Email Wiretapping- Don't be a victim

>web-based email systems automatically strip out
On the face of it, does email wiretapping soundJavaScriptprograms from incoming email messages
scary? Yes? Yesit is scary and you should now howand therefore are notvulnerable.
it's done and how to combatit.The loophole is made possible because JavaScript is
A little while ago the known (but not known with aable to readtext in an email message. If a message is
load presence)organisation called "The US basedforwarded to someoneelse, the hidden JavaScript
Privacy Foundation" becameaware of a as un-yetcode can read any text that has beenadded to the
widely known security hole in the latestincarnationsmessage when it is forwarded. This JavaScript
of email clients produced by Microsoft and Netscape.codeexecutes when the forwarded message is read.
The security loophole essentially allows the sender ofThe JavaScript codethen silently sends off this text
an emailmessage to see what has been writtenusing a hidden form to a webserver belonging to the
when the message isforwarded with comments tooriginal sender of the message. Theoriginal sender can
other recipients. This procedure hasbeen nicknamethen retrieve the text at their convenienceand read
"email wiretapping". As you can imagine this leadstoit.
surreptitiously monitoring of written messagesA "wiretapped" email message is difficult to detect.
attachedand/or forwarded messages. Some not soAnindividual can avoid the email wiretap by turning off
pleasant uses involve:JavaScriptin the email reader. However, if the
1) In a sensitive business negotiation conducted viaindividual forwards themessage to someone who has
normal email,one party can learn inside informationJavaScript turned on, thatrecipient's forwarded
from the other parties asthe proposal is discussedmessages can still be" wiretapped".
through the recipient company'sinternal email system.Additionally, copying the original message into a new
2) A seeded email message could capture thousandsemail,rather than forwarding it, may not defeat the
of emailaddresses as the forwarded message is sentproblem.
around the world.What can users can do?
Seeded with what? JavaScript is the answer and itIt is possible to partially eliminate the email
can easilyhide in any HTML email. Of course thewiretappingproblem by turning off JavaScript in HTML
JavaScript capability hasto be enabled within the emailemail messages. Youcan visit the home webpage for
client. Typical email readers withyour appropriate browser packageif you are not sure
JavaScript functionality include Outlook, Outlookon how to do this.
Express, andSwitching off the JavaScript is only a partial solution
Netscape 6 Mail. Earlier versions of the Netscape mailbecausea "wiretapped" message will still work if it is
readersare not affected because they do not fullyreplied to, orforwarded, to someone whose email
support all theintricacies of JavaScript. Eudora and theprogram is vulnerable to themalicious JavaScript. The
AOL 6.0 series of emailreaders are not affectedbest policy is some form of group orcorporate
because JavaScript is turned off bydefault (but areagreement on how to tackle this, especial
vulnerable if turned on of course). Hotmail andotherwherecommercially sensitive material is involved.