• 22 Posts
  • 327 Comments
Joined 1 year ago
cake
Cake day: June 2nd, 2023

help-circle










  • I feel maybe that’s a dovecot issue? Or a spamassassin issue?

    In my setup it seems “normal” that spam sent to aliases gets in the “catch all” instead of the mailbox of the user that has that alias. Very infuriating as I had to tune down the spam filter to block only the most obvious spam as false positives get “lost”

    Although since 3-4 months ago I didn’t receive any misdirected spam in the catch-all mailbox, so it might be that’s now it has been fixed (I’m one of those guys that run updates automatically unattended because my hobby is fixing problems when there’s a breaking feature after update)



  • Yes but in this case it’s something that parses stuff received from internet, not a calculator or a sudoku app. There’s a tiny chance that a specially crafted email could be exploited. It’s very unlikely that it would be explicitly targeted as it’s a niche app that now gets less than a download a day, but still IMHO it’s dangerous.

    On the fdroid community I once recommended to everyone a 100% offline app that generated generic images for contacts without pictures and because it was abandoned in 2018 I was downvoted by many who would say “what if an attacker with some top tier social engineering skill persuaded you to use a specially crafted exploited image as a contact picture on your phone, then when you used this app to parse existing picture, the 6 years old image library would be exploited and your phone hacked??” - something that has the same probability of “what if the same day you found on the ground a winning lottery ticket a meteorite hits the ground, bounces back all the stairs and hits you while waiting the subway pushing you on an incoming train?”