<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Outlook HTML is better broken and safe, than rich and dangerous</title>
	<atom:link href="http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html/feed" rel="self" type="application/rss+xml" />
	<link>http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html</link>
	<description>Tech writing blog</description>
	<lastBuildDate>Thu, 18 Mar 2010 14:46:18 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: tim</title>
		<link>http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html/comment-page-1#comment-135945</link>
		<dc:creator>tim</dc:creator>
		<pubDate>Thu, 25 Jun 2009 17:08:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html#comment-135945</guid>
		<description>@Dan yes I thought that was what you meant; I don&#039;t have any messages, that I&#039;m aware of and value, where that is a problem.

Tim</description>
		<content:encoded><![CDATA[<p>@Dan yes I thought that was what you meant; I don&#8217;t have any messages, that I&#8217;m aware of and value, where that is a problem.</p>
<p>Tim</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Hallock</title>
		<link>http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html/comment-page-1#comment-135944</link>
		<dc:creator>Dan Hallock</dc:creator>
		<pubDate>Thu, 25 Jun 2009 17:01:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html#comment-135944</guid>
		<description>Clarification: what I mean by broken archives is that existing e-mail messages which rendered properly in 2003, now render improperly in 2007 and will continue to render improperly in 2010.

Aside: I&#039;m curious how Outlook Web Access handles the security implications of HTML e-mail. I know it blocks external content by default. Who knows, there might even be a time-tested pre-parser there that they could use in Outlook.</description>
		<content:encoded><![CDATA[<p>Clarification: what I mean by broken archives is that existing e-mail messages which rendered properly in 2003, now render improperly in 2007 and will continue to render improperly in 2010.</p>
<p>Aside: I&#8217;m curious how Outlook Web Access handles the security implications of HTML e-mail. I know it blocks external content by default. Who knows, there might even be a time-tested pre-parser there that they could use in Outlook.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tim</title>
		<link>http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html/comment-page-1#comment-135939</link>
		<dc:creator>tim</dc:creator>
		<pubDate>Thu, 25 Jun 2009 16:22:48 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html#comment-135939</guid>
		<description>@Dan Hallock well spotted, but according to this Secunia search that is the only one:

http://secunia.com/advisories/product/13799/?task=advisories

Anyway, point taken. My views are coloured by the dreadful security problems with embedded IE in Outlook in OL 97, 98 and 2000 days. My email archive is fine, by the way.

Tim</description>
		<content:encoded><![CDATA[<p>@Dan Hallock well spotted, but according to this Secunia search that is the only one:</p>
<p><a href="http://secunia.com/advisories/product/13799/?task=advisories" rel="nofollow">http://secunia.com/advisories/product/13799/?task=advisories</a></p>
<p>Anyway, point taken. My views are coloured by the dreadful security problems with embedded IE in Outlook in OL 97, 98 and 2000 days. My email archive is fine, by the way.</p>
<p>Tim</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: John Dowdell</title>
		<link>http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html/comment-page-1#comment-135938</link>
		<dc:creator>John Dowdell</dc:creator>
		<pubDate>Thu, 25 Jun 2009 15:42:11 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html#comment-135938</guid>
		<description>Thanks for the voice of sanity, Tim... greatly appreciated.

I watched with horror ten years ago as marketers drove what was clearly unsafe. File formats routinely self-destruct when they attempt to duplicate other formats. RSS is another example... originally for short notifications, then there was pressure to make it a duplicate publishing format.

But it&#039;s hard to push back against those who wish certain features they&#039;ve seen in other formats. It colors my judgment of the WhatWG&#039;s &quot;HTML5&quot; proposals today.

jd/adobe</description>
		<content:encoded><![CDATA[<p>Thanks for the voice of sanity, Tim&#8230; greatly appreciated.</p>
<p>I watched with horror ten years ago as marketers drove what was clearly unsafe. File formats routinely self-destruct when they attempt to duplicate other formats. RSS is another example&#8230; originally for short notifications, then there was pressure to make it a duplicate publishing format.</p>
<p>But it&#8217;s hard to push back against those who wish certain features they&#8217;ve seen in other formats. It colors my judgment of the WhatWG&#8217;s &#8220;HTML5&#8243; proposals today.</p>
<p>jd/adobe</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan Hallock</title>
		<link>http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html/comment-page-1#comment-135937</link>
		<dc:creator>Dan Hallock</dc:creator>
		<pubDate>Thu, 25 Jun 2009 15:36:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html#comment-135937</guid>
		<description>A silly argument and you know it. There&#039;s no need to hand off an e-mail to Internet Explorer untouched; pre-parse it and strip ActiveX and JavaScript. Outlook 2007 broke people&#039;s archives of existing mail and broke compatibility with other e-mail clients. It was a regression for users in every way from 2003.

