<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Byung Kyu Park&#039;s Personal Website &#187; gmail</title>
	<atom:link href="http://bkpark.com/tag/gmail/feed/" rel="self" type="application/rss+xml" />
	<link>http://bkpark.com</link>
	<description>Everything about Byung Kyu Park</description>
	<lastBuildDate>Tue, 07 Feb 2012 16:59:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Calmail leaks IP addresses!</title>
		<link>http://bkpark.com/2009/11/29/calmail-leaks-ip-addresses/</link>
		<comments>http://bkpark.com/2009/11/29/calmail-leaks-ip-addresses/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 09:43:47 +0000</pubDate>
		<dc:creator>bkpark</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[tech]]></category>
		<category><![CDATA[calmail]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[ip address]]></category>
		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://byungkyupark.com/?p=347</guid>
		<description><![CDATA[For regular visitors of my blog from UCB, here&#8217;s an early holiday Christmas present to you: Calmail leaks IP addresses! Here&#8217;s a quick demonstration (I&#8217;ve seen similar headers on emails from friends and colleagues, but I didn&#8217;t want to expose their info; I&#8217;ve redacted some info here as I didn&#8217;t want to expose my &#8230; [...]]]></description>
			<content:encoded><![CDATA[<p>For regular visitors of my blog from UCB, here&#8217;s an early <strike>holiday</strike> Christmas present to you: Calmail leaks IP addresses! Here&#8217;s a quick demonstration (I&#8217;ve seen similar headers on emails from friends and colleagues, but I didn&#8217;t want to expose their info; I&#8217;ve redacted some info here as I didn&#8217;t want to expose my &#8230; secret email server scheme, or my real username for Calmail):</p>
<pre>
Return-path: <span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@visitor3.berkeley.edu</span>
Envelope-to: <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>
Delivery-date: Sun, 29 Nov 2009 01:32:12 -0800
Received: from visitor3.berkeley.edu ([128.32.124.159])
        by helen.byungkyupark.com with esmtps (TLS1.0:RSA_AES_256_CBC_SHA1:32)
        (Exim 4.69)
        (envelope-from <<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@visitor3.berkeley.edu</span>>)
        id 1NEg8a-0000jX-J7
        for <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>; Sun, 29 Nov 2009 01:32:12 -0800
Received: from xxxxxxx by visitor3.Berkeley.EDU with local (Exim 4.69)
        (envelope-from <<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=dyDLj35ECYXkCGNyD8Wn7Z4SXacqEPNBRCYEGwbOlAE=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@visitor3.berkeley.edu</span>>)
        id 1NEg8a-0001rk-4v
        for <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=zscrs5YV0BrJPIqvASyMDTm6MznGNiH4PWSsGVR6w-4=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@xxxxxx.xxx</span>; Sun, 29 Nov 2009 01:32:12 -0800
Received: from smtp-out1.berkeley.edu ([128.32.61.106])
        by visitor3.Berkeley.EDU with esmtp (Exim 4.69)
        (envelope-from <<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>>)
        id 1NEg8a-0001rW-2q
        for <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@byungkyupark.com</span>; Sun, 29 Nov 2009 01:32:12 -0800
Received: from arsenic.calmail ([192.168.1.2] helo=calmail.berkeley.edu)
        by fe2.calmail with esmtpsa (TLSv1:AES256-SHA:256)
        (Exim 4.69)
        (auth plain:<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>)
        (envelope-from <<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>>)
        id 1NEg8T-0000qs-8R
        for <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@byungkyupark.com</span>; Sun, 29 Nov 2009 01:32:06 -0800
MIME-Version: 1.0
Received: from visitor3.Berkeley.EDU [128.32.124.159]
        with HTTP/1.1 (POST); Sun, 29 Nov 2009 01:32:05 -0800
Date: Sun, 29 Nov 2009 01:32:05 -0800
From: "Byung Kyu Park, BA" <<span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>>
To: <span class="mh-email">bkp<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=jXl0hewn54aHhNoqbqT8GHWVD3Hq20ZF_0ks3DnwKT0=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@byungkyupark.com</span>
Subject: This will demonstrate how Calmail leaks IP addresses
Message-ID: <<span class="mh-email">7272<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=PIZb3BZ65wtedD-LBrEO1s6_ddlpl4eURLiWRU9gu9bksB0BbGqHyEQoJjzd3s48' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=PIZb3BZ65wtedD-LBrEO1s6_ddlpl4eURLiWRU9gu9bksB0BbGqHyEQoJjzd3s48', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>>
X-Sender: <span class="mh-email">xxxx<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=HrlVOPk__MUtIJuG2xh1qI7bfAQjdGssJUyLOdr3Ctg=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>
User-Agent: RoundCube Webmail/0.3-RC1.UCB3
Content-Type: multipart/alternative;
        boundary="=_ad4b95d1d25a334cada12ae4c3335783"

Content-Transfer-Encoding: 8bit
Content-Type: text/plain; charset="UTF-8"

And this email was composed on the RoundCube webmail client.

Andrew
</pre>
<p>You will see that the detailed email header (which most email clients hide, but there is always an option to show full headers) reveals the IP from which I was accessing Calmail&#8217;s webmail interface (no, I&#8217;m not in the lab right now; but I am proxying through one of my servers, because I consider my current IP address a confidential, personal, private information). Similar headers show if you use SMTP protocol or if you use the other webmail.</p>
<p>I am not entirely sure if this is a feature or bug&mdash;embedding IP information in headers will help with legitimate activities of law enforcement authorities, as well as illegitimate (is there any other kind?) squelching of dissenting voices&mdash;so I haven&#8217;t reported it to <span class="mh-email">abu<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=WdX4nZ0t6okDHer_vsLt9SbNbqXWq2EEI392bvkc4iY=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=WdX4nZ0t6okDHer_vsLt9SbNbqXWq2EEI392bvkc4iY=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span> or, I don&#8217;t know, <span class="mh-email">h<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=JzlZGyzrhl1f-vxngDtmvDxa-12AwpOtYWLW3LGae3g=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=JzlZGyzrhl1f-vxngDtmvDxa-12AwpOtYWLW3LGae3g=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>? <span class="mh-email">secu<a href='http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=F_ZV3im-1FOCU20DjclP1b88u6z2m8jp5vIEDGzZM3A=' onclick="window.open('http://www.google.com/recaptcha/mailhide/d?k=01_XBzvkXPAGq9nDA-tWWsQA==&amp;c=F_ZV3im-1FOCU20DjclP1b88u6z2m8jp5vIEDGzZM3A=', '', 'toolbar=0,scrollbars=0,location=0,statusbar=0,menubar=0,resizable=0,width=500,height=300'); return false;" title="Reveal this e-mail address">...</a>@berkeley.edu</span>?</p>
<p>In any case, now that you know, now you can avoid using Calmail&mdash;if you value your privacy.</p>
<p>Ironically, GMail may be one of the most secure email system to use, as far as privacy goes, because headers from GMail is fairly clean from any private information. Or, I guess if you are like me, you run a computer server at work, on which you run a bunch of things like websites and email servers so whose IP address isn&#8217;t exactly a state secret. You can proxy everything through that server (like I did here) or run your mail clients and what-not on that server.</p>
<p>No matter what you do, just remember: when you send an email through Calmail, you announce to your recipient what your IP address is at that moment. Don&#8217;t send that email if you are not comfortable with that.</p>
]]></content:encoded>
			<wfw:commentRss>http://bkpark.com/2009/11/29/calmail-leaks-ip-addresses/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

