Remix.run Logo
sega_sai 4 days ago

It seems to me that having an email client that simply disables all the links in the email is probably a good idea. Or maybe, there should be explicit white-listing of domains that are allowed to be hyperlinks.

SahAssar 4 days ago | parent | next [-]

And who would control that whitelist? How would it be any different than the domain system or PKI CA system we have now?

Do you think there would be the time to properly review applications to get on the whitelist?

0xDEAFBEAD 3 days ago | parent | next [-]

Presumably Gmail already has anti-spam features which trigger based on domain name etc.

They could add anti-phish features which force confirmation before clicking a link to an uncommon domain. Startups could pay a nominal fee to get their domain reviewed and whitelisted.

toast0 3 days ago | parent | prev | next [-]

In a world where those sending email were consistent, the user could control the whitelist. 'This link is from a domain you've clicked through X times, do you want to click through? Yes / Yes and don't ask again'

If it's new, you should be more cautious. Except even those companies that should know better need you to link through 7 levels of redirect tracking, and they're always using a new one.

sega_sai 3 days ago | parent | prev [-]

A user for example. By default nothing would be in the whitelist. Then you would add things to the whitelist manually. Since it's not that frequent this needs to be done, that probably would be a useful extra step to stop phishing.

2OEH8eoCRo0 4 days ago | parent | prev [-]

I've always thought it's insane that anyone on the planet with a connection can drop a clickable link in front of you. Clickable links in email should be considered harmful. Force the user to copy/paste

URLs are also getting too damn long

falcor84 4 days ago | parent [-]

How would copy-pasting help in this scenario?