haydenwoodhead / burner.kiwi

No bullshit temporary mail service written in Go
https://burner.kiwi
MIT License
216 stars 26 forks source link

emailprivacytester.com FAIL #4

Open synox opened 5 years ago

synox commented 5 years ago

The sandboxed iframe does not protect enough from leaked information.

See https://www.emailprivacytester.com/test?code=5c94fc430dedd107e0336465

Screenshot 2019-03-22 at 22 17 52
haydenwoodhead commented 5 years ago

Thanks for bringing this up. I will definitely be investigating how this could be improved, however I don't see this as of critical importance considering iOS's built in mail app and gmail's web app still have some failures when testing using this site.

iOS Mail App: 1eg