Why plain text email, 2026 edition 0 ▲ tinyapps.org 1 hour ago · Tech · hide · 0 comments Gareth Heyes, CSS: the bomb inside your inbox: "It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this paper I'm going to show you how to break out of trust boundaries, exfiltrate tokens, compromise 3rd party websites and even steal passwords." Previously: 2001: Why HTML in E-Mail is a Bad Idea 2002: 7 reasons why HTML e-mail is EVIL 2004: HTML email considered harmful | use plain text email 2006: Force Apple Mail to Display Incoming Messages as Plain Text 2009: Just say no to HTML email and proprietary attachments 2011: Test your mail client's leakiness No comments yet. Log in to reply on the Fediverse. Comments will appear here.