<html>
<head>
<meta http-equiv="content-type" content="text/html; charset=windows-1252">
</head>
<body smarttemplateinserted="true" bgcolor="#FFFFFF" text="#000000">
<div id="smartTemplate4-template"><br>
</div>
<div id="smartTemplate4-quoteHeader">
<style type="text/css" scoped="">
#newHeaderAG1 b { font-weight:bold; color: #990033; min-width: 4.5em; max-width:none; display:inline-block;}
</style>
<blockquote type="cite" style="margin-bottom: -20px !important;
padding-bottom:20px !important;">
<div id="newHeaderAG1" style="font-size: x-small; padding:1em;
background-color:rgba(220,220,240,0.4); border-radius:3px;"> <b>Subject:</b>Re:
What happened to hiring an architect?<br>
<b>From:</b>Disaster Master
<a class="moz-txt-link-rfc2396E" href="mailto:disasterlistmanager@gmail.com"><disasterlistmanager@gmail.com></a><br>
<b>To:</b>Tb-planning <br>
<b>Sent: </b>Friday, 16/12/2016 15:24:27 15:24 GMT ST +0000
[Week 50]<br>
</div>
</blockquote>
</div>
<blockquote class=" cite"
id="mid_f2273f62_0389_ab8e_7b21_2990cb9aee97_gmail_com"
cite="mid:f2273f62-0389-ab8e-7b21-2990cb9aee97@gmail.com"
type="cite">
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
<div class="moz-cite-prefix">On 12/15/2016 7:02 PM, R Kent James <a
moz-do-not-send="true" class="moz-txt-link-rfc2396E"
href="mailto:kent@caspia.com"><kent@caspia.com></a>
wrote: </div>
<blockquote class=" cite"
id="mid_12b6c4eb_e0a5_b693_cbc5_a0dff2de72ba_caspia_com"
cite="mid:12b6c4eb-e0a5-b693-cbc5-a0dff2de72ba@caspia.com"
type="cite">
<pre wrap="">Postbox's new release is on Gecko 7.0.1, which is now over 5 years old. I have not heard any great outcry about their security issues, and someone on this list (...cough.. BK...cough..ensa) keeps telling us what a great product that is, and how popular it is in Mozilla. So clearly forking Gecko is a CHOICE, and if people at Mozilla are using it then some people at Mozilla must not care that it is based on old Gecko, either.</pre>
</blockquote>
<br>
This supports my feeling that the security risks are actually much
smaller for TB than they would be for, for example, Pale Moon.<br>
</blockquote>
<p>Postbox has no browser tabs. If Thunderbird was still based on
that old Gecko version that would be a viable attack vector; just
open a tab and do evil stuff from there. Especially easy as there
isn't even a URL bar, so you cannot check certificates / identity.<br>
</p>
<p>Axel</p>
<br>
</body>
</html>