUtn8V8MI2g/EFHuVLCsyaxmFTwtoRJgTcdu7XhOdEyA5fHfbOfK3q48BHbsiqapJ5evSdRnhY0UVNAjk8mTebuPT30GqgM/Iw0++Po5QoJ2gG4AFn614SucP+S6OXZf80+EYHwuUh1YkM0H0UwTK9889LEXyGwrBH2Ct+B9Ii8JzkeL/yvR5KKfi7PyVfeMJ/LxtYIn+sp+l9PudzqqGfyo0sg2mwkGOtSn188TZysar36q0N3w5hqc3Ld9fIgViDDZTWfo3OKk//oYbJrVrFLZ+h5my8XabOBM8niZi/yQ9i7+0+KjGip2KeRrvpqyTxZpdkTez+Ogp5HdWaO4TNY7QjY3frmFfsmWZgdTu+Yk/an9MLGeU9r44Z1egPW5tG0CaPFfURqoz0wYx8z4nfDTE+hwl38GIMTLk4owtgciUti+nB1+9+Wgi3bqS6G1xYXJnLyUFXGeonBmeU751IwQPKElWFJjRmCdJzLpg3P4AL3EpC/DnDvnU5LvneA/98vZsFbjnyQ1MqSedoLT97bQamhJCEkqVH8TvKr8MxzyVvv2tgh+odfEYi9I4NG5OSX2HVwAZKK99pB1ls2Gyg0GvVgowf3dtzIz/5ILx1+tbx5gCbYO1J1aV7YR5IGtqjDABCFurU+cF38czj5o64+ZteSXts4kUq/ynhBqozhDuEeJtHfvEZFRa9elIv3ZLuDVb0EzuAwj4mbVX1fGabdA+CpqumkDXIr9h5hZqvViyox/yuSheD4BJ+aRibPpuvpd4eYxqs/nn8HOC7sRuC6eDGWyt6uhPalLNlphCQMWjL3P4nT4BnDoClMn4RgpnBAtcN3qM6ggbAQK7RcCKtjxZVNEb6wF5FHsP+UhV4onh9Nu/UyE18BiPZqJHKniTGjStQtimJ3BcBzbY5BhYCXu4/TWrfFwGVYa7eBGkkLailltqg1f4PW7oUMv4vCblH4nuoV6zuCvytjvUBunDULYaHyladxEmwPYdM2bjqnt60clE0yQowR9/z4cSxvLTaw7gbny+f/Y0hpIN5KwwC7YwVsVjG+vgf59UsvcKmihktQe72qBYqBoovg24zFxIEtffaBP00QQ5X24HnCuKvSUgRdWhOY6AqEHhOYgTPA2LPs/pQDXtOwECpEhZWtDUIdXoXZ2dvef7uTBfUk22iwo15+Aj35CcZINKQc71BChv2ZrVd188yaRXDKaEo392dPcvpLVPXm2wEI0I7AyT7wu3sWhVqIn8aED8B/i0da6yLvpy9AUokaQQlIWb5wHvxYrlnKGZNJwLG6B0Yx6LJkvf6v7gIxTwsdtPHxS9RRW4H7d22ji4gL08PyTiSlpyhvjSusTn/kJfdw8w111K0YOfA0xiQt+pIb1lto6MT/thkhgiLhW6DZp2ph1rZXJHCgbd5/1qwbbLJBRTVe5p93o195sgtiK4UFXWe0NMWFadzXAc/cLLua2ChDL/wAZKLXoLLDJu9kO6Hoio7wlEB+3rD0P2hI8eU9TxhD2r+3gB2BlpR7f/+1PimEz1a+yQ3KixhChBkcFbE+MqEhWM5F4KqXg8vijP8rFiO0RqFJv5JK4aisf4PRU9crlTYAmbzQKf3m5cTSlpoUgTzgitMI12VA/jemdeFGbEwEl9npVCkfy3fOoT1Fgd8WIutDeYE7ejPjMRtaeYoQVtsGToN1hf+u4gVpfS9DP2ghP/ozSQY9vgTet6NX1ujTKxQfV+pvRHchGsVUvFBpL8pZp7HdhOfopRbdx2I/1yWbcCdxzCA34mf82Q2pg1/u7IhcNLF5y4AsQTBgoglOAa8D96yZBpjAOgDDvmd6DGVB8TfPKpAjEo73rdXGzhI4TWAAETNIl6UAvAPVCbDNC+dAkX4DTzmeqENu29+Z5ixXPNzMOIAUwdkidO5NQboVaPSaQLlI9blsZocIrcdmDehUMuYNCa+46hZYzgiic73a6e+HzScbgZstlGoseGOglRMVgWBggjWeEWg8g+98c7Gg+JL9q4JlWdGrj4sQ8zHoSYBnhviWGyzTQ3d/+yhPBitdK3IBElrRgInwcBxHlhbgTSLduc08A8ThgR+3aGaDAXZzuZ/7EKUhH3297MoWpdwDyXDjKcbGPoxxmtKi4QM4HIQN1UCT6uo3joVYSofcZCJV3gceQbrTiabH19v4X6VgSt+y84a8024WqNud6CFONQRHtYTU+IInkQAlFtzTLix1p7K34VXAxj9RyvFwHfSWV913dPSLAIGWqpcUwCTDD8ffBzUGpP2U/r9W4op8tLyL5QvZ06sHFFlsI52WSnL8YL9SZ56QGlq+r0XPdImKHK9Con3vcK7tGBNCC9fmQpOLIlSMK8CE2GD/dCUGKlrLhLvlusaUC1JykQKPJ3kLCdAVaP/j8oJSz4l6jWBpETWWFKC7unktfl8+X/5OoUSDeNiaGU3lCXFC72t5FaNzY6NnKn2mbAWZuM+SZuGhJdl7bi6bivk7x0+JjGk2zMwhGpeM4Cig8721eIyThZyWe+d92c3NqN64j2spf57aUhF/2LYC2Ls5uXSjz0ZpcoiUEbtF3/RdGmrWMnQqttZHbiTds5QEDddxzzR3uYl74OhBCk+sfSDqXGT2ZXVUZS+2b2jMwgjH6KpuExaCMUUvgktL6Hjs0e2ykOxYg3ITd4sCts5yzWBPt/J8G+7MUFtT0RBE3dwygjaSP1nO8YKntdyRsnRwZ0ZEucla1/OmaSqlMfyLInrBtf9vuZf/BM3A6gjG9qiJW+IenfJHjyLCNZi3jl4k0mSqNYXXWB6gD7BZgP2d8UOpi2FUbzsXLwMOAUdSik1zC4h3QRHs7N1ctD+XqC8Or4hBkvWPeGutELwjTSBJRQrjT1TMYufv0grLrFPMKIV6WLBUNbJjfP0fCwrkdzug4w7ClM0nYO56BZ3cFfr2mvs8JySvprmu66Xro3iC6kvHMOTRQ2oGAlE9vNeGnb0u887yMglB4RjdH/dSkqOHiz2aHyyWcf8MF7WPME48buS1UX92A+3q4N3hSjkttoON0sEhO9HkxLFPcly4dS+7Q/L/P4UGXWZwC3OteG491aLbiEz+SNzK9+6/5M8fi8ks/6/8bJWjgQ89IgCrYIiAAJzZ7gtY1bD2D/mrtnCdo6UAqb8F2jjSX7sxw72L0r8AGLQWZGcJhgcaTIP783H9JBlJ56Z7PHuHzEDcGpADgR06QmWsA8bMmJvMm1ABq3EKMHRqwLqsPWYxAcq1hy3dQJ7aSS/O7PaMj03lTPeyiAtJzpSf1WniSZvWekhhGfNJcVtFrRyggv3xvqrk63Us5dZjWzrI/FLlpsdngC6eVbWKDIUI5CTomUToFwxoR7ATyViVUFOL4LUdkBSCIrY5YTLg9SlFj2swdFBbwPbjTv8RaMYldTXdKQ1hUHNvQhN7fo+y6WTy30/BS6QVg2mfcgn/hec9UDAH/rx5IET8dwKuryI8iMamzxGlNCdjJrybufyv1ZLjGJNk5eMVnG2yQLyq7iWXeJeojtwoyCPl/9LjqGKngOFQpq6RKAcz4GqwZZlRd2/IlUvAHKSLynXZpd1zwDudMWCjahlhnSQxnOzwVZQG4WSJrLtoYhOsANjcVoMyYIUPosJ1nDZLHKNQQFPKnc1/vy0v0oZlysxWm2tdQmYBkHPrxGclqODyvgBNuTBCfZaABl5G/BMzpxuDocx7R6YEhYngATwpLsCCA+VBqmZNh+Ga0I32a6+jD9rXIHWZh+CB+uO6Ead2wyeuZ2dPPMpwiInkpojP2g1c4O/f4OZk6mwna7peQoptrXlWLDlCsPQ0zCgDy1tF/QpfqA0LhMKJ9S3t3wy/MeH61K7UPufs4bSbAa22W5B75T2djSuYPRv8C3rrPdk9pfhvqYirjfu8colc5O4g0evN2pZY1xpxG2BQ9A1X43iCHd1kisziNI0/JYVPzLImWPZwL7Hatwh5x8hH1yYzLc5ini+G4R5+gz2Do0GUSDYaqwUcKUiMSc2Ek9u4Y1ZtUH++/7qe8gARL3PMwX+yszma+H5C6nQFkMHYP0qb98cDXUupr64lO3fcmMQ2JX53HZtn8xJz6YG0vrkrPSbwpFR8/ENXHpthvPlFHVWatqyb4VocNc/PiQxF3V4uEECSTp1M3wZMW3yuifU2L4++6oC43b/p1Y/WEXfUlfTd50RmwZX5JCEAMyoCjspeaT/GMJUoOj4sxwr4ajwbNfoLdAocR76OFAhp4ex8plMYUS2SUVfkrj41ZBUnl+dvjq8ZzZpXWrrsbtCXKxO9QLrVyJTI4VWdYwxQxJm2OYffuFbR2VNTVRDQm3eYS3og4nbzXAPFKHBSJHrFkWIJOXxoUz5Xj2l9aKcYCYDm0+UYxs4f1KJ3WMpQ8gNwc2HboUx/Pb80PdMovQEFJ1FTc4E3eyF18bOxa2L2Nqta+fhXgaoVy4vYkXMuzhAvCDuK7eHqsowkIVc+KXX5hfvvS3x5z3/97B3TwShBVdNZC+ToxY1J+QYQz40khVRyfxPlYFScCRqVBgH52NAkHm7FEqySgAAAAgC2fLNkA/RmBZyIps5fzMxZJcoVl2N+5MVF6GVwXLETm3xTim5lslqWVvVNmYCZNsz4Nd4p7TxDSFbDhDAq/dYrWO7NxZ+u1KYYfrFgr0bg0CLJO+71mweHRm1V3h48xeCAAggWBKsStPT8apzQmb95gPSsh8DfUzX20cyUDnmJ57F8wFlAdy1lxiHnIer7fR5Od6QTcvQ0dDtkKDOJSJYbOx3yylUuyRSKN3nheqtalXw7kouSrz2pf9zear5YGPrtom4MFeY3C7RybLYteurTdpw9emTLzraBX1BYSRvnWFTX1vu2JgLVK7GsIS361MUOjU8Zj0h4/MHpDYMySklrd9B8hU0Zu3NSZv1bAAAY63+OV5LJpDielCpvGVRedEinYKEwY4cYHQcG94ThpAm4BgHluekooZouc9hlAbSCnY7qml3dmRavzEvQbtKkmHexGoQeH9/XS8M96ERT7q7V0aBFBpxNyA9X/tByP2uUBXmBMMwvN21f9RkSiUiWG0FJL86xNIdyK2na7zHbdfkSoWnp0YAQ2bePfmT5WzSpLwtYwPdJorUW9DEbEzOTx9yBrdy9/KXydb6INIfDwfxOo4NM28AHo4SuwJ0yxwwyZwy/2NPekFCJZWPKWEAvnSk9wF94hFDTfvB8kR0SNOhubrd7B5Nt57jRV8GaWS8e0qTH+8lAt3wBVY+dts8zKNh2oOumXoRjO1NGNm4sVCdmDIyeUeqLQvf7x4tp5D83beRPgE3hz+An5Cnu8H0v6ZukizB6g9YhTXWFZh4aSX2jrnltrLoGvbo8jUQda1M3oNDHEsNOw/RRrmmO4lar0gQypbQ+Ko0JyJ0Z4TO4xTDXGP6uOqn4izbLEXL7Yq/obitM2VHGhkDI5VYY6jvGzSR6ULMXlFxw4Av1AqKttBpyug+2a2awqmyxhA26aqokpPrd82TkD1STNuskV0U4aD1qBfXeh4tI1i92VXK/Lk2XW6eQsp6EjPMe0UT+CPwTV2KA1xbTL0bzJgaTN0eKla92WHIAxyjycEvF4c+unuIG2u/wv4ABfKc84a3cR2iBhsEG69CAAVMs2GvwBxZMoAB4tX1SpVyVEtlamRWNT6oAYRUwffg9ZcSRePTUJO1wbwiJ8NUIh6AAbE9xPTcwvXM52FZ940wabQ9TOAs79twHfgi44Dpylt5Tkgbjynjli7y2K59A1Sw/1JauFmbI8A6RUGlgGMvUSDWRBzMWmxs2QE++vJhGJTVmKsHb80LNrc4EydBWVkiHjyY4PBdz8qevQHyezwHprIXyUBGbcn0IUhY4tSBLGajQNiGwkDj3bpdRaqHhtKc5T1N1rtSn1+Uno8OujnYGlSl1Um6s+doQ0J2KL2Bb55eFg+zqznEUjROCy/XBktuMFJw5lPM6Gf4ZmQjFJsZ8fZ40hFMoSfDjgJ0INK3o1suNLNOpzOcslN8J9IsE9mp28ZXmbE82q50JzyJWvxSjEgPU2IWXIM/22obGyPW56peA3e7/q0BfIUOQOAyPUxUWG6BV23IC5g0FRPGn1wg+mvnH1mEgKk+QYr7NIyr/5FLDnWW5p3KCOab9uXBdIlsxzLwjz4HGA/56JyjHitmDaDw5SdXuENwjqsW2OTsgxngDAhrMvEKpZN+nT79Rh13F6Lnp91+ai+3sN95IR4oMEctHtgSY+mMrx25gCAiBPM5cGQrDda5LOAUVhSXKni+vzyUZ6sfaEt4J+1Y8tZmp8oFKhFT5tZwIKnoy8CHHjqhBWMQBWuzFYwVF/09HhkvDL4J3lhTAi8xJ9EHvHT9FD7u397bt9q38oH6dZqzskwAj6Ief4g9HRNZyipY0alxSvky6SoEIORhB3i160qKScT21bTthlRiEgQHRvEdy5k8et4xpdJAYTSiqt6nvzaFFOjMYPpTGcaCTUZP4QuZvWWIe4l/YlBKrYQ4FLcdtn3udM+NwuWG8HyYJ1M7YTV6YEu1XNRpAsC140ZDBhTbybBKw3wnq6A6XZW8lRGG6+nSehY2Bb2B3iNn4AHFum/5qNF8s2KNQGx2D0nDHG6HXt6OF7SFg0ABrgR8/CXBBPtH2d3VIlEHYtbF7G1WtjR8Pnrr6rhErtNtgPzNaysVe2DnZ5o0jWK9B8t6woRFYOLKqzkrNNNMPyOeW5dNi9eC851JOwLO74Ho/PalrZCVALMLnwENmEajk6hP71X1k7KXcpds7Jzf4xFC62vSZyQn52+aU02KwOVmABWP9aD3nyBFvUErCyts2ZwyF6Mc5Scin8jYksI2RhmiHKjBGhq+3QaUc/RqxtCdeaLfADkMspGvf20+RmEVB49veNN97jyVKtjDG9P2ogEjLqkgyUHwNiD+N2c8s1yXtY9L9QBp5o8cz9V/If4CE+lQRl2J4wDwkiB1zGNcYr1uvWKcmUEgUWB5De+EzXGyVYNPp8+Fg3sCUjgsNTTiKzWYyyTsea6gTy2S70vmyEvY/4qt/LOJNXD+ub9pGlc5YJa1+pEVY8tbrEacd9zos7mHGBeOgbdOG3Z9BbQDX8u7OKmNroRW1GHxdABhATF49z1vKvwTq1SBVUX611AIe8/k/Xg4DncStLVmNWj3pFAHc8fC6JteOqBagjeGMwgjpXe9AmJ5TcZ711jFN5MD9xIDDWJooF4M1eUZU6xeHMVx8/UHvxU96TcMJZlD9ELyxPgLdQUzuhkG2Kl26JAhJZLqd5UzsXURpXHmXs1mGMtqrP315xw0qKMsN76f7CqkhAHzn5tLme6XaCXCNGXoJ/JgZKxrFkkDkxATLmu9evQo5pA3q3PLQ1zwqsJr+XKBa5YQ7Dp1sOupvK5Bdo40h8opOAUPpia01GD1qiqf1jzJzqFoQPCGx+mUTulPP5sOf9ya7kWa2lWbXPN5eQf1XBrB1waRroO93omYowA8iJNw9jmwRXDBQvARUJREhLTnge8yJI1CzKLfA4kNpwMgYBx7G0yD3/1RcFpFPTAN+Yho48VdtbHPb9YPxP4PbozSR/JKJKfSJgmanQE4YsUuMdr5aYqDrYENAAOR6Df/r472nG7uhgQuG/F8oBYfPKoDMcL4UqWqAfLw0ppQRMW8mkWC0+0NOQ3JZUOlZV+UKMzyAc5a5qYDbB8Qzgv01BIp4yq8/bLe53gvOidKYlROrzF51Re2geGVGGXh/B2Qjt1if0HnYocRw8flsMVoCnizDuiJDDJpN1tYt8N1OuQzXyHqAuZ0CukSrXU9jtgzrzwAAwt/RuJ33yDO83QUtjMjktNDnHtCGAiKSIUczRI6BHPisjEf8/D0RxYireC7T84Rn4/hk3tKGKffIUf5JgefUmxV+yrwbqx30U+6NYRzN10ZKdCwAxcw1lzuoAajBIQAaEIywhSxxDQlfybXMGGFcf2Pqqf8i7KY1vIuVudg9x2hhfvjXJBPU4GmncmzgAeUa9HqQcvQM3Q3R8xzLn7eqAIqWDG7JjTA9Zs2BlUnEJ/KrBs8EoC6ADFJ6oEkxBhS9lX0+Yly4Jd9TRlUOcU59rnZBsTfTYUtfGjLCcMVX2FfKW38zqyU+nzsCnnALcrVKDwaSTZho/vXqtkuIxYmlYMiff+G8oudZ0zaH3V1y7aRXdjQLOZ0gukKG1kjrU60baVMCUczYH6/rTjGVYlGkdz2mtLtkg3clgt6Y8l+KFTbgln1GLH45sGQm6ZQDTB9KnwcWmGKtMVjgmTWzgbuFJ/P/iDF5vN0auCdUUD4dmOx1LBsiAe9x/WPXkYOhjyzMIOc/9oV6Fmea7xc/f5mzON1S1KEjlKE/un8hDVphJJqJCPwDuaFc/1T1Hi3AL44VxbnOwJvFymeTvgAAAAePJDuAwEOFpiKFhnPEQyG4lHGfTun6f3IfInwghamH2wydeMI8SOvlJ1oe+Sk/qVY/7DVhV3154aPiXc7IIlEVcLVkHyTma3N+lGvmzq4Kxdo6yUbIDmjxFee7+urYmMNMhd44AH+5xypjZZXF1wRTAnPJBPAkB0nzNUrXEGxPiXk4mKn7tecErSalG2hxI/JiUuxymJVs++jroRDXdARuBS+7v94jCkCctEEILR/nZodOlKktSqNQVfPE4AuIQtcBcPSoa+IyJonGtbF5j9qtOtNx7zX73VxJ2s/fR+tNyTgGDoEXQmUlwTEBbQdo8ZQ7q9vaTx2efIf8T9muFkTgewDB0J4YgZ35vJfwVv+MBtbjYj0MmvjN6EM5CiH9xmvqUKMUT7s0bet7fWQvGdaAz2pOaXM9wYzIpURL8Ga4WROCMkHGPKTrrLaqY5Q4fRtZhU8QfW/+H2da1yXdzLPpInSP7lCIAVftc3fJ3t39ozgxGZjcO1kk6gq6LHR2847BwHkx38bQmy69/57nlVRl6OVt0xhMLHaGfCPeB/mUqs7c6SLVtyx1Pf6aPer7utNakv8eyfB+GebbCFR0S+JJtjWmNTAVXsIhO+nDB3Sf8pYN9uDRuoeVMj8WCRG1TKo2r/xFY8Z9bD+AoAAAAAAAAC56S+R4Dyl7ATge5oXaXDFyuSFfBTNz7oZO8Uoj86QZTOYnk2oFg/ma7PXvEfdX5I+DlSF/PBo8aEVQF9Jt7aZZj+o8nTVudKXwAJDbgfvMw6nzzDRGkQYuv07y06ZRHMKHfBNCd+mIAU9NIC22ChAhthNM9xogFgnpkCYxO0j8cpqsGIO5oA+ZitJsLjX9/uvYakY/zrcpWcns06KtzgvbUv6fEku9w7vfSBbjuNL8Ogng+Fx1kBDwdK8UC0sVUMeGMj8bww51cll6yiEkE0AycIdalw1L54pBidLiQ+PmQjCEhLVyg2RkHJ2hfDD4iNY6CL/V8T8btPFIJ3KYIgP5jB2gIIK2nlDUA4a1lXK/HxZdbCkVJm8UsOck2XKCXIcMTFMxNCHeoutwGDeG3yIBZkYoCYVd9DMmr2alpJkhRQtB2ZRoewLJ6Mqdt4ng4noRU4oPWDArnTQJyV7cjwKvOQ9hKPirVhyHHe5qKOj6vCgAXrC9nqRel/LuaT8I1RojoNvR4B0QkwpDBKL315JOJ9fTZNcZjQOvZv2x7zg/zR4Rt1ZWoQAATjg96KB53ZobJItciM7/fQyV3MMfrtkws5+nEmgzAers8c01dFhwr3RHpWcAHlxoAIG4JjTsA6G9WgV4SDpGL9YOjHXz36Gix+QvkYLPIyTNEIA1q6Og8tuQaXePI2o5Mqfuk+EHrR90ns/cWgMh/lNbnXYPoFaxVz1SjgnangGQ/zKUZ/yHh12UUQZmQMQrXmsUWcsXZ7VTULGC3i2AoQEp3a1Rn7YGSyoiXfrfJSElQi5mtA+Z+9zT1YtWW79x3nQzcAj262TwLB4am63Us28oeW1T5WbOOa1alUi+NRl6wPx1VE1eKVLctzh7hTiRfj/cTFpY7g23155UbyfvP/Sx3zM+0wAbRGmWTvkUZK+D1y0L5zJsjLiPHNmT33Mw7jTtxpdrCrdx7qJRhENuAI27z6e1C4ZAxv+NqyhzA3ZkbeQ4pl06SVnDzlL0wOPTC/Q1DXo9aL5yBpIFB+ngHXYprnBAllLbq/Sjqy2S2Lwb+ZA394xV6iJpSKGUaH5i4I6SdDa/zTLvl3OJFnbgJNAvw8us4SvftuWs23ssBVzt3UhfaTxSs9mLwUl5tb/0hnrR5zg3I11DMa/YUatvpIVr8Z/3pSh7XXN75BAwFo0uk+Ww75TbvFQQ0sAAs1mAAsSjnoy+f2QiESw2zUtD7Dw/e2IzrR4BiDT5Hmsh2WAqE9CVqAAO1CVggSK+LM+KVVqATErVdeEGTzyzWUwlcLRWdjsLBzvozxglfiALvEJudyanEIYlBNmsfz83vWrmf3oIXSiPUHNrk2CV4gOUNMQ9AbUhXjwDJcCyKlly85mRFgvnTvQ2wpOwwi04IK/+AuuzEnXYJmgJdvp9vQjwVsAAACOAurIAAAA="></a></div></section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/edent/status/953960182433935360"><span aria-label="16 likes" class="social-embed-meta">❤️ 16</span><span aria-label="0 replies" class="social-embed-meta">💬 0</span><span aria-label="23 reposts" class="social-embed-meta">🔁 23</span><time datetime="2018-01-18T12:00:05.000Z" itemprop="datePublished">12:00 - Thu 18 January 2018</time></a></footer></blockquote><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/Mailchimp" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-square" src="data:image/webp;base64,UklGRggDAABXRUJQVlA4IPwCAACwDQCdASowADAAPq1Gm0mmI6KhNVqoAMAViWwAnTK4wJ+V/jN7EVSfxWzEtE3DHnAdRXvLv7hTWMYCtBlgaQKab46M2JYXMs4CCfpSAt8poIF8zkCZSz/nSykK0DwI6nJIDbWcfRoC77rOkXdhg65aKqjCau8AAP78EEkEJjwfTHnI5h+Z96doHWNPkTuT/ACXudjzaerRubbAL1H//8p/JTfKgN/KPKfvIWe+foJmHiP/iAyIsX2+T1is8caGOW/wP9/jlpwk+1TVkahoUFAbmT822SCXYlRuNwcNauJIlx5Mvld3u0j00tBZp0igCTLjbi+b3lbKQGBM0VIv4MvUTLf6IXcbNSRZv2GTyPji0iknlDvIY4AgM3/4hdskLDnJfCgwDrYTub+/ve13VJxblYOByfcNmOdK/8drWU1/6M+Pz/3T4ynafCIrgFwquWLQoRnSC9Pk4ZREUL1UugxK619u1PCO4O9mRsUwvJ/FSLUqTXVxLfOGaKRiri2FyAbmmvBUGzJVL9L9jTGz8ojFwPH4VpR1PceqSLt13S/xsdp0UNFCysSIcXAzkVK154X7D4VZm+osvcd2tf2eTnjmdGJCsMap9h36vgswQngLkhcmAy260CPqluEnD+3boFy0a/93HdhzRMWBSflf4ZdS2qW/mNMH7rIV9KPGMoT/TVWlFvSDFSDK7R57+z23CnFkjopNkiDXIDVFC1wapt//8PbwF4/PfoAtqVUsOR+buPd+XT851ffVny8fCgyxHL5PAVZfKgdk5++8evSInv9mm4OhoCfXTAsa1Sv7nv/Nr1UcRqeAGOOyu0lsD1pn1ecPPoJgXDeFBZm2YewJ91WjHAtnXMVBaS7msgTPq/bd9/VGqMqL+l/KQ4b7FaekKVQsOySEZxse0S87IciKf7/wllWXXZqUbK+dMhiShC2fHUH3oVqlY5ufUbVSlxYkPgl7b6UqC+aPCxQuPm6rheR4L8Najbw95KQAOLYmwUwY4OiDu3V5dNKVTqwAAA==" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Intuit Mailchimp</p>@Mailchimp</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody"><small class="social-embed-reply"><a href="https://twitter.com/edent/status/953960182433935360">Replying to @edent</a></small><a href="https://twitter.com/edent">@edent</a> The issue has been fixed. We’re sorry for the delay, and we’re reviewing how we handle reported issues.</section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/Mailchimp/status/954001872897171457"><span aria-label="4 likes" class="social-embed-meta">❤️ 4</span><span aria-label="1 replies" class="social-embed-meta">💬 1</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2018-01-18T14:45:45.000Z" itemprop="datePublished">14:45 - Thu 18 January 2018</time></a></footer></blockquote>

