Making Netscape 4 More Secure

Return to Uncle Vlad Advises

Return to DOIM Information Technology Update

How to turn off HTML formatting and Scripting in Mozilla

1. Disable Evil HTML Formatting of Your Messages

A few reasons why you should not use HTML formatted mail:

a) 99% of spammers use HTML formatting of messages.

b) Spammers may insert in messages the tags and scripts that would report to them that your
email address is active and would target you as a profitable victim.

c) Scripts inserted in messages may activate even if you disable scripting in messages
as is indicated in the next section (the bad guys are very inventive and Microsoft software is full of holes!)

d) Replying to your HTML formatted messages may create problems because like not
everybody drives the same car as you do, the same way, not everybody uses the same
email program as you do -- and these may work differently with HTML formatted messages.

e) Modern viruses steal your email identity and may spread infection with scripts in
HTML formatted messages sent as if by you to protected mailing lists.

f) Why should you emulate the bad guys-- spammers and virus infection terrorists?
If you behave this way in an airport, you will be persecuted by law!

Here is how you turn off HTML formatting in Netscape 4:

a) Select from the main menu bar Edit | Preferences and click on the plus sign in the
Mail & Newsgroups node. You will get the picture show below where you should click on
Formatting

Now you select the radio-buttons "Use the plain text..." and "Convert message into plain text..."
and proceed to Section 2.

2. Disable Scripting in Received Messages

Allowing active programing elements in an email or news message is perhaps one
of the most senseless things in computerized communications, introduced specifically to
promote commercials -- and the spam. As you understand the script (program) embedded
in a message may be a harmless sales trick (although annoying for many), yet the Internet
terrorists create malicious programs-scripts that infect computers with viruses or simply
crash them. Email programs would automatically launch these scripts releasing the
virus.

The picture below shows how to turn off this undesirable feature in Netscape 4 mail. Nevertheless
such methods do not reliably work in some other programs (MS Outlook) and even when
automatic launching scripts id disables may activate using security holes in Microsoft software
(typically in Microsoft Internet Explorer)

To turn off scripting in email and newsgroups you continue the sequence of changing
preferences Edit | Preferences and open up the Advanced node .

Here you may retain Enable Java check (although many security experts recommend turning it off:
Java is a program that a website loads and runs on your computer and may be malicious). You
get nothing good if you retain Java, only some adolescent jokes are implemented currently in
this way on websites.

You should retain Enable JavaScript check because many websites use Javascript for
navigation and dynamic design of pages (although creating havoc in the World Wide Web
because web designers are not good programmers and make numerous errors in scripting).

You MUST uncheck "Enable JavaScript for Mail and News"

Regarding cookies, accepting them may insert spyware and viruses on your computer,
while disabling cookies will create problems with connecting to many websites and with
using passwords for protected websites.

I accept all cookies but run a spyware detection program Ad-aware (free) and erase
all cookies on exiting the browser selecting "Disable cookies" before exit. (Do not forget
to turn them on again when you restart! )



Return to Uncle Vlad Advises
Return to DOIM Information Technology Update
1-13-2003