TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

UPenn uses 3rd party to scan and rewrite all URLs in emails

31 点作者 podiki超过 3 年前

6 条评论

musicale超过 3 年前
Lots of schools and companies do this; I understand why, but it makes it hard to communicate with people at such institutions.<p>And that&#x27;s not even considering the security and privacy risks to email users from third-party email scanning and rewriting.<p>I could also imagine legal issues going both ways, particularly if the third party is tempted to retain data about email users.<p>For example, some universities that use Gmail and Google Apps for Education (for example) required that Google <i>not</i> scan student email, presumably due to privacy and legal requirements, or faculty email (due to faculty objections), and Google itself ultimately abandoned the practice in the face of a lawsuit.<p><a href="https:&#x2F;&#x2F;marketbrief.edweek.org&#x2F;marketplace-k-12&#x2F;google_abandons_scanning_of_student_email_accounts&#x2F;" rel="nofollow">https:&#x2F;&#x2F;marketbrief.edweek.org&#x2F;marketplace-k-12&#x2F;google_aband...</a>
评论 #28714756 未加载
评论 #28713208 未加载
gwittel超过 3 年前
Disclaimer: Involved in building these sort of systems so I can go on about a lot (though not as much detail as I&#x27;d like).<p>At this point, most security vendors that handle email do this (or offer it). The main reason for re-writing is its device independent. A browser plugin only gets you so far, and doesn&#x27;t handle modern needs where devices that have mail access will be unmanaged.<p>The tradeoff is yeah, the URLs are ugly. There&#x27;s a balance between highlighting where the URL goes, embedding the info necessary for redirects, preventing redirect abuse, per user policy, etc.<p>In the end, its all really about buying time. At mail delivery time, you can only get some % of threats. Given there&#x27;s a gap between delivery, and click time, you can use that to your advantage and at least prevent some % of the user base being exposed to bad stuff.<p>On top of it all, you have all sorts of edge cases like what to do with things that aren&#x27;t URLs, but mail clients turn into clickable links. What about URLs in attachments? \o&#x2F; Time to run away.
vondur超过 3 年前
Microsoft has the same service for Office 365 users. We also get a warning when an email comes from a domain other than ours. This is to help warn users of possible scams using spoofed email addresses.
评论 #28714050 未加载
chromatin超过 3 年前
I’m surprised this is news? My employer has been using proofpoint to do this for years.
podiki超过 3 年前
I can understand the problems of phishing etc. for probably the majority of email users at a large institution...but then you have every link rewritten to look stranger, and tons of data (links sent, clicked on, with all the metadata of that) in the hands of a 3rd party. I don&#x27;t think this is the right solution, is this really the best we can do right now?
fred_is_fred超过 3 年前
Lots of places do this including my current employer.
评论 #28711700 未加载