<hr>

<h3 id="discussion-around-the-web"><a href="https://shkspr.mobi/blog/2018/01/mailchimp-leaks-your-email-address/#discussion-around-the-web">Discussion around the web</a></h3>

<ul>
<li><a href="https://www.infosecurity-magazine.com/news/mailchimp-found-leaking-email/">InfoSecurity Magazine</a></li>
<li><a href="https://www.tripwire.com/state-of-security/latest-security-news/mailchimp-fixes-privacy-issue-leaked-respondents-email-addresses/">TripWire</a></li>
<li><a href="https://www.securitylab.ru/news/490901.php">SecurityLab</a></li>
<li><a href="https://www.security.nl/posting/546599/E-mailmarketingplatform+MailChimp+lekte+e-mailadressen">Security.nl</a></li>
<li><a href="https://www.reddit.com/r/netsec/comments/7racee/mailchimp_leaks_your_email_address/">Reddit's /r/netsec</a></li>
<li><a href="https://www.grahamcluley.com/mailchimp-plugs-privacy-hole/">Graham Cluley</a></li>
</ul>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=28968&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2018/01/mailchimp-leaks-your-email-address/feed/</wfw:commentRss>
			<slash:comments>8</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Would you fall for this phishing scam?]]></title>
		<link>https://shkspr.mobi/blog/2016/12/would-you-fall-for-this-phishing-scam/</link>
					<comments>https://shkspr.mobi/blog/2016/12/would-you-fall-for-this-phishing-scam/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Fri, 09 Dec 2016 11:47:18 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[scam]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[spam]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=24292</guid>

					<description><![CDATA[Gmail is usually pretty good at stopping spam from reaching my inbox.  When it slips up, it reminds me of just how terrifying the modern internet is.  Early one morning, I received this email from someone I know (details redacted by me).    It came from his email, it has his signature at the bottom.  This doesn&#039;t look like someone hijacking his email so far.  I don&#039;t put much stock by &#34;Protected…]]></description>
										<content:encoded><![CDATA[<p>Gmail is usually pretty good at stopping spam from reaching my inbox.  When it slips up, it reminds me of just how terrifying the modern internet is.</p>

<p>Early one morning, I received this email from someone I know (details redacted by me).</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2016/12/Scam-email-with-fake-invoice.png" alt="Scam email with fake invoice" width="450" height="725" class="aligncenter size-full wp-image-24306">

<p>It came from his email, it has his signature at the bottom.  This doesn't look like someone hijacking his email so far.</p>

<p>I don't put much stock by "Protected by Antivirus" claims - because they provide no proof that scanning has taken place.</p>

<p>I <em>know</em> you shouldn't open attachments.  But it's a PDF and Google is showing a plausible looking preview.  It was early in the morning, and I clicked on it.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2016/12/Fake-sign-n-to-Google-website.png" alt="Fake sign in to Google website" width="450" height="725" class="aligncenter size-full wp-image-24295">

<p><em>*sigh*</em> Last night I had factory reset my phone.  I was slowly logging back in to all my services.  So this screen wasn't unexpected for me.  And, to be honest, I've got a bunch of Google accounts and always have to log in and out of them.  OK, let's type in my email.... WAIT! WHAT?</p>

<p>A look at the URL bar shows <code>accounts.googledrive.com.adge.gq</code>.  That's <strong>not</strong> a Google URl.  Had they used something like <code>login.accounts.googledrive.com...</code> it would have been long enough for me not to see the phony <code>adge.gq</code> at the end.  I'd almost certainly have clicked through.</p>

