<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body bgcolor="#FFFFFF" text="#000000">
<div class="moz-cite-prefix">On 12/16/2016 11:32 AM, Axel Grude
<a class="moz-txt-link-rfc2396E" href="mailto:axel.grude@gmail.com"><axel.grude@gmail.com></a> wrote:<br>
</div>
<blockquote
cite="mid:2c0eb889-020a-d7b2-f5f0-f036bcdff5b4@gmail.com"
type="cite">
<meta http-equiv="content-type" content="text/html;
charset=windows-1252">
<div id="smartTemplate4-template"><br>
</div>
<div id="smartTemplate4-quoteHeader">
<style type="text/css" scoped="">
#newHeaderAG1 b { font-weight:bold; color: #990033; min-width: 4.5em; max-width:none; display:inline-block;}
</style>
<blockquote type="cite" style="margin-bottom: -20px !important;
padding-bottom:20px !important;">
<div id="newHeaderAG1" style="font-size: x-small; padding:1em;
background-color:rgba(220,220,240,0.4); border-radius:3px;">
<b>Subject:</b>Re: What happened to hiring an architect?<br>
<b>From:</b>Disaster Master <a moz-do-not-send="true"
class="moz-txt-link-rfc2396E"
href="mailto:disasterlistmanager@gmail.com"><disasterlistmanager@gmail.com></a><br>
<b>To:</b>Tb-planning <br>
<b>Sent: </b>Friday, 16/12/2016 15:24:27 15:24 GMT ST +0000
[Week 50]<br>
</div>
</blockquote>
</div>
<blockquote class=" cite"
id="mid_f2273f62_0389_ab8e_7b21_2990cb9aee97_gmail_com"
cite="mid:f2273f62-0389-ab8e-7b21-2990cb9aee97@gmail.com"
type="cite">
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
<div class="moz-cite-prefix">On 12/15/2016 7:02 PM, R Kent James
<a moz-do-not-send="true" class="moz-txt-link-rfc2396E"
href="mailto:kent@caspia.com"><kent@caspia.com></a>
wrote: </div>
<blockquote class=" cite"
id="mid_12b6c4eb_e0a5_b693_cbc5_a0dff2de72ba_caspia_com"
cite="mid:12b6c4eb-e0a5-b693-cbc5-a0dff2de72ba@caspia.com"
type="cite">
<pre wrap="">Postbox's new release is on Gecko 7.0.1, which is now over 5 years old. I have not heard any great outcry about their security issues, and someone on this list (...cough.. BK...cough..ensa) keeps telling us what a great product that is, and how popular it is in Mozilla. So clearly forking Gecko is a CHOICE, and if people at Mozilla are using it then some people at Mozilla must not care that it is based on old Gecko, either.</pre>
</blockquote>
<br>
This supports my feeling that the security risks are actually
much smaller for TB than they would be for, for example, Pale
Moon.<br>
</blockquote>
<p>Postbox has no browser tabs. If Thunderbird was still based on
that old Gecko version that would be a viable attack vector;
just open a tab and do evil stuff from there. Especially easy as
there isn't even a URL bar, so you cannot check certificates /
identity.<br>
</p>
</blockquote>
<br>
Hence my prior comment that that is one of the first things that
should go in TB. I would never use it as a browser anyway, I only
want HTML email rendering.<br>
</body>
</html>