▲ | alanh 6 days ago | ||||||||||||||||
"The message format is not dangerous. It is the message viewers that are dangerous in this particular regard." Ah, I see. We should allow HTML but display it as plain text. | |||||||||||||||||
▲ | JdeBP 6 days ago | parent [-] | ||||||||||||||||
Or do what actually happened in the 20 years since that myth was actively doing the rounds: display HTML with sandboxed text/html viewers, as pine was doing back then, and as other systems eventually cottoned on to doing. By the time that the 2010s came along, the idea of sandboxing had taken root. Even in the middle 2000s, mail readers such as NEO and Eudora came with feature-reduced internal HTML viewers as an option instead of using the full HTML engine from a (contemporary) WWW browser that would do things like auto-fetch external images. | |||||||||||||||||
|