logoalt Hacker News

chowellsyesterday at 9:17 PM1 replyview on HN

The article addresses this, actually. Fetching any unsecured content is an attack vector. https://danq.me/2026/01/28/hsbc-dont-understand-email/#footn...


Replies

crazygringoyesterday at 9:32 PM

In this particular case, injecting content into the image to make someone read a false message doesn't seem possible. The pixel <img> tag has width and height set to one. This overrides whatever the image size is. No altered message will be readable.

show 1 reply