Earlier quoted context omitted.
GMail displays them. It uses a proxy for downloading, but I don't think that matters unless they're preloading all images unconditionally upon server-side receipt of the message. Apple's macOS Mail.app client displays external images by default, as does their iOS app.
Maybe the proxy removes metadata such as useragent, but often the pic urls contain uniquely identifiable information, eg a number that is unique to that email that received the email. That way you still leak that it is opened, how often, etc (unless they cache, I don't know).
Spy pixels in emails 'have become endemic'
31–40 of 341 posts
Re: Spy pixels in emails 'have become endemic'
#32I can't think of any email clients that automatically download external images by default. The article seems to be over-blowing the issue a bit.
Re: Spy pixels in emails 'have become endemic'
#33https://mailtrack.io/en/ yeah. webmails open images by default so companies like these are charging top dollar for the priveldge
Re: Spy pixels in emails 'have become endemic'
#34Earlier quoted context omitted.
Maybe the proxy removes metadata such as useragent, but often the pic urls contain uniquely identifiable information, eg a number that is unique to that email that received the email. That way you still leak that it is opened, how often, etc (unless they cache, I don't know).
Isnt the proxy downloading and caching the image before the user opens the email? If so doesnt that prevent tracking if/when the user actually opens the email?
Re: Spy pixels in emails 'have become endemic'
#35I can't think of any email clients that automatically download external images by default. The article seems to be over-blowing the issue a bit.
Did you know that Hey allows you to block tracking pixels for the low price of $99/year? Now you do!
Not the kind of thing I'd expect to see from the publicly funded BBC.
Re: Spy pixels in emails 'have become endemic'
#36Re: Spy pixels in emails 'have become endemic'
#37Earlier quoted context omitted.
How? https://jioegijogeijesgioegeg.tracking.example.com/niowefioe.png?sdgsdbuegiu=rojpopwmrmwk has four places to store unique information. Does Gooogle's proxy remove all of them?
Download via a proxy and cache the image when you receive the e-mail. It's processed in the queue and opened. Was it the user? Did it hit Inbox? Where did it got opened? When it's opened? How many times it opened? All these information's reliability got out of the window with a single optimization. You can't know how this mail was processed and it's fate. So, your tracking pixel and URL returned something useless to…
Edit: oh :(
Re: Spy pixels in emails 'have become endemic'
#38Anyone knows if pihole blocks those addresses?
https://github.com/apparition47/MailTrackerBlocker/blob/main...
https://gist.github.com/dhh/360f4dc7ddbce786f8e82b97cdad9d20
https://gist.github.com/leggett/8c2ab9735037cb66c218fdbe898d...
Re: Spy pixels in emails 'have become endemic'
#39HTML emails already use only a subset of HTML, so I don't understand why it wasn't trimmed down more to only allow images as data URLs or encoded in Base64.
Re: Spy pixels in emails 'have become endemic'
#401. Helps to prune users who never open emails thus giving you a smaller more engaged list.
2. Helps to see if the content they are sending to users is leading to engagement so they can send better emails next time.
Yes, yes I know. Why even send emails in the first place.
All email marketing is not evil.
But legitimate marketers have businesses to run in the real world and without these little pixels they would be sending un-targeted and mostly useless marketing messages to legitimate subscribers.