Back in the day, some systems used to acknowledge the request for a read receipt by default giving them the ability to determine if a number was actively watched.
Hopefully everything has it disabled by default these days.
Same for SMS read receipts.
That's still true for both email and text messages.
Just opening text messages can infect your phone too. In one case, iphone users didn't even have to open the message (https://www.bleepingcomputer.com/news/security/apple-zero-cl...).
There have been similar problems with outlook allowing unread email to infect a device (https://www.csoonline.com/article/3486789/microsoft-outlook-...)
It doesn't matter what the platform is, spam is toxic and should be handled carefully and as little as possible.
Unless the behavior has changed (maybe it has)?
As an example, consider what happens when a user sends a link to a website over iMessage. In that case, the sending device will first render a preview of the webpage and collect some metadata about it (such as the title and page description), then pack those fields into an NSKeyedArchiver archive. This archive is then encrypted with a temporary key and uploaded to the iCloud servers. Finally, the link as well as the decryption key are sent to the receiver as part of the iMessage. In order to create a useful user notification about the incoming iMessage, this data has to be processed by the receiver on a 0-click code path. As that again involves a fair amount of complexity, it is also done inside BlastDoor: after receiving the BlastDoor reply from above and realizing that the message contains an attachment, imagent first instructs IMTransferAgent to download and decrypt the iCloud attachment.
⁽¹⁾ https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime...
I got 7 political spam texts today. I don't think the STOP is working.
Same thing
Your messaging client may helpfully request the url they sent you to show a url preview.
In an email, your client renders the html including img tags (yes, this can be disabled, and may not even be default for most people anymore; it’s still a thing)