Live data from Hacker News

Dear Email Industry, We’ve Got a GDPR Problem

jacquescorbytuech.com

81–90 of 215 posts

Re: Dear Email Industry, We’ve Got a GDPR Problem

#81
post #45

Earlier quoted context omitted.

I don't think anybody would call generic emails "the email industry"

It’s only people who are in the email marketing industry who think that they are the email industry. The email industry would comprise a lot more than just marketing. You have email providers. You have email clients. You have non commercial newsletters. You have evites. You have e-cards. You have emails related to ticketing and reservations. The email industry is far larger than email marketing, despite what the emai…

I don't think email marketers think they encompass the entirety of the email industry, I was writing that article from the perspective of being an email marketer proposing something to my peers, ie others in the industry.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#82

Earlier quoted context omitted.

Not having marketing spammers is still better than having spammers and scammers

There's usually an unsubscribe button for marketing spam, and if there isn't I usually block their email. You can't do that with scammers / illegal spam.

Have you ever clicked one of those? I've never been sure if that wouldn't have worsened the situation by giving feedback that this is an active mail address managed by somebody.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#83
post #59

Earlier quoted context omitted.

This isn't bound to email marketing, unless you put all commercial communication dealt via email as email marketing.

I think any email that uses tracking pixels could be classified as either spam or marketing, or possibly both. If you use tracking pixels in your receipts, I think you're doing it wrong.

What about mandatory service announcements where you want to know if you reached clients before breaking them?

Re: Dear Email Industry, We’ve Got a GDPR Problem

#84
post #60
post #13

Earlier quoted context omitted.

We already have more than enough cookie popups and "heads up" emails whenever a company changes a comma in their ToS. GDPR is a bureaucratic madness and not something to be imitated. Want to educate users about privacy? do it with extensive educational campaigns, not by ruining everyone's experience on the web

It's not GDPR's fault that websites have awful user experience. If they really cared about privacy then they wouldn't use popups that required multiple clicks to remove tracking cookies.

If you have to untick boxes they're not in compliance with GDPR. If the button to not have tracking is gray and "accept all" is green, you're not in compliance. Many websites deliberately try to make it harder to opt-out, which is directly against the GDPR.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#85

Earlier quoted context omitted.

Do any email clients block tracking pixels? My understanding is that they block images by default but if you choose to view them you will load all the tracking pixels.

I guess I'm just not that familiar with HTML email anymore in general, and when I do read it I generally do not have images regardless. I always assumed that disabling 1x1px images would be first on the list of mitigations against this technique. I was under the impression that email clients, in addition to an option to block images in general (usually on by default for an address or origin), generally prevented the…

Depending on the platform used to send the email, it's trivial to change that pixel to any other image, ie a brand logo in the template.

On the whole, disabling images entirely is the only real defence against email tracking.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#86
post #7

Off-topic: I absolutely love the design choices made by the author of this site. It's the basic browser stylesheet with some nice refinements. A real triumph of minimalism and incredibly readable.

Font is too big.

Just make it smaller? Ctrl + mouse wheel down or minus in chrome.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#87

Earlier quoted context omitted.

Do any email clients block tracking pixels? My understanding is that they block images by default but if you choose to view them you will load all the tracking pixels.

I guess I'm just not that familiar with HTML email anymore in general, and when I do read it I generally do not have images regardless. I always assumed that disabling 1x1px images would be first on the list of mitigations against this technique. I was under the impression that email clients, in addition to an option to block images in general (usually on by default for an address or origin), generally prevented the…

The easiest way is to disable them by default which is why Thunderbird defaults to not loading from senders not yet whitelisted, which thankfully most HTML email has the text on the email, it's those darn emails that have all the text in an image that I get suspicious of and delete (usually spam / probably malware). It would be nice to see plugins to block them for sure. I use Thunderbird for work, keep forgetting to use it for regular email. At least even webmail email services block pictures by default now, probably to prevent browser exploitation, never know when someone finds some rogue PNG exploit.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#88
post #49

Earlier quoted context omitted.

As an european who rejects ad trackers on every website, I can confirm that a good 95% of them are correctly implemented and will let you keep browsing. Some of them (usually americans with a poor understanding of why they even implemented that) will kick you out or ask you again on every page load until you accept. We need a standard for managing these controls on the browser side, which major browsers can then impl…

I find that some vendors will have a section for "information storage and access" and list both the cookie used to remember your gdpr setting and cookies from doubleclick in there. Or the opt out page just leads to instructions to disable cookies in your browser.

Every single website seems to have a slightly different layout for the permission manager thing, even when the software for multiple websites is (in name) the same software developed by the same company. Why? Tricking the user into accepting something they wouldn't want to seems to be a major reason. It drives me nuts. If there was a single permission manager whose layout is controlled by the Firefox devs this wouldn't be a problem.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#89

Earlier quoted context omitted.

Not having marketing spammers is still better than having spammers and scammers

There's usually an unsubscribe button for marketing spam, and if there isn't I usually block their email. You can't do that with scammers / illegal spam.

Marketers, spammers and scammers are the same thing - sources of unsolicited e-mail, engaging with whom is not good for you. Eliminating marketers from the trio means only that much less messages to worry about.

Re: Dear Email Industry, We’ve Got a GDPR Problem

#90
post #7

Off-topic: I absolutely love the design choices made by the author of this site. It's the basic browser stylesheet with some nice refinements. A real triumph of minimalism and incredibly readable.

Font is too big.

Totally. Not sure though, why. 1.2em would have just been fine, but instead 24px (which is 1.5em) is too large.
Post reply on HN