# Uh oh, opened spam. How bad could it get?

**URL:** <https://boards.straightdope.com/t/uh-oh-opened-spam-how-bad-could-it-get/724773>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [July 10, 2015, 2:51pm UTC](https://boards.straightdope.com/t/uh-oh-opened-spam-how-bad-could-it-get/724773 "2015-07-10T14:51:35Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Leaper](https://avatars.discourse-cdn.com/v4/letter/l/4bbf92/32.png) [@Leaper](https://boards.straightdope.com/u/Leaper)\
**Post date:** [July 10, 2015, 2:51pm UTC](https://boards.straightdope.com/t/uh-oh-opened-spam-how-bad-could-it-get/724773/1 "2015-07-10T14:51:35Z")

</div>

I was a dummy and opened an email in my iPad mail client from someone I didn’t recognize (I have a job interview today, and thought it might be related). Nope, spam.

In addition to letting the bad guys know I’m here, I also got repeated attempts to log me into stuff like FaceTime and other such apps. What are the chances it got into apps already opened? I know the virus threat is low, but could I have given away any passwords? I don’t think so, but I’d love to confirm.

---

<div class="post-metadata">

**Author:** ![Leaper](https://avatars.discourse-cdn.com/v4/letter/l/4bbf92/32.png) [@Leaper](https://boards.straightdope.com/u/Leaper)\
**Post date:** [July 10, 2015, 3:10pm UTC](https://boards.straightdope.com/t/uh-oh-opened-spam-how-bad-could-it-get/724773/2 "2015-07-10T15:10:22Z")

</div>

Just remembered one of the other password demands: iCloud. Thus my concern.

I also found myself unexpectedly logged out of iMessage, but I’d also just restarted the iPad, so I don’t necessarily connect the two.

---

<div class="post-metadata">

**Author:** ![Kenm](https://avatars.discourse-cdn.com/v4/letter/k/bc79bd/32.png) [@Kenm](https://boards.straightdope.com/u/Kenm)\
**Post date:** [July 10, 2015, 3:31pm UTC](https://boards.straightdope.com/t/uh-oh-opened-spam-how-bad-could-it-get/724773/3 "2015-07-10T15:31:31Z")

</div>

If you can turn off images loading automatically, any [**web bugs**](https://en.wikipedia.org/wiki/Web_bug) can’t be returned to the spammer.

> [@](#):
>
> In email  
> Web bugs are frequently used in email marketing as a way of determining which recipients open the email. Doing this allows marketers to know who has seen the promotion or announcement that they have sent, and allows them to back-off or re-engage appropriately.  
> Some email web bug tracking can be disabled by:  
> • Turning off HTML display, displaying text only.  
> • Turning off image display, while still using HTML.

---

<div class="post-metadata">

**Author:** ![Leaper](https://avatars.discourse-cdn.com/v4/letter/l/4bbf92/32.png) [@Leaper](https://boards.straightdope.com/u/Leaper)\
**Post date:** [July 10, 2015, 3:35pm UTC](https://boards.straightdope.com/t/uh-oh-opened-spam-how-bad-could-it-get/724773/4 "2015-07-10T15:35:40Z")

</div>

I did; I checked on that as soon as it happened. “Load remote images” is indeed off. Yet I saw images.

---

<div class="post-metadata">

**Author:** ![flight](https://avatars.discourse-cdn.com/v4/letter/f/bbce88/32.png) [@flight](https://boards.straightdope.com/u/flight)\
**Post date:** [July 10, 2015, 5:16pm UTC](https://boards.straightdope.com/t/uh-oh-opened-spam-how-bad-could-it-get/724773/5 "2015-07-10T17:16:41Z")

</div>

There are two kinds of images, those are sent with the message, and those that are retrieved from the web. The second kind are the remote images that are not loaded. The first kind is generally not dangerous.

