logoalt Hacker News

jttnr • today at 6:49 AM • 2 replies • view on HN

The thing with all these vibe-coded email clients is: how well do they sanitize the full-content view of HTML emails? Thunderbird and the like go to great lengths to make viewing those emails safe, e.g., by preventing inline JavaScript and all kinds of tracking techniques (pixels, CSS references, etc.). Without having checked, do these vibe-coded clients just render the HTML in a WebView, or do they have similar protections in place?


Replies

achempion • today at 9:01 AM

This is actually a very tricky problem. We solve this by never rendering mails in trusted origin. It's basically sanitisation + isolated sandboxed iframe for defence in depth + standard security stuff like CSP headers. When I was looking into this, I was surprised how many popular mail clients relay primarily on sanitization and render mails within trusted origin (ex: marco, superhuman).

Other interesting problem to solve for mail clients is the editor. You should be able to forward/edit untrusted html content. Source: I develop tecotype.com for mac/linux/windows.

koiueo • today at 7:41 AM

"claude, make no mistakes" is your best protection

➕ show 1 reply