<p>The rest of the page is a <em>pixel perfect</em> recreation of the Google login page.  With the exception of the "email provider" choice.  If I'd have been less awake, I'm fairly sure I'd have fallen for this.</p>

<p>I put in a fake email just to see what would happen.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2016/12/Fake-Google-password-field.png" alt="Fake Google password field" width="450" height="725" class="aligncenter size-full wp-image-24294">

<p>Asking for a password - thankfully, the scammers didn't use <a href="https://gravatar.com/">Gravatar</a> to show the user a picture of themselves.</p>

<p>I put in a fake password - and got this extraordinary attempt to phish my details.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2016/12/Fake-2FA-screen.png" alt="Fake 2FA screen" width="450" height="725" class="aligncenter size-full wp-image-24293">

<p>ARGH! Trying to steal yet more information. That's a realistic error message. I'm used to seeing asterisks blocking out my sensitive details.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2016/12/Asking-for-phone-number.png" alt="Asking for phone number" width="450" height="278" class="aligncenter size-full wp-image-24301">

<p>If you fell for this, you've given up your email and password - no doubt used to send more spam - and opened yourself up to a barrage of scam phone calls claiming to be from your "email provider".  If you reused your password with any other service - like your phone provider - your entire online identity is at risk of compromise.</p>

<p>I know what you're thinking.  I should never have clicked on that link in the first place.  I am <em>usually</em> quite security minded.  In fact, before clicking on it, I long-pressed on the link so that Google could show me its destination.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2016/12/A-secure-Google-URL-is-presented-to-the-user.png" alt="" width="450" height="453" class="aligncenter size-full wp-image-24303">

<p>Even a vigilant user gets no protection here from Gmail.</p>

<p>Today these criminals were unlucky. But they only have to be lucky once. Users will have to be lucky always.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=24292&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2016/12/would-you-fall-for-this-phishing-scam/feed/</wfw:commentRss>
			<slash:comments>5</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Interesting Email Metadata]]></title>
		<link>https://shkspr.mobi/blog/2016/11/interesting-email-metadata/</link>
					<comments>https://shkspr.mobi/blog/2016/11/interesting-email-metadata/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Thu, 24 Nov 2016 08:22:49 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[metadata]]></category>
		<category><![CDATA[NaBloPoMo]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=23558</guid>

					<description><![CDATA[For many years, my email footer said &#34;Sent via my Casio cPhone&#34; - my attempt to poke fun at the users who hadn&#039;t updated their iPhone&#039;s default email signature.  This leads to an interesting question:  Marc Blank-Settle @bbcmarc on Threads@MarcSettleIs there an easy way to see what device an email is sent from? If I type the attached on an email on my PC, can the truth be shown easily?…]]></description>
										<content:encoded><![CDATA[<p>For many years, my email footer said "Sent via my Casio cPhone" - my attempt to poke fun at the users who hadn't updated their iPhone's default email signature.</p>

<p>This leads to an interesting question:</p>

<blockquote class="social-embed" id="social-embed-791289437661622277" lang="en" itemscope="" itemtype="https://schema.org/SocialMediaPosting"><header class="social-embed-header" itemprop="author" itemscope="" itemtype="https://schema.org/Person"><a href="https://twitter.com/MarcSettle" class="social-embed-user" itemprop="url"><img class="social-embed-avatar social-embed-avatar-circle" src="data:image/webp;base64,UklGRvQCAABXRUJQVlA4IOgCAABQDQCdASowADAAPqlKmkmmJKKhNV1YAMAVCWgAnTMADmEyR/twTc3iL5rwIrg9luafLO45e+mwbJBPGCvz2heebj3GwHxLigCM4N5hIzmdkoWX8/ygW1a11IYlJZvtdVPg71YH2YHtaF0I+R9rICDpSBGAAP3MLAMqK0xVEvcXwSrdrr82qfrOZTiF/6rKyVgk2I6a0awjDrLe/0UvDir0AB2Uc7OmKSdbCILtYqMrEz25n4/Irno7+7Vm+9psnKZe2OsbqmLKZbiMyVF24qOlxD1B6oKrUWvvJdZfbg7sm2cQWK3t2mRs/CqD6glS+N6CRGDtRt5hdCV5EG6ZByYpYdbi0fJ28+JtaUKm+l+B/cfkseB7fUTGZHq6bBGHnjKpae7GQG9ptSs3R3D2s1iSvriGMM16MjYGcqo3ap9vTxhr471k1EgSKrd8YiaW6AWKWu1Vcn6deVObhoR+eICJz7lg3J4cVQzahme1wdG8vNJHDhpSMbJel8Xn/1im6sv6NLbuszyeveA7F/0cTS2Ss6csCh/iz+bvL9POL6rdlG+6GlwXyFhOTNVNrpyatEvN4PnXd0yvA3QWYIWILLyBGX67s58dHnGmObNlIDqp0DfpvSQbSmKt0iB/ntkMzgW23p4a+/TcSFJf5JXe8HbmN0vZt3SqaoDfYOwmyUwS1EZ+qekeCWbxxb2HkkzYgf8FkWlMss77EizgV9P9YT67g50r+JPOgAXFm3QTdYO8E/HZI9Nzo47zCKlEbZZIDrkjDQHjl2VyL85owAPqqZTrgYQFgYDn/Jl8TmIQk+B6C04OMrTnxpbUvxtBAyTwSwCKbDpKGR7xan0Tk4h+rUATCL9jmQdQ0ustYhNj2mO+CGBL145TpKVd5z8k89EI/YeyZvt3wg84+0KEAyW+DE01IEf4n1QzSmjk8LYxs7QBVHJm5oAMJMp5yHzzr6KhljCkOyRv9oM0qSFJuwmK4bbNkwUukQcEAAA=" alt="" itemprop="image"><div class="social-embed-user-names"><p class="social-embed-user-names-name" itemprop="name">Marc Blank-Settle @bbcmarc on Threads</p>@MarcSettle</div></a><img class="social-embed-logo" alt="Twitter" src="data:image/svg+xml,%3Csvg%20xmlns%3D%22http%3A%2F%2Fwww.w3.org%2F2000%2Fsvg%22%0Aaria-label%3D%22Twitter%22%20role%3D%22img%22%0AviewBox%3D%220%200%20512%20512%22%3E%3Cpath%0Ad%3D%22m0%200H512V512H0%22%0Afill%3D%22%23fff%22%2F%3E%3Cpath%20fill%3D%22%231d9bf0%22%20d%3D%22m458%20140q-23%2010-45%2012%2025-15%2034-43-24%2014-50%2019a79%2079%200%2000-135%2072q-101-7-163-83a80%2080%200%200024%20106q-17%200-36-10s-3%2062%2064%2079q-19%205-36%201s15%2053%2074%2055q-50%2040-117%2033a224%20224%200%2000346-200q23-16%2040-41%22%2F%3E%3C%2Fsvg%3E"></header><section class="social-embed-text" itemprop="articleBody">Is there an easy way to see what device an email is sent from? If I type the attached on an email on my PC, can the truth be shown easily? <a href="https://twitter.com/MarcSettle/status/791289437661622277/photo/1">pic.x.com/i8impwkxlo</a><div class="social-embed-media-grid"><a href="https://pbs.twimg.com/media/Cvs5Xx2WYAABS7G.jpg" class="social-embed-media-link"><img class="social-embed-media" alt="" src="data:image/webp;base64,UklGRhoHAABXRUJQVlA4IA4HAAAwJQCdASp3ATEAPrVao04nJaMiJlQ5IOAWiWlu/HA4puM5HpP/bR/HvdLbq3Tre4Kr+3o/mfAvxje9M17Fv0k6i/ZPf9/lPAn4P6gToPu7+V9AL1l+sd2LqTd1+fbvPvr/+v9gP+Xf4T/n+yr/Nfs55yvzr/W+wP/M/676aHsN/bz2Tv27HzgCyzIwksToFsn1cUM6MtgFUXTkaGMQzcaysErx1FjZhwW2mDMg8Z1R/S/Y4FfE11U0iiBANd7KC9ZHCkOPWHaevss1+5hJbMW7VY7Xjh3nTUiK55mpve5PIpwMg7UodsCxRgNHw6xYZ2nbYUchLkNDDJLZLZgWpnEZ5wGiybENQPgQGwCKfejRwyjLmLcaxgwDj2Dlx8Sxji9VhAPtS5WyfVxoBhJYnQLZNgAA/vm44JYQC4QAAY7ojW0k90B+fgLavSy7yUMsE4LN2TxJUYu3qlJ0YkJDutcMBtgXBX3Gb3egiJcE4Zo58cqO/zQMN2faXUsYWXFmTtEiq9P/kF1xDbU7vpNhJWjomR/zQF6hTOpxwg3KK98OHR72UQFIN1J80r1fFi/1ddYpoR0Qr5I8+ZAJufd76pOh8SS7MXAk3qbsF2KKH3P82sOleVafSFKTbLoWnTNWQuHWuCzo3xa/iSd0f6e5RkKKQrhzvGpTJZ3c2rUBBacmfKJM8euCd135XnNUMd2yp5oTGUmC4EDU/2lYRz17UmtOXi/F4xHzmmExRn9pOWN0oFBpi7R5iQTAS7W9VydDc8GvnEWryjdoW2S7P0ofXZ808xnn43Qim48m4vbFIEKc2s4Xmf98v4YdKnEcGLEiwpFNxJihTzZEy8MsVdx/yiJq1IvCiMRIxc7tbYuz50JLZkMAG5VE0Hz9REJAb2wV4+jEEHC+6yDr+gWK+SmYywIfsEgoONuwIDITnc95o5P9x3ORvfAvs7en5vDyo2YD4rHYssRwpAxTuXboVhLaZTZO6TJ3P810bzamOowAh0AIbV5a6d4IjxCqamjPdJogydp4qEiFmIQbLkGVkzhjorPaHVDlW+enZC+7ieYCSMfW7g1skgzO7mqvKMGtDmmAmB9HnqD2Qp+B57wf8c3IpVi8F0pmDIGRBqNqG4Miu+HvVC7vjLTVY82Fy8fNvUzQ/fZC/FPr0oRj+B6z0xHzQ67+bFvFGIdV2S8Gwk4bSL2BXfBZcL4O3scsrkiLaPJVneGd6vHBWzE5QUw7f1jt8fZMtLQlgVfyOzBErBj0vkN4LSvaPTTfDv/F/3Pk8xpRjrah3JIGPjw98uHz/1gzLi426pTEipy9YeW+rawb0rkJ6qsGz+4VA2wAHLmDOe0zMT9LPceD4kFKYAt/px/rRK8kq3sDC5tTlJQiix1k4wMY/wmIlLW1l3pEvfvVRfsYltNjgAzQHA2VRgyoc0GwBFR2R0mMP+yuBmqbYNFOxypdoRpsy1MekZEIt7QUBXh2H2/y12IM9odcRGhymusz1Gffh7QUw3VFytc33wD5wafCALMw2M/f/fVNTEyanunbYIKDXWseBGOi1Z3biWPM1HbtOvb/jko6sjw4P4Q+LvMeYwj+tZlmT5U+L92YEzhITMwKDu3MdJ3zmmLM0+KLM+d300xsYDQXsdMnxK0JYgyDpoDUzj7YZWE2dfx6aox9up4SRJEjFEYnanieS2I5n3S90oFGCaaXL+BF1G9HGwvvnKfxt3Hcdap3MA6UWVWMKx7BdQdKtw8zRtUq8NdcaakVfysBuQ9ms+VqSNNiKFdh9vbMoi4c65RIwgSMwaef4kw0ufgGgD4aOTq47iP336aKDFZeA0fYZfAGfUvBe5EEO9lTfSGdug+wULSKLPWY7dmnDlSztbiMbw9JvetQEenkSU547j6LDsrP2T+KLPydoVWoIAlfNti+SQAawM9BCZZl5JJndKZZTE0IHxWXeM6e5GzOj2qkGBNhhZjMtPtigameJuaecMRUHqHwinEOMyny7E3kyvPYIUBU51K5NnHGhofz4P7tsIU7xx6cxLxKhAri+nuP2RwWKMAxpu6whxjBfPjradxP0p3B9o86RwuiCh4yqJUL/OfeSjZPRprPM/tfVPJgRO83snTBf3qoE1kQx5lDum4MbM3oquxIajdH3lTCo476BI/xKwKL5IrLNgSDUX0M5ORTIluhYCSkiZcH8ub64w1ne/GPsWw5JE7mBx5VHAjbVg1/PkAmqup3ORTSP8ReRba5cmxkneDss7wUxqIrhrXZUaj6oTsg0Ptk9w5GKsT8rvTBSJYE2nTrw3WOF+QX4K0k0aM9I7DkNoNgr2G5r5jf2HXtk8X5q4FaXMJKatlrquz3pLin3937yCQP4ZoNc/n+3TWr+r3n7wDFsIsAAQ0FazP/ZAABkY2IN8/KaAPWgAc9gAAAAAA="></a></div></section><hr class="social-embed-hr"><footer class="social-embed-footer"><a href="https://twitter.com/MarcSettle/status/791289437661622277"><span aria-label="1 likes" class="social-embed-meta">❤️ 1</span><span aria-label="3 replies" class="social-embed-meta">💬 3</span><span aria-label="0 reposts" class="social-embed-meta">🔁 0</span><time datetime="2016-10-26T14:44:38.000Z" itemprop="datePublished">14:44 - Wed 26 October 2016</time></a></footer></blockquote>

