Welcome to the MacNN Forums.

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

You are here: MacNN Forums > News > Tech News > OS X Spotlight search may share details with spammers, reports say

OS X Spotlight search may share details with spammers, reports say
Thread Tools
NewsPoster
MacNN Staff
Join Date: Jul 2012
Status: Offline
Reply With Quote
Jan 9, 2015, 01:44 PM
 
OS X Yosemite's incarnation of Spotlight is potentially sharing personal data with spammers and possible malicious parties, reports say. An option in Mail lets users turn off the loading of remote content in emails, something security experts recommend in order to avoid letting third parties track behavior. The new Spotlight can search through Mail messages alongside other sources, but in doing so will automatically load remote images, regardless of whether Mail is set to do so or not.

The flaw, likely to be a bug, can allow spam-sending parties the ability to monitor which IP and email addresses are receiving the junk mail, and how often a message has been viewed. That data could be pieced together with other content to paint a more detailed picture of targets.

The behavior was recently noticed by a German security publication, Heise, and confirmed by IDG News. Spotlight may even be overriding remote content blocking in other apps, but this remains to be tested.

Apple has yet to comment on the matter. It should, however, be possible for the company to patch more secure code into Yosemite.
( Last edited by NewsPoster; Jan 10, 2015 at 07:36 AM. )
     
lockhartt
Junior Member
Join Date: Apr 2000
Status: Offline
Reply With Quote
Jan 9, 2015, 03:23 PM
 
How is this sharing personal info? Loading a remote image can only confirm data they already have by confirming receipt and viewing of the email... with the notable exception of the IP address, which is already exposed to every website a user visits. This doesn't "share" or "expose" anything.

Yes, disabling remote content is a good idea if you don't have adequate anti-spam measures in place - and, yes, having Spotlight override this preference isn't really cool... but, to say that Spotlight is sharing personal information with spammers is ridiculously misleading.
     
Jeronimo2000
Dedicated MacNNer
Join Date: Aug 2001
Status: Offline
Reply With Quote
Jan 9, 2015, 06:18 PM
 
Misleading, attention-grabbing headline. Cheap shot.
     
chimaera
Dedicated MacNNer
Join Date: Apr 2007
Status: Offline
Reply With Quote
Jan 9, 2015, 06:26 PM
 
@ lockhartt, it's unlikely someone would have visited the spammer website, so they wouldn't get your IP address otherwise. This way, it lets them fill in the blanks, turning an email address into a physical location. Useful for further targeted advertising.

It also confirms if your email is a valid address, and lets them know if writing spam a certain way produces a higher opening percentage. In all cases, letting remote images load produces more spam in the future.
     
   
 
Forum Links
Forum Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Top
Privacy Policy
All times are GMT -4. The time now is 01:53 AM.
All contents of these forums © 1995-2017 MacNN. All rights reserved.
Branding + Design: www.gesamtbild.com
vBulletin v.3.8.8 © 2000-2017, Jelsoft Enterprises Ltd.,