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [July 10, 2015, 5:18pm UTC](https://boards.straightdope.com/t/uh-oh-opened-spam-how-bad-could-it-get/724773/6 "2015-07-10T17:18:10Z")

</div>

I just opened SPAM[sup]®[/sup].

It was delicious on a sandwich.

---

<div class="post-metadata">

**Author:** ![Xema](https://avatars.discourse-cdn.com/v4/letter/x/9de053/32.png) [@Xema](https://boards.straightdope.com/u/Xema)\
**Post date:** [July 11, 2015, 4:29am UTC](https://boards.straightdope.com/t/uh-oh-opened-spam-how-bad-could-it-get/724773/7 "2015-07-11T04:29:48Z")

</div>

> [@Johnny\_L.A](#):
>
> I just opened SPAM[sup]®[/sup].  
> It was delicious on a sandwich.

You really ought to serve eggs, spam, spam and bacon with that.

---

<div class="post-metadata">

**Author:** ![Curid1992](https://avatars.discourse-cdn.com/v4/letter/c/b9bd4f/32.png) [@Curid1992](https://boards.straightdope.com/u/Curid1992)\
**Post date:** [July 11, 2015, 7:47pm UTC](https://boards.straightdope.com/t/uh-oh-opened-spam-how-bad-could-it-get/724773/8 "2015-07-11T19:47:57Z")

</div>

> [@Leaper](#):
>
> I was a dummy and opened an email in my iPad mail client from someone I didn’t recognize (I have a job interview today, and thought it might be related). Nope, spam.
> 
> In addition to letting the bad guys know I’m here, I also got repeated attempts to log me into stuff like FaceTime and other such apps. What are the chances it got into apps already opened? I know the virus threat is low, but could I have given away any passwords? I don’t think so, but I’d love to confirm.

I don’t think your email address or iPad would have been compromised by this. However, you might want to be a bit on the safe side and consider system restoring (or factory resetting) your iPad.

Luckily I haven’t had any such bad luck with regards to spam email.

And make sure you mark any more spam like that, as spam, so the email client can learn what is good and what should be binned! 🙂

---

<div class="post-metadata">

**Author:** ![Mama\_Zappa](https://avatars.discourse-cdn.com/v4/letter/m/71e660/32.png) [@Mama\_Zappa](https://boards.straightdope.com/u/Mama_Zappa)\
**Post date:** [July 14, 2015, 8:06pm UTC](https://boards.straightdope.com/t/uh-oh-opened-spam-how-bad-could-it-get/724773/9 "2015-07-14T20:06:07Z")

</div>

It couldn’t hurt (aside from the pain-in-the-ass effect) to go through a round of password changes, especially for anything you routinely access on your phone.

Typo Knig’s phone was stolen a few weeks back, and we immediately changed anything he accesses routinely on it, and have been changing all our others as we have time. A vault helps with that (we have 1Password).

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [July 14, 2015, 8:11pm UTC](https://boards.straightdope.com/t/uh-oh-opened-spam-how-bad-could-it-get/724773/10 "2015-07-14T20:11:22Z")

</div>

You are worried about getting malware on an iPad?

The risk is as close to zero as you can imagine. iOS is completely sandboxed - third-parties can’t install applications (malware) without going through the App Store.

---

<div class="post-metadata">

**Author:** ![Spiderman](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/spiderman/32/230_2.png) [@Spiderman](https://boards.straightdope.com/u/Spiderman)\
**Post date:** [July 14, 2015, 8:22pm UTC](https://boards.straightdope.com/t/uh-oh-opened-spam-how-bad-could-it-get/724773/11 "2015-07-14T20:22:13Z")

</div>

> [@Johnny\_L.A](#):
>
> I just opened SPAM[sup]®[/sup].
> 
> It was delicious on a sandwich.

REPORTED!

SPAM[sup]®[/sup] & delicious in the same post??? Hell, SPAM[sup]®[/sup] & \*edible \*don’t belong together!