<p>Because 2016 is <em>maximum news</em>, I'm sure there are some interesting stories based on email releases which have been missed.  Metadata tells stories.</p>

<p>So, what metadata can we pick up from an email?</p>

<p>In GMail, it's quite easy to see all the raw data sent with an email as it travels through the Internet.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2016/10/Show-Original-In-Gmail.png" alt="show original in gmail" width="268" height="305" class="aligncenter size-full wp-image-23559">

<p>Let's take a look at some of the more interesting fields.</p>

<p>Here's an email that I've sent from my mobile - I've redacted some bits for my privacy.</p>

<pre><code>Received: from [192.168.1.42] (oxfd.cable.virginm.net. [82.6.ZZZ.ZZZ])
 by smtp.gmail.com with ESMTPSA id l6sm9069017wmg.11.2016.10.08.09.37.57
 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
 Sat, 08 Oct 2016 09:37:58 -0700 (PDT)
</code></pre>

<p>Well, first off we can see the sender's <em>internal</em>&nbsp;IP address.  That gives us a little insight into their network topology. Of more interest is the sender's <em>external</em> IP address.</p>

<p>This can leak all sorts of interesting information.  Location, service provider, connection speed - even ISP contract details in some cases.</p>

<p>Let's suppose someone sends an email which says "Sorry, at home with the flu today."  You check the IP address and find that they're connected to the WiFi at Disney World.  Isn't that interesting...</p>

<p>A little further down the headers, we find (again, redacted)</p>

<pre><code>Message-ID: &lt;yqwertyuigm4u5v.1471234534@com.syntomo.email&gt;
</code></pre>

<p>Oh ho! What do we have here? <a href="https://en.wikipedia.org/wiki/Message-ID">The Message-ID</a> is a unique string. Most email clients will choose a unique suffix.</p>

<p>This means, if you received this message from me, you could tell which email program I used and (possibly) which device.</p>

<p>So if I send you an email saying "sorry, my phone is broken" - you'll be able to tell if that's a lie.</p>

<p>There's another leak of client information at the <a href="http://stackoverflow.com/questions/3508338/what-is-the-boundary-in-multipart-form-data">multipart boundary</a></p>

<pre><code>Content-Type: multipart/alternative; boundary="--_com.syntomo.email_596674815977850"

----_com.syntomo.email_596674815977850
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: base64

SGVyZSB3ZSBnbyEg
</code></pre>

<h2 id="much-more"><a href="https://shkspr.mobi/blog/2016/11/interesting-email-metadata/#much-more">Much more</a></h2>

<p>This brief blog post only scratches the surface of what can be found - and what you could do with the information.</p>

<p>Other "interesting" metadata includes:</p>

<ul>
    <li>User's Timezone - not as accurate as an IP address, but if their phone says they're at GMT+2 but they claim to be at GMT-7, is that interesting?</li>
    <li>Reply threading - was this email originally a reply?</li>
    <li>What language their equipment is set to. Some email headers contain <code>Accept-Language:</code> and <code>Content-Language:</code> information. Why is your "Urgent email from the FBI" sent from computer that's set to Chinese?</li>
    <li>Software versions - do the sender's servers have known vulnerabilities?</li>
    <li>Operating System - is the sender's equipment up to date?</li>
</ul>

<p>I'm sure there are several other pieces of information which could prove interesting.</p>

<h2 id="manipulation"><a href="https://shkspr.mobi/blog/2016/11/interesting-email-metadata/#manipulation">Manipulation</a></h2>

<p>This is <strong>not</strong> a cast iron investigative tool.  It is possible for programs to mangle the metadata - either deliberately or not. Some people will take care to mask their email footprint, others will not.</p>

<p>Metadata is <em>everywhere</em>.  While your emails are unlikely to get leaked to the press (I hope!) you should consider just how easy it is for a little white lie to be uncovered.</p>

<p>Sent from my iPhone.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=23558&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2016/11/interesting-email-metadata/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Why can't you send email to a Chinese address?]]></title>
		<link>https://shkspr.mobi/blog/2016/09/why-cant-you-send-email-to-a-chinese-address/</link>
					<comments>https://shkspr.mobi/blog/2016/09/why-cant-you-send-email-to-a-chinese-address/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Tue, 20 Sep 2016 11:41:33 +0000</pubDate>
				<category><![CDATA[usability]]></category>
		<category><![CDATA[chinese]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[i18n]]></category>
		<category><![CDATA[unicode]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=23331</guid>

					<description><![CDATA[We all know what an email address looks like and how to validate them, right?  A few years ago I got the Chinese domain name 莎士比亚.org.  You can browse to it, link to it, and send email to it.  Or can you?  When I tried two years ago, none of the major email providers supported sending to non-ASCII email addresses.  Today, I tried again with six of the big &#34;Western&#34; webmail providers.  How did they…]]></description>
										<content:encoded><![CDATA[<p>We all know what an email address looks like and <a href="https://david-gilbertson.medium.com/the-100-correct-way-to-validate-email-addresses-7c4818f24643">how to validate them</a>, right?</p>

<p>A few years ago I got the Chinese domain name <a href="https://莎士比亚.org">莎士比亚.org</a>.  You can browse to it, link to it, and send email to it.  <em>Or can you?</em></p>

<p>When I tried <a href="https://shkspr.mobi/blog/2014/01/poor-idn-support-from-major-webmail-providers/">two years ago</a>, <strong>none</strong> of the major email providers supported sending to non-ASCII email addresses.</p>

<p>Today, I tried again with six of the big "Western" webmail providers.  How did they do?</p>

<h2 id="show-me-the-data"><a href="https://shkspr.mobi/blog/2016/09/why-cant-you-send-email-to-a-chinese-address/#show-me-the-data">Show Me The Data!</a></h2>

<p>I tested by trying to send an email to <code>test@莎士比亚.org</code> and the <a href="https://en.wikipedia.org/wiki/Punycode">Punycode</a> representation <code>test@xn--jlq54w7ypemw.org</code></p>

<table>
<thead>
<tr>
  <th align="right"></th>
  <th align="center">test@莎士比亚.org</th>
  <th align="center">test@xn--jlq54w7ypemw.org</th>
</tr>
</thead>
<tbody>
<tr>
  <td align="right">Gmail</td>
  <td align="center"><span style="color:green">✔</span></td>
  <td align="center"><span style="color:green">✔</span></td>
</tr>
<tr>
  <td align="right">Outlook</td>
  <td align="center"><span style="color:green">✔</span></td>
  <td align="center"><span style="color:green">✔</span></td>
</tr>
<tr>
  <td align="right">Yahoo</td>
  <td align="center"><span style="color:red">❌</span></td>
  <td align="center"><span style="color:red">❌</span></td>
</tr>
<tr>
  <td align="right">iCloud</td>
  <td align="center"><span style="color:red">❌</span></td>
  <td align="center"><span style="color:green">✔</span></td>
</tr>
<tr>
  <td align="right">OWA</td>
  <td align="center"><span style="color:red">❌</span></td>
  <td align="center"><span style="color:green">✔</span></td>
</tr>
<tr>
  <td align="right">FastMail</td>
  <td align="center"><span style="color:green">✔</span> ⭐</td>
  <td align="center"><span style="color:green">✔</span></td>
</tr>
</tbody>
</table>

<h2 id="winners"><a href="https://shkspr.mobi/blog/2016/09/why-cant-you-send-email-to-a-chinese-address/#winners">Winners!</a></h2>