Secunia Advisory SA30285 can be exploited through the Outlook Word renderer. There are probably others; that&#039;s all I came up with in 90 seconds of looking.</description>
		<content:encoded><![CDATA[<p>A silly argument and you know it. There&#8217;s no need to hand off an e-mail to Internet Explorer untouched; pre-parse it and strip ActiveX and JavaScript. Outlook 2007 broke people&#8217;s archives of existing mail and broke compatibility with other e-mail clients. It was a regression for users in every way from 2003.</p>
<p>Secunia Advisory SA30285 can be exploited through the Outlook Word renderer. There are probably others; that&#8217;s all I came up with in 90 seconds of looking.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tim</title>
		<link>http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html/comment-page-1#comment-135898</link>
		<dc:creator>tim</dc:creator>
		<pubDate>Thu, 25 Jun 2009 08:22:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html#comment-135898</guid>
		<description>@Scott 

Thanks for the comment.

Are you aware of any security exploits for Word in Outlook (exploiting the viewer, not attachments)? Second, what do you think are the chances of Microsoft embedding Gecko or WebKit in Outlook?

Tim</description>
		<content:encoded><![CDATA[<p>@Scott </p>
<p>Thanks for the comment.</p>
<p>Are you aware of any security exploits for Word in Outlook (exploiting the viewer, not attachments)? Second, what do you think are the chances of Microsoft embedding Gecko or WebKit in Outlook?</p>
<p>Tim</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Willeke</title>
		<link>http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html/comment-page-1#comment-135895</link>
		<dc:creator>Scott Willeke</dc:creator>
		<pubDate>Thu, 25 Jun 2009 08:14:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.itwriting.com/blog/1546-outlook-html-is-better-broken-and-safe-than-rich-and-dangerous.html#comment-135895</guid>
		<description>First, the word rendering engine is broken in any case. Take standard HTML that Microsoft claims they welcome and it works in most major email clients except word (and Gmail).

Second, nobody is asking to make Outlook unsafe. If Internet Explorer isn&#039;t safe to use as you imply, then Outlook shouldn&#039;t use use it. Firefox/Gecko has an embeddable engine, so does WebKit/Safari that are widely used in email clients and are proven to be safe for years long before and after IE &amp; Outlook were so widely exploited. BTW: As I recall Word had some well known security exploits to, so the implication that using word is safer doesn&#039;t fly.

Third, standard HTML emails supported by other email clients do not allow &quot;JavaScript, Flash and the like&quot;. Nobody is suggesting that it be added to Outlook.

For me, we write software for business (not &quot;email marketing&quot; either) and our customers often want to be able to send emails with some basic text formatting and maybe some images inside the content to a large group of people who use various email clients. A reasonable request and one that for non-programmers would seem simple enough. However, due to incompatibility of Outlook - and Gmail- it is incredibly difficult to accomplish with reasonable HTML. By embracing Word as a renderer in Office (another thing that surely contributes to Outlooks notoriously poor performance) Microsoft is only exacerbating the problem.</description>
		<content:encoded><![CDATA[<p>First, the word rendering engine is broken in any case. Take standard HTML that Microsoft claims they welcome and it works in most major email clients except word (and Gmail).</p>
<p>Second, nobody is asking to make Outlook unsafe. If Internet Explorer isn&#8217;t safe to use as you imply, then Outlook shouldn&#8217;t use use it. Firefox/Gecko has an embeddable engine, so does WebKit/Safari that are widely used in email clients and are proven to be safe for years long before and after IE &amp; Outlook were so widely exploited. BTW: As I recall Word had some well known security exploits to, so the implication that using word is safer doesn&#8217;t fly.</p>
<p>Third, standard HTML emails supported by other email clients do not allow &#8220;JavaScript, Flash and the like&#8221;. Nobody is suggesting that it be added to Outlook.</p>
<p>For me, we write software for business (not &#8220;email marketing&#8221; either) and our customers often want to be able to send emails with some basic text formatting and maybe some images inside the content to a large group of people who use various email clients. A reasonable request and one that for non-programmers would seem simple enough. However, due to incompatibility of Outlook &#8211; and Gmail- it is incredibly difficult to accomplish with reasonable HTML. By embracing Word as a renderer in Office (another thing that surely contributes to Outlooks notoriously poor performance) Microsoft is only exacerbating the problem.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
