Pages: 1
RSS
The Bat! Pro 5.1.0.4 downloads off-line images by default, no way to change it, That and the new IE rendering engine are a BIG security issue!
 
I have just upgraded from The Bat! Professional 5.0.36.2 to 5.1.0.4. I paid the licence upgrade without hesitation, because I have been a faithful The Bat! user for some years now, love the program and knew that I would want to keep having the latest version.

However, I was terrified when I noticed that it was downloading off-line images without being commanded to do so! As you know, that is a huge security and privacy liability, because off-line images can be used in many hazardous ways: the URL can be used by spammers to confirm valid e-mail addresses, or by sites in general to track user visits, or they can be used to download specially crafted malicious files disguised as harmless images, and there are even the infamous one-pixel transparent GIFs that are completely invisible and serve the same nasty functions without the user even knowing they exist. No way I would want my e-mail client to download images by default! Not even Web-based e-mail services like Gmail or Yahoo! download images by default.

My first reaction was to look for the image download manager on the message pane. It was gone! Now, the press release for version 5.1 says that "Image download manager is equipped with the option of creating various rules..." etc., but there was NO download manager at all! Rather, there used to be one until version 5.0, but that feature apparently has been removed now, not added. The former easy icon with a drop-down menu was gone and nowhere to be found. I could not find any menu option to prevent images from being downloaded, nor was there any preference setting that even mentioned it. The help file said nothing about it either - in fact, I found that the help file had not been updated to the new version and still clearly stated: "The program does not download images from outside sources! Only images embedded in the message are shown." Absolutely not true for 5.1.0.4 - I had just seen it do exactly that before my eyes, without being commanded to do so (of course: how could I command it to do or not do anything about that without a download manager?).

That removed feature alone would be enough to make the new version of The Bat! dreadfully unsafe. But it got even worse. In my attempt to find a way to disable off-line image downloads, I right-clicked the message pane. Instead of the usual menu with options for the message, I was surprised to see the same context menu I see when right-clicking a Web page on Internet Explorer (a rare event, because I only use IE if there is absolutely no choice).

What??? The Bat! is now using IE to render HTML messages??? Good heavens!!! If I had wanted a direct privileged channel to the Windows kernel for a malicious e-mail to use, I'd be using Windows Live Mail! If I'm using a different e-mail client, one of the reasons is precisely to avoid that big security vulnerability that will always exist with IE, by itself or in embedded form. And again, there was nowhere to be found an option to use an alternative rendering engine - contrary to what the press release says: "Users can choose which module ... satisfies their needs best or just switch between these two modules." That, combined with the automatic download of off-line images, is the perfect recipe for disaster. Such an option should never even have been  made available, let alone activated by default and with no obvious way to disable it.

I thoroughly searched the program interface and could find neither a download manager, nor any option to switch the rendering engine as promised. If they are there, they are well hidden and need to be brought to the front. Also if they are there, I'd welcome and thank any hint about wh ere they could be. In the meantime, I have returned to 5.0.36.2, which does not have such absolutely unacceptable security liabilities. As it is, 5.1.0.4 is too unsafe for me to even consider using it.

Even if there is a way to prevent automatic off-line image downloads and switch the rendering engine, and I just couldn't find it, The Bat! is in urgent need of a 5.1.1 version or such that addresses the following issues:

- Off-line image downloads should be OFF by default.

- The HTML rendering engine should be the native one by default, not IE. (Considering that there has always been an option to view the message in a browser, I can't think of any useful purpose that feature can have.)

- Such features need to be made more obvious and easy to find and use.

- The help file needs to be updated (it still has the Windows 2000 interface on screen captures and that says a lot).

If The Bat! 5.1 continues as it is, I will regretfully have to start considering another e-mail client. Please, Ritlabs, don't spoil the best e-mail client around by making it a security liability.

Thanks for your attention and help with these IMO extremely serious security issues.
 
TOOLS / IMAGE DOWNLOAD MANAGER and set it the way you like :D
 
Thanks, Rick. Once I fruitlessly searched for such options and couldn't find them, I panicked at the obvious risks and immediately returned to 5.0.36.2, preventing any further searches. After your tip, I reinstalled 5.1.0.4 and looked for it again. The download manager is where you said it was, and I also found how to change the rendering engine - it's in the Preferences window, under Viewer/Editor - HTML Viewer.

However, I believe this is still a step backwards in terms of usability. Formerly, I could download the images of only one specific message, if I wanted or needed that. I could even easily choose which specific images to download or not. Now, apparently I have to access the top menu (as opposed to using an icon and drop-down menu right at hand), enter a rule, save it and view the desired message again. Then, if I don't want any other message from that sender or site to be downloaded again, I have to repeat the operation to delete the rule. Definitely clumsy. The rules certainly add functionality and that per se is welcome, but not at the cost of removing previous functionality.

As for the rendering engine, maybe Ritlabs was too eager to show off the new feature, but defaulting to IE (especially as the option says it's a "beta" feature) and also defaulting to not following The Bat!'s rules but leaving it under IE control (which was why images were being downloaded in my case before) is a very serious security risk and most definitely a very bad design decision.

In that case, the option warns that "Security is provided by your computer security systems (antivirus software, firewall etc.)", but first, security software is not perfect and can still fail - it's better to eliminate the problem by the root; second, security software can do nothing about privacy-intruding URLs, which are one of the greatest issues in this case and are often coded in unpredictable and undetectable ways; and third, what if the user trusts crappy security software (as it's often the case)?

I hope The Bat! defaults to the more secure options in future releases. Not all users are aware of such security risks and how to avoid them.

Finally, the help file needs to be updated. It says absolutely nothing about the new features. Unfortunately, documentation has never been Ritlabs' forte and that problem still remains.

Well, now my investment is justified, as I can now safely use the version I paid to upgrade to. But other users may not be so lucky and may be exposed to unnecessary risks. Please, Ritlabs, fix this ASAP!
Edited: goytabr - 24 April 2012 01:12:11
 
That is the one "problem" with the Bat - there are SO MANY features that sometimes one cannot find what they are looking for.  ;)

I think you will find that when you are on an HTML message, the globe appears on the message or preview pane and you can click it to automatically add the rule and see the graphics.

The Image download manager is still a work in progress - wild cards don't seem to work and I would like to be able to "allow all" yet specify folders such as "spam" to NOT show pictures. I can't really complain though if "all" really means "all"  :D
 
No globe appears on HTML messages. Neither on the preview pane, nor on message windows. Maybe it has to do with the fact that I use exclusively user folders? (Filters automatically route virtually all messages there.) But that wasn't a problem before. :(
 
goytabr: Thanks very much for pursuing this.  I heartily agree about the ill-advised default settings, and the lack of notice about this change.  

Also thanks for pointing out the Viewer/Editor - HTML Viewer settings.  Settings which seem to get me back to my comfort zone are:

Download embedded images from external sites: Never
Use The Bat HTML viewer: Yes
 
I also 100% agree with defaulting to TheBat! HTML viewer and never automatically downloading images.

TheBat! developers should know that after trying many different email clients, I too was initially attracted to TheBat! email client for their sensible programming and ethical decisions.  I hope this error in judgement is temporary.

If the developers wish to show off some new features perhaps some things should be included as options in the setup process during install.
Pages: 1