<p>Both Gmail and Outlook failed the last time I tried them - I'm very pleased to say that both of them now support sending to Chinese addresses.</p>

<p>One strange thing to note, when looking through Outlook's message details, I found this example of <a href="https://en.wikipedia.org/wiki/Mojibake">Mojibake</a>.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2016/09/Outlook-Encoding-Issues-.png" alt="Outlook showing encoding errors, mangling up the email address" width="528" height="163" class="aligncenter size-full wp-image-23344"></p>

<h2 id="losers"><a href="https://shkspr.mobi/blog/2016/09/why-cant-you-send-email-to-a-chinese-address/#losers">Losers!</a></h2>

<h3 id="yahoo"><a href="https://shkspr.mobi/blog/2016/09/why-cant-you-send-email-to-a-chinese-address/#yahoo">Yahoo</a></h3>

<p>The biggest loser is Yahoo.  Very strange considering <a href="https://en.wikipedia.org/wiki/Jerry_Yang">Jerry Yang</a>, their founder, is Taiwanese-American.  Even stranger given <a href="https://en.wikipedia.org/wiki/Criticism_of_Yahoo!#Work_in_the_People.27s_Republic_of_China">Yahoo's continued dealings with China</a>.</p>

<p>The Yahoo webmail portal simply wouldn't let me send to a Chinese domain name.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2016/09/Yahoo-email-not-recognised-.png" alt="Yahoo unable to send a message to a Chinese email address" width="640" height="349" class="aligncenter size-full wp-image-23340">

<p>The Punycode representation appeared to send but immediately failed.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2016/09/Yahoo-unable-to-send-message-.png" alt="Yahoo unable to send a message to a Chinese email address" width="638" height="169" class="aligncenter size-full wp-image-23339">

<h3 id="icloud"><a href="https://shkspr.mobi/blog/2016/09/why-cant-you-send-email-to-a-chinese-address/#icloud">iCloud</a></h3>

<p>Apple's much-vaunted "It Just Works" philosophy obviously doesn't extend to International email addresses.  It accepted the Punycode but gave this <em>delightful</em> error message on the Chinese domain.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2016/09/iCloud-Delivery-Failure-Notification-.png" alt="iCloud showing a delivery failure notification" width="607" height="458" class="aligncenter size-full wp-image-23342">

<h3 id="owa"><a href="https://shkspr.mobi/blog/2016/09/why-cant-you-send-email-to-a-chinese-address/#owa">OWA</a></h3>

<p>Microsoft's Outlook Web Access got <em>very</em> confused and tried to look up the email address in the local directory.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2016/09/OWA-No-Match-Found-.png" alt="Outlook Web Access showing no match found" width="543" height="170" class="aligncenter size-full wp-image-23343">

<h2 id="errr"><a href="https://shkspr.mobi/blog/2016/09/why-cant-you-send-email-to-a-chinese-address/#errr">Errr?</a></h2>

<h3 id="%e2%ad%90-fastmail"><a href="https://shkspr.mobi/blog/2016/09/why-cant-you-send-email-to-a-chinese-address/#%e2%ad%90-fastmail">⭐ FastMail</a></h3>

<p>Lots of people recommended that I try <a href="https://www.fastmail.com/">Fastmail</a> - it <em>really</em> didn't like the look of the Chinese domain and painted it with a red error colour.  That said, it sent the email without further complaint.</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2016/09/Fastmail-showing-red-error-on-email-.png" alt="Fastmail apparently showing that the email address is invalid" width="545" height="436" class="aligncenter size-full wp-image-23345">

<h2 id="what-about-a-chinese-local-part"><a href="https://shkspr.mobi/blog/2016/09/why-cant-you-send-email-to-a-chinese-address/#what-about-a-chinese-local-part">What about a Chinese Local-Part?</a></h2>

<p>Email is a venerable protocol. That's a polite way of saying it is old and outdated.  The <a href="https://en.wikipedia.org/wiki/Email_address#Local-part">local-part</a> of the email address (<code>test@</code>) is generally restricted to a handful of <a href="https://www.jochentopf.com/email/chars.html">7 Bit ASCII characters</a>.  None of the email providers I tried would let me sign up with a Chinese name. So no 你好@yahoo.com for me!</p>

<p>But what happens if you're foolish enough to try to send an email to <code>你好@莎士比亚.org</code>?</p>

<p>Well you'll probably get this error message:</p>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2016/09/SMTPUTF8-Delivery-Failure-Notification.png" alt="Technical details of permanent failure: local-part of envelope RCPT address contains utf8 but remote server did not offer SMTPUTF8" width="659" height="160" class="aligncenter size-full wp-image-23348">

<p>In 2012, <a href="https://tools.ietf.org/html/rfc6531">RFC 6531 defined how International Email Addresses should work</a>.  Over four years later and <a href="https://en.wikipedia.org/wiki/Extended_SMTP#SMTPUTF8">support is <em>still</em> not widespread</a>.</p>

<p>It's 2016 and the majority of the world <strong>can't send an email to their preferred name</strong>.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=23331&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2016/09/why-cant-you-send-email-to-a-chinese-address/feed/</wfw:commentRss>
			<slash:comments>4</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Don't Use Bit.ly To Advertise Your PGP Key]]></title>
		<link>https://shkspr.mobi/blog/2015/03/dont-use-bit-ly-to-advertise-your-pgp-key/</link>
					<comments>https://shkspr.mobi/blog/2015/03/dont-use-bit-ly-to-advertise-your-pgp-key/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Wed, 25 Mar 2015 11:45:14 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[guardian]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[pgp]]></category>
		<category><![CDATA[security]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=20761</guid>

					<description><![CDATA[I had dinner with the outgoing editor of The Guardian the other night. Clever chap, sure he&#039;ll go far in life.  The Guardian is very hot on security.  Many of their writers have PGP keys which they publicly advertise.  In theory, that&#039;s great (complaints about PGP notwithstanding) - but the reality shows just how tricky it is to act in a security conscious manner.  Have a look at Alan&#039;s Twitter…]]></description>
										<content:encoded><![CDATA[<p>I had dinner with the outgoing editor of The Guardian the other night. Clever chap, sure he'll go far in life.</p>

<p>The Guardian is very hot on security.  Many of their writers have PGP keys which they publicly advertise.  In theory, that's great (<a href="https://moxie.org/2015/02/24/gpg-and-me.html">complaints about PGP notwithstanding</a>) - but the reality shows just how tricky it is to act in a security conscious manner.</p>

<p>Have a look at Alan's Twitter profile.</p>

<p><a href="https://twitter.com/arusbridger"><img src="https://shkspr.mobi/blog/wp-content/uploads/2015/03/arusbridger-Twitter-Profile-fs8.png" alt="arusbridger Twitter Profile-fs8" width="360" height="585" class="aligncenter size-full wp-image-20762"></a></p>

<p>In the bio, we see a link -  <a href="http://bit.ly/1g4S9WR">http://bit.ly/1g4S9WR</a> which points to <a href="http://static.guim.co.uk/ni/1393869928289/Public-Key.asc">http://static.guim.co.uk/ni/1393869928289/Public-Key.asc</a>.</p>

<p>Let's take a look at a few reasons why this is sub-optimal.</p>

<h2 id="control"><a href="https://shkspr.mobi/blog/2015/03/dont-use-bit-ly-to-advertise-your-pgp-key/#control">Control</a></h2>

<p>Who controls bit.ly?  Not Alan.  Not the Guardian.  How easy would it be for a rogue employee to subtly redirect that URL elsewhere?</p>

<p>Gone are the days of <a href="http://www.pcmag.com/article2/0,2817,2370354,00.asp">Libya exercising its control on the .ly space</a> (you <em>did</em> know that's what .ly stood for, right?)  But that doesn't mean you should trust a third party with directing people to sensitive information!</p>

<p>Bit.ly isn't accessible over HTTPS.  A sufficiently determined attacker can see who is accessing the page - and possibly redirect the URL to a different site.</p>

<h2 id="information-leakage"><a href="https://shkspr.mobi/blog/2015/03/dont-use-bit-ly-to-advertise-your-pgp-key/#information-leakage">Information Leakage</a></h2>

<p>Most bit.ly links allow you to append a "+" to the URL to see a page of statistics.  I've <a href="https://shkspr.mobi/blog/2011/12/bit-ly-considered-unsafe-for-qr-codes/" title="Bit.ly Considered Unsafe (for QR Codes)">written</a> about this <a href="https://shkspr.mobi/blog/2013/04/inferring-facebooks-mobile-use-via-bit-ly/">several</a> <a href="https://shkspr.mobi/blog/2011/01/metros-use-of-qr-codes/">times</a>.</p>

<p>Off we go to <a href="http://bit.ly/1g4S9WR+">http://bit.ly/1g4S9WR+</a>
<a href="http://bit.ly/1g4S9WR+"><img src="https://shkspr.mobi/blog/wp-content/uploads/2015/03/arusbridger-bitly-stats-fs8.png" alt="arusbridger bitly stats-fs8" width="1024" height="1402" class="aligncenter size-full wp-image-20763"></a></p>

<p>We can see when a cluster of people have visited the URL and what country they're in.  Is this leaking the identity of a journalistic source? Not directly - but it could help narrow down the target.</p>

<h2 id="homographic-disambiguation"><a href="https://shkspr.mobi/blog/2015/03/dont-use-bit-ly-to-advertise-your-pgp-key/#homographic-disambiguation">Homographic Disambiguation</a></h2>

<p>Bit.ly allows you to create your own custom URLs.  <a href="https://shkspr.mobi/blog/2011/04/dear-nokia/" title="Dear Nokia...">Useful for pulling pranks</a> - and <em>extremely</em> useful for redirecting people.</p>

<p>So, if someone hacked the Twitter account and replaced <a href="http://bit.ly/1g4S9WR">http://bit.ly/1g4S9WR</a> with <a href="http://bit.ly/Ig4S9WR">http://bit.ly/Ig4S9WR</a> - how long would it be before someone noticed?  The latter example uses an upper-case i rather than the numeral 1 - and points to <em>my</em> PGP key.</p>

<h2 id="final-destination"><a href="https://shkspr.mobi/blog/2015/03/dont-use-bit-ly-to-advertise-your-pgp-key/#final-destination">Final Destination</a></h2>

