Mail.app too dangerous to use?
The recent security flaws in Mac OS X have produced a range of responses. But in a lengthy article, IT columnist and Unix administrator John Welch
sets a new high point.
It’s not enough to be (extra) careful about opening attachments in emails that you are unsure about. More drastic action is required:
If you are using Apple’s Mail, I’d consider switching to another mail program, at least temporarily. The problem with Mail is that it allows you to open a file with a single click, and there’s no warning from the application to give you a second chance to cancel that action. Neither Thunderbird nor Microsoft Entourage allow for this, so you might want to think about switching until Apple fixes that.
Oddly, later in the article he suggests: “Just take the common-sense steps that we all should be taking anyway, and you’ll be fine.”
Similar Posts:
- Security flaw with scripts in Mail.app
- More security flaws in Mac OSX
- Thunderbird 1.5.0.2 is out
- Exchange Server 2007, Mail.app and Safari
- Thunderbird 1.5.0.4: Universal binary!
Tags: Apple Mail, attachments, entourage, mac osx, mail.app, scripts, security, thunderbird, vulnerability

February 26th, 2006 at 6:58 am
Wow. “Most users are too stupid to not open attachments from unknown senders so we recommend migrating mail clients!” (which is a non-trivial task to do properly)
Sigh. ;)
February 26th, 2006 at 8:02 pm
Yes, it did seem like extreme advice.
Although I have noticed in the past that system administrators can have a low regard for the intelligence of “normal” users ;-)
February 27th, 2006 at 8:50 am
Yeah, switching mail programs can be an ongoing, relatively complicated, non-trivially time consuming process (e.g. as migrating from Mulberry to Apple Mail was for me). And by the time that’s successfully accomplished to work around for this particularly problem Apple will probably have released a fix. Personally, I’ll take the known risk continuing to use Apple Mail (carefully conservatively, as always) over spending a substantial amount of time switching and then ramping up productivity with an alternative mail program. In some other situation I might feel and act differently.
One corollary to that might be something like:
Certain sysadmins assume (often mistakenly, if not downright arrogantly) that something technically obvious to them will always be just as apparent to everyone else.
February 27th, 2006 at 8:56 am
Fair point.
I should put on the record that some of my best friends are systems administrators, terrific guys, every one of them.