Ditto Posted April 23, 2025 Posted April 23, 2025 I received an email from a colleague (and therefore the same domain) with the key content in a picture. The image was blocked and although I could download, I would have thought being from an internal source, it would be fine. So I raised the topic with our out-sourced support and proposed we had a company wide solution, not one for me to close the ticket! Various nonsensical moves ultimately resulted in the issue going to 3rd line support. I have just received the following comment: "...whether there is a problem with all images showing if we set things up that way?". Also, "There is little impact, security or otherwise, of having images download for all....whether internal or external". I've replied with a link to a MS statement as to why the default is not to download images. For awareness, this is in desktop Outlook as part of M365. Your comments and insights are welcomed.
sigma Posted April 23, 2025 Posted April 23, 2025 That's a no from me. That's not just all the images, but the all tracking pixels that send back whether you opened it or not, even on emails with no apparent images. What about executables sent in images? I would hope they wouldn't get through the various defences , but still... https://security.stackexchange.com/questions/81677/how-is-it-possible-to-embed-executable-code-in-an-image 1
PotNoodleTech Posted April 24, 2025 Posted April 24, 2025 I mean images are no where near as dangerous as PDFs do you block those too?
sigma Posted April 24, 2025 Posted April 24, 2025 PDF's are generally attached, not embedded, so wouldn't open "by default". 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now