<p>But, let's assume that no-one has monkeyed with the shortlink.  We end up at <code><a href="http://static.guim.co.uk/ni/1393869928289/Public-Key.asc">http://static.guim.co.uk/ni/1393869928289/Public-Key.asc</a></code>.</p>

<p>What is "guim.co.uk"?  I <em>guess</em> it's a server used by the GUardian to serve IMages - but it doesn't quite carry the same trust as seeing the public key on TheGuardian.com</p>

<p>guim also suffers from security issues.  It's not served over HTTPS - which means that it's possible to see who is accessing the page and, crucially, a man-in-the-middle could alter its contents.</p>

<h2 id="putting-it-all-together"><a href="https://shkspr.mobi/blog/2015/03/dont-use-bit-ly-to-advertise-your-pgp-key/#putting-it-all-together">Putting it all together</a></h2>

<p>By exploiting one or all of these weaknesses, a malicious attacker could create quite a convincing forgery.</p>

<p>If a random Bit.ly link took you to GUlM.CO.UK (a lower case L) and served you a PGP key for alan@guardian-email.co.uk (not the real address) - would you be convinced that it was a legitimate key for the correct user?</p>

<h2 id="fixing-it"><a href="https://shkspr.mobi/blog/2015/03/dont-use-bit-ly-to-advertise-your-pgp-key/#fixing-it">Fixing It</a></h2>

<p>This is a pretty simple fix.</p>

<ul>
    <li>Use a direct link...</li>
    <li>...to a trustworth site...</li>
    <li>...served over HTTPS...</li>
    <li>...</li>
    <li>That's it!</li>
</ul>

<p>Security is, sadly, too hard for most people.  I wrote about <a href="https://shkspr.mobi/blog/2015/03/the-usability-of-anti-apartheid-encryption/" title="The Usability of Anti-Apartheid Encryption">how freedom fighters in South Africa were unable to maintain security due to human weaknesses</a> - nothing much has changed in the intervening years.</p>

<p>I've shared these tips directly with The Guardian's security people, and they are in the process of changing to a more robust system.</p>

<p>I've been reading "<a href="http://www.amazon.co.uk/s/?_encoding=UTF8&amp;camp=1634&amp;creative=19450&amp;field-keywords=think%20like%20a%20freak&amp;linkCode=ur2&amp;sprefix=think%20like%20a%20fr%2Caps%2C252&amp;tag=shkspr-21&amp;url=search-alias%3Daps&amp;linkId=SIEJV6JFQJA7JDBU">Think Like A Freak</a>" by the authors of Freakonomics.  In it, the authors ask us to start thinking more like maverick economists.  It's a fine way to increase your cognative ability and get a fresh perspective on the world.</p>

<p>I'd like to ask you to <strong>think like a hacker</strong>.  Find every weakness in the chain and work to eliminate it.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=20761&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2015/03/dont-use-bit-ly-to-advertise-your-pgp-key/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Episode 10: Better Email #CampaignForRealEmail]]></title>
		<link>https://shkspr.mobi/blog/2014/11/episode-10-better-email-campaignforrealemail/</link>
					<comments>https://shkspr.mobi/blog/2014/11/episode-10-better-email-campaignforrealemail/#respond</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Wed, 26 Nov 2014 07:01:35 +0000</pubDate>
				<category><![CDATA[About A Minute]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[NaBloPoMo]]></category>
		<category><![CDATA[podcast]]></category>
		<guid isPermaLink="false">https://shkspr.mobi/blog/?p=19991</guid>

					<description><![CDATA[Does your email suck? Chris Woods has some suggestions on how to fix it.  Check out his Better Emails tool for Outlook.  	🔊 Better Emails🎤 Terence Eden 	 	 		💾 Download this audio file. 	     Get About A Minute as soon as each episode goes live. Stick this Podcast Feed into your podcatcher  Or you can Subscribe on iTunes   Intro music &#34;Gran Vals&#34; performed by Brian Streckfus. Stopwatch Icon by Ils…]]></description>
										<content:encoded><![CDATA[<p>Does your email suck? <a href="https://twitter.com/mcwoods">Chris Woods</a> has some suggestions on how to fix it.  Check out his <a href="https://web.archive.org/web/20150115213116/http://www.better-emails.com/">Better Emails tool for Outlook</a>.
</p><figure class="audio">
	<figcaption>🔊 Better Emails<br>🎤 Terence Eden</figcaption>
	
	<audio controls="" loading="lazy" src="https://shkspr.mobi/blog/wp-content/uploads/2014/11/AAM-Better-Emails.mp3">
		<p>💾 <a href="https://shkspr.mobi/blog/wp-content/uploads/2014/11/AAM-Better-Emails.mp3">Download this audio file</a>.</p>
	</audio>
</figure><p></p>

<hr>

<p>Get About A Minute as soon as each episode goes live.
<a href="https://shkspr.mobi/blog/category/aam-podcast/feed/">Stick this Podcast Feed into your podcatcher</a>
<a href="https://shkspr.mobi/blog/category/aam-podcast/feed/"><img src="https://shkspr.mobi/blog/wp-content/uploads/2014/11/podcaster_small.jpg" alt="podcaster_small" width="128" height="144" class="alignnone size-full wp-image-19965"></a>
Or you can <a href="https://itunes.apple.com/gb/podcast/about-a-minute/id939617328?mt=2&amp;uo=4">Subscribe on iTunes</a>
<a href="https://itunes.apple.com/gb/podcast/about-a-minute/id939617328?mt=2&amp;uo=4" target="itunes_store" style="display:inline-block;overflow:hidden;background:url(https://linkmaker.itunes.apple.com/htmlResources/assets/en_us//images/web/linkmaker/badge_subscribe-lrg.png) no-repeat;width:135px;height:40px;@media only screen{background-image:url(https://linkmaker.itunes.apple.com/htmlResources/assets/en_us//images/web/linkmaker/badge_subscribe-lrg.svg);}"></a></p>

<p>Intro music <a href="https://www.youtube.com/watch?v=adxr3RGOdrI">"Gran Vals" performed by Brian Streckfus</a>.
<a href="http://thenounproject.com/term/stopwatch/14262/">Stopwatch Icon by Ilsur Aptukov from The Noun Project</a>.</p>

<p><a rel="license" href="http://creativecommons.org/licenses/by-sa/4.0/"><img alt="Creative Commons Licence" style="border-width:0" src="https://i.creativecommons.org/l/by-sa/4.0/88x31.png"></a><br>This podcast is licensed under a <a rel="license" href="http://creativecommons.org/licenses/by-sa/4.0/">Creative Commons Attribution-ShareAlike 4.0 International License</a>.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=19991&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2014/11/episode-10-better-email-campaignforrealemail/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://shkspr.mobi/blog/wp-content/uploads/2014/11/AAM-Better-Emails.mp3" length="0" type="audio/mpeg" />

			</item>
		<item>
		<title><![CDATA[Dark Patterns - Opt-Out / Opt-In]]></title>
		<link>https://shkspr.mobi/blog/2014/06/dark-patterns-opt-out-opt-in/</link>
					<comments>https://shkspr.mobi/blog/2014/06/dark-patterns-opt-out-opt-in/#respond</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Wed, 04 Jun 2014 11:38:10 +0000</pubDate>
				<category><![CDATA[usability]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[opt-out]]></category>
		<category><![CDATA[spam]]></category>
		<guid isPermaLink="false">http://shkspr.mobi/blog/?p=10458</guid>

					<description><![CDATA[Hanlon&#039;s Razor states, &#34;Never attribute to malice that which is adequately explained by stupidity.&#34;  It would be nice to think that all mistakes and errors we encounter are just the result of bone-headedness.  Sadly, that&#039;s not the case.  Quite often malicious people deliberately try to trick you into taking actions you would normally have ignored.  In usability, we call this a &#34;Dark Pattern&#34;.  A …]]></description>
										<content:encoded><![CDATA[<p><a href="https://en.wikipedia.org/wiki/Hanlon%27s_razor">Hanlon's Razor</a> states, "Never attribute to malice that which is adequately explained by stupidity."</p>

<p>It would be nice to think that all mistakes and errors we encounter are just the result of bone-headedness.  Sadly, that's not the case.  Quite often malicious people deliberately try to trick you into taking actions you would normally have ignored.</p>

<p>In usability, we call this a "Dark Pattern".</p>

<blockquote><p>A Dark Pattern is a type of user interface that appears to have been carefully crafted to trick users into doing things, such as buying insurance with their purchase or signing up for recurring bills.
</p><p><cite><a href="http://darkpatterns.org/">DarkPatterns.org</a></cite>
</p></blockquote>

<p>I came across a classic example of this when I signed up to speak at a conference recently:</p>

<p></p><div id="attachment_10461" style="width: 707px" class="wp-caption aligncenter"><img aria-describedby="caption-attachment-10461" src="https://shkspr.mobi/blog/wp-content/uploads/2014/06/Opt-out-dark-pattern.png" alt="Name redacted to protect the guilty." width="697" height="163" class="size-full wp-image-10461"><p id="caption-attachment-10461" class="wp-caption-text">Name redacted to protect the guilty.</p></div><p></p>

<p>The tick-boxes perform the opposite action to each other.  One says "tick for <strong>no</strong> email" the other says "tick to <strong>receive</strong> email".</p>

<p>A casual reader is likely to see that the first box is "opt-out" and then naively assume that the second tick box performs the same action.</p>

<p>Recently, the <a href="http://www.thedrum.com/news/2014/06/02/john-lewis-fined-over-spam-emails">department store John Lewis had to pay damages after they spammed a customer</a>.</p>

<p>In their defence, they said:</p>

<blockquote><p>“Mr Mansfield voluntarily gave us his email address, set up an account online and <strong>chose not to opt-out</strong> of marketing communications when that option was available to him.</p></blockquote>

<p>(Emphasis added).</p>

<p>It is not enough to simply ask the customer to opt-out.  Companies need to ensure that they only market to people who have actively chosen to opt-in.</p>

<p>In the EU, companies are governed by <a href="http://eur-lex.europa.eu/LexUriServ/LexUriServ.do?uri=CONSLEG:2002L0058:20091219:EN:HTML">Article 13 of the Directive on Privacy and Electronic Communication</a>, which states that companies...</p>

<blockquote><p>...may use these electronic contact details for direct marketing of its own similar products or services provided that customers clearly and distinctly are given the opportunity to object, free of charge and <strong>in an easy manner</strong>, to such use of electronic contact details at the time of their collection and on the occasion of each message in case the customer has not initially refused such use.</p></blockquote>

