Cached Leopard Mail images: friend or foe?
TUAW reader Simon wrote in to us, to share one of his favorite new Leopard features--and its unexpected consequences. After clicking on an All Images search, he was astonished to find any number of odd gifs and jpgs pertaining to, um, Viagra, and er, male enhancement. He quickly realized that All Images was displaying bits (and we do mean bits) from Mail's download cache. This means that although he set Mail to not download HTML images, they're getting downloaded anyway. Simple annoyance or possible security breech? You tell us in the comments.
Share
TUAW reader Simon wrote in to us, to share one of his favorite new Leopard features--and its unexpected consequences. After clicking on an...
Add a Comment
mail attachment images or no, i dread to think what would happen if i looked at 'All Images' with cover flow on my machine.
November 08 2007 at 8:46 PM Report abuse Permalink rate up rate down ReplyThis is a SERIOUS security breach. Aside from being extremely annoying, almost every single mac virus/exploit I've hear of comes from disguised image files.
That's why I love gmail's "Images have not been downloaded. Should I?"
Am I the only one who thinks the real problem is that spotlight ought to exclude the cache by default? Let people who need to search those files turn it on deliberately, but for the most part the files in the cache are collateral damage from internet activity, and not things we are looking for or even know are stored on our hard drives. They're noise and should be filtered out.
At least now I know to change my spotlight settings to exclude the cache folders.
Just tell Little Snitch to block images in Mail. If you allready allowed it just delete the preferences of Mail and wait for the next pic-spam.
November 08 2007 at 4:38 AM Report abuse Permalink rate up rate down ReplyThey're attachments embedded in the email according to the multipart specification, not downloaded from an external server. It's the same process that lets Mail 3.0 add spiffy stationary to your messages.
November 08 2007 at 2:55 AM Report abuse Permalink rate up rate down ReplyThank you for your statement, Simon. It's now up to TUAW to post a corrigendum.
November 08 2007 at 2:10 AM Report abuse Permalink rate up rate down ReplyAs a quick temporary work around, I just had spotlight ignore my Deleted Messages, Junk, Trash mailboxes. Works fine for me.
November 08 2007 at 2:02 AM Report abuse Permalink rate up rate down ReplyThese images are NOT HTML references cached, these are attachments that many spam e-mails now have. If the user would enable the attachment count column in their e-mail message list, they'd see which (spam) messages come with attachments.
The strategy is to attach the entire spam as a picture with a noisy background pattern, such as to prevent text based spam filtering and to thwart OCR based image to text conversion during spam filtering.
These images will deleted from the cache as the messages are DELETED, but not if the messages are just MOVED to the spam folder. Also, for the images to be deleted, the "remove unedited downloads" preference (under Mail's General tab) must be set to "After message is deleted", because as far as Mail is concerned, it's "downloading" the images from a data source i.e. the attachment.
It would of course be nice if the mail download folder could distinguish between what's in the Junk folder and what's not, but if you don't want these sort of surprises, change your spam handling rules to custom settings and have spam deleted on arrival, then you should not have these images in the first place.
I've noticed a breach along the same lines. I have multiple users and although you can't access another users files by going to their home folder, spotlight and "search for" return other users files that are then viewable by quickview.
November 07 2007 at 11:17 PM Report abuse Permalink rate up rate down ReplyYou know - you guys are right - these have to be attachments. It makes sense - and it makes me feel better about Mail not downloading html images in the background. Thanks TUAW community - you guys are the best.
- Simon
Hot Apps on TUAW
Deals of the Day
more deals- Refurb Apple MacBook Air Laptops: 12" 64GB SSD for $699 + free shipping
- JVC Motion Sensing Clock Radio with Dual iPod Docks for $55 + free shipping
- Apple iPhone Headset with Mic for $4 + $2 s&h
- miFrame Picture Frame Dock for iPad for $64 + $8 s&h
- Refurb Apple iPod nano 8GB MP3 Player for $99 + free shipping, 16GB for $119
- Hannspree Apple-Shaped 28" 1080p LCD HDTV for $270 + free shipping
Software Updates
more updates- EFI Firmware Update brings Lion Internet Recovery to 2010-model Macs
- OS X Lion 10.7.3 released with Safari 5.1.3, Wi-Fi bug fix
- Aperture updated to 3.2.2, addresses Photo Stream issue
- Apple updates Keynote to address Lion issues
- Google Search app gets new look on iPad
- Apple releases Apple TV Software Update 4.4.3



25 Comments