Closed Bug 1423440 Opened 7 years ago Closed 7 years ago

Mailsploit: Remove @ from real name in From

Categories

(MailNews Core :: MIME, enhancement)

enhancement
Not set
normal

Tracking

(Not tracked)

RESOLVED WONTFIX

People

(Reporter: BenB, Unassigned)

References

Details

This is part of bug 1423430. See there for background. If there is an @ sign in the real name part of the From, strip it. It's highly likely to be spoofing some other address. (And yes, I know that some devs use this on bugzilla as a feature :-) . But we're not normal people.) We may do this in libmime or in the frontend.
This is clearly a WONFTFIX since this will upset a good part of the user community. There is nothing wrong with having: "Men @ Work" <menatwork@example.com> People use this and complain if it doesn't work, see bug 1359774. Let's not overreact, please.
Status: NEW → RESOLVED
Closed: 7 years ago
Resolution: --- → WONTFIX
Group: mail-core-security
Group: mail-core-security
I found some more real life examples: From: "Bugzilla@Mozilla" <bugzilla-daemon@mozilla.org> - Check that one, BMO e-mail invalid! Then Yahoo groups send this: From: "Real name xxx@gmail.com [Barcelona-Freecycle]" <Barcelona-Freecycle-noreply@yahoogroups.com> From: "Real Name yyy@yahoo.com [freecycle-berlin]" <freecycle-berlin-noreply@yahoogroups.de>
Yes. And if the "@" was replaced by " ", that wouldn't be a huge problem. The problem is that "fred@whitehouse.gov <head.political.communications@spammer.com>" is going to be read as "Fred from the White House" by most users
As long as TB doesn't do the stupid Apple Mail thing called "smart address" this is not so much a problem. Pressing "reply" or "compose message to" or the such is still safe. Inside a quoted part of the from name the "@" is a legal character and therefore should not get removed or replaced. Maybe some users get confused and click on a link in such a message and that's bad, but hopefully this not the majority.
You need to log in before you can comment on or make changes to this bug.