<p>(Emphasis added)</p>

<p>The UK interpretation of the law - <a href="https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/">The Privacy and Electronic Communications (EC Directive) Regulations 2003, section 22</a> - states that email marketing may only be sent when...</p>

<blockquote><p>...the recipient has been given a <em>simple</em> means of refusing (free of charge except for the costs of the transmission of the refusal) the use of his contact details for the purposes of such direct marketing</p></blockquote>

<p>(Emphasis added)</p>

<p>Looking at the above screenshot, I think it could certainly be argued that there wasn't a "simple" way to refuse to be contacted.  It's not "easy" to quickly understand that the same action (ticking a box) can have radically different consequences.</p>

<p>Companies need to ensure that they're only pushing marketing to those people who have <strong>clearly</strong> stated that they want to receive it.  Dark Patterns like this aren't just unethical - they're potentially illegal.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=10458&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2014/06/dark-patterns-opt-out-opt-in/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[Poor IDN Support From Major Webmail Providers]]></title>
		<link>https://shkspr.mobi/blog/2014/01/poor-idn-support-from-major-webmail-providers/</link>
					<comments>https://shkspr.mobi/blog/2014/01/poor-idn-support-from-major-webmail-providers/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Tue, 07 Jan 2014 12:25:18 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[idn]]></category>
		<guid isPermaLink="false">http://shkspr.mobi/blog/?p=9454</guid>

					<description><![CDATA[As I mentioned in a previous post, I&#039;m sick of people not being able to spell or pronounce shkspr.mobi correctly.  So I&#039;ve decided to double down and start using my alternate domain 莎士比亚.org.  It&#039;s pronounced &#34;Sha-shi-bi-ya&#34;, if that helps.  Getting my email account set up with my hosting provider was easy enough but it turned out to be quite tricky to send email to my account.  This is what happe…]]></description>
										<content:encoded><![CDATA[<p>As I <a href="https://shkspr.mobi/blog/2013/12/how-do-you-pronounce-your-domain-name/" title="How Do You Pronounce Your Domain Name?">mentioned in a previous post</a>, I'm sick of people not being able to spell or pronounce shkspr.mobi correctly.  So I've decided to double down and start using my alternate domain <a href="http://莎士比亚.org">莎士比亚.org</a>.  It's pronounced "Sha-shi-bi-ya", if that helps.</p>

<p>Getting my email account set up with my hosting provider was easy enough but it turned out to be quite tricky to send email <em>to</em> my account.</p>

<p>This is what happened when I tried to send an email from Gmail to test@莎士比亚.org:
<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/01/GMail-IDN-Support-fs8.png" alt="GMail IDN Support" width="736" height="607" class="aligncenter size-full wp-image-9452"></p>

<blockquote>Error
The address "test@莎士比亚.org" in the "To" field was not recognised</blockquote>

<h2 id="a-quick-bit-of-history"><a href="https://shkspr.mobi/blog/2014/01/poor-idn-support-from-major-webmail-providers/#a-quick-bit-of-history">A Quick Bit of History</a></h2>

<p>The Internet was build and designed for English speaking people.  At its core, many systems only understand the Latin alphabet.  Not the fancy Latin alphabet with exotic accents and symbols, mind, just A-Z, 0-9, and a handful of punctuation marks.  There simply isn't the capability to do "foreign" characters.</p>

<p>As non-English speakers began to use the Internet, they wanted methods to read and write addresses in their own languages - not an unreasonable desire!</p>

<p>Thus was born "<a href="http://en.wikipedia.org/wiki/Punycode">Punycode</a>" - a method to turn non-English characters into something the infrastructure could understand.</p>

<p>For example, 莎士比亚.org is rendered in Punycode as xn--jlq54w7ypemw.org.  You don't have to understand how it works - just accept that it does :-)</p>

<p>I tried the four most popular free email providers to see if their interfaces would accept the following email addresses as valid destinations:</p>

<pre>test@莎士比亚.org
test@xn--jlq54w7ypemw.org</pre>

<p>The results were <em>not</em> encouraging.</p>

<h3 id="yahoo"><a href="https://shkspr.mobi/blog/2014/01/poor-idn-support-from-major-webmail-providers/#yahoo">Yahoo</a></h3>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/01/Yahoo-Email-IDN-fs8.png" alt="Yahoo Email IDN-fs8" width="875" height="617" class="aligncenter size-full wp-image-9456">

<h3 id="outlook"><a href="https://shkspr.mobi/blog/2014/01/poor-idn-support-from-major-webmail-providers/#outlook">Outlook</a></h3>

<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/01/Outlook-IDN-Test-fs8.png" alt="Outlook IDN Test" width="599" height="575" class="aligncenter size-full wp-image-9457">

<blockquote>The recipient's address can only contain letters (a-z or A-Z), numbers (0-9) and specific symbols (such as @). Please try again.</blockquote>

<h3 id="icloud"><a href="https://shkspr.mobi/blog/2014/01/poor-idn-support-from-major-webmail-providers/#icloud">iCloud</a></h3>

<p>Apple's iCloud was curious. It marked both the IDN and Punycode version in red to indicate that they were invalid.  Yet the mail was allowed to send.
<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/01/iCloud-Test-fs8.png" alt="iCloud Test" width="715" height="292" class="aligncenter size-full wp-image-9458">
However, it immediately failed with this error
<img src="https://shkspr.mobi/blog/wp-content/uploads/2014/01/iCloud-IDN-fail-fs8.png" alt="iCloud IDN fail" width="546" height="429" class="aligncenter size-full wp-image-9459"></p>

<blockquote> Reason: syntax error; address contains 8bit characters</blockquote>

<h2 id="now-what"><a href="https://shkspr.mobi/blog/2014/01/poor-idn-support-from-major-webmail-providers/#now-what">Now What?</a></h2>

<p>Internationalised Domain Names <a href="http://en.wikipedia.org/wiki/Internationalized_domain_name">have existed since 2010</a>.  With billions of people accessing the web from non-English speaking countries, it's essential that web services adapt to accept to serve their needs.</p>

<p>It's simply inexcusable to alienate so many potential users.</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=9454&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2014/01/poor-idn-support-from-major-webmail-providers/feed/</wfw:commentRss>
			<slash:comments>6</slash:comments>
		
		
			</item>
		<item>
		<title><![CDATA[How Do You Pronounce Your Domain Name?]]></title>
		<link>https://shkspr.mobi/blog/2013/12/how-do-you-pronounce-your-domain-name/</link>
					<comments>https://shkspr.mobi/blog/2013/12/how-do-you-pronounce-your-domain-name/#comments</comments>
				<dc:creator><![CDATA[@edent]]></dc:creator>
		<pubDate>Fri, 27 Dec 2013 14:15:33 +0000</pubDate>
				<category><![CDATA[/etc/]]></category>
		<category><![CDATA[chinese]]></category>
		<category><![CDATA[domains]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[rant]]></category>
		<guid isPermaLink="false">http://shkspr.mobi/blog/?p=9392</guid>

					<description><![CDATA[I was listening to a podcast recently which was kind enough to mention one of my blog posts.  The presenter said:  ...and you should Google for this, because I&#039;m really not sure how to pronounce this.  Is it shu-huk-spur? dot mobby?  Le sigh!  It&#039;s a conversation I have most weeks when I&#039;m on the phone to someone - usually a call centre - and they ask for my email address.  &#34;Sierra Hotel Kilo…]]></description>
										<content:encoded><![CDATA[<p>I was listening to a podcast recently which was kind enough to mention one of my blog posts.  The presenter said:</p>

<blockquote>...and you should Google for this, because I'm really not sure how to pronounce this.  Is it shu-huk-spur? dot mobby?</blockquote>

<p><em>Le sigh!</em>  It's a conversation I have most weeks when I'm on the phone to someone - usually a call centre - and they ask for my email address.</p>

<blockquote>"Sierra Hotel Kilo Sierra Papa Romeo Dot Mike Oscar Bravo India"</blockquote>

<p>Whereupon I am inevitably asked:</p>

<blockquote>Is that dot com or dot co dot UK at the end, sir?</blockquote>

<p>Yes! I have chosen an almost unpronounceable domain on an obscure TLD.  Woe is me!</p>

<p>Originally, I thought this wouldn't be a problem. Typing in the domain is quick and easy.  But a surprising number of organisations still insist on taking personal data over the phone.  Which means more reading out the phonetic spelling.</p>

<p>Frustratingly, a large number of websites refuse to accept .mobi as a valid TLD for email addresses.  The geniuses who coded them appeared to think that every email address must end with a 3 character (.com, .org, .net) or 2 character (.uk, .de, .io) sequence.  Despite the fact that there are <a href="http://www.iana.org/domains/root/db">dozens of domains which don't fit in this restriction</a>.</p>

<h2 id="doubling-down"><a href="https://shkspr.mobi/blog/2013/12/how-do-you-pronounce-your-domain-name/#doubling-down">Doubling Down</a></h2>

<p>Being the belligerent sod that I am, I refuse to give in to the tyranny of the spoken word!  We live in an digital world and digital data should be communicated by digital means.  I want to impart information like my email address over the wire - not over the phone.</p>

<p>Regular readers will know that I was thwarted in my quest to buy a .中国 domain - but I did manage to grab <a href="http://莎士比亚.org/" title="http://莎士比亚.org/">http://莎士比亚.org/</a>.</p>

<p>I think I'm going to move my primary email to that domain.  When I get some call-centre who won't let me fill in a form online to give them my details, I shall very politely say my email address is:</p>

<blockquote>Eden - yes, like the garden - at Shā​shì​bǐ​yà... Oh, of course, the <a href="http://commons.wikimedia.org/wiki/Commons:Stroke_Order_Project">stroke order</a> is... Well, no, it's a Mandarin Chinese domain... No... No... Fine, would you like the punycode representation?  Hello?</blockquote>

<p>I'll also refuse to do business when any organisation which doesn't recognise IDN email addresses. That'll show 'em!</p>

<p>Perhaps I'll also move this blog over to that domain as well. I wonder what impact speakability has on SEO?</p>
<img src="https://shkspr.mobi/blog/wp-content/themes/edent-wordpress-theme/info/okgo.php?ID=9392&HTTP_REFERER=RSS" alt="" width="1" height="1" loading="eager">]]></content:encoded>
					
					<wfw:commentRss>https://shkspr.mobi/blog/2013/12/how-do-you-pronounce-your-domain-name/feed/</wfw:commentRss>
			<slash:comments>21</slash:comments>
		
		
			</item>
	</channel>
</rss>
