Live data from Hacker News

Spy pixels in emails 'have become endemic'

bbc.co.uk

151–160 of 341 posts

Re: Spy pixels in emails 'have become endemic'

#151

Earlier quoted context omitted.

I'm not sure why people would be wary of clicking the unsubscribe link on something they explicitly subscribed to in the first place. I mean, they trusted you enough to give you their email address to subscribe in the first place, right? The only scenario I can think of is when people didn't intentionally subscribe or were coerced into subscribing and those newsletters can go to hell and fully deserve to be marked as…

I've unsubscribed before only to find myself subscribed to a bunch of similar things instead. Clicking a link confirms your address reaches a person and is therefore worth spamming. Plus the risk of phishing. Plus the dark patterns in the unsubscribe UI.

> Clicking a link confirms your address reaches a person and is therefore worth spamming

I think this is received wisdom that might have been true 20 years ago, but doesn’t stand up to scrutiny.

Re: Spy pixels in emails 'have become endemic'

#152

Earlier quoted context omitted.

I'm not sure why people would be wary of clicking the unsubscribe link on something they explicitly subscribed to in the first place. I mean, they trusted you enough to give you their email address to subscribe in the first place, right? The only scenario I can think of is when people didn't intentionally subscribe or were coerced into subscribing and those newsletters can go to hell and fully deserve to be marked as…

I run https://www.emailprivacytester.com - People will visit my site, enter their email address, receive an email from me, click the "confirm" link in that email, then once confirmed that they control the email address, go to another section of the website and send themselves a test email. Then they will go into their email client and click the spam button on both of the emails that I sent them. The confirmation emai…

They do that because they have no guarantee that a site will respect an “unsubscribe” request, and it wouldn’t drag them through a shady multi-step “but why” dialog, and it wouldn’t send them another email with “Dear sucker, we see your request and sadly have to react, but you know how these servers work, right? Wait for a week or twelve before all our systems are aware that you wanted to unsubscribe from one of our many non-enumerable spam channels. And if they don’t, feel free to repeat, best regards”. Fair players like you are so rare these days, and to them you are yet another nobody who gets rich on ads and spam.

Re: Spy pixels in emails 'have become endemic'

#153

Earlier quoted context omitted.

Honestly, if people get what they want and a lot of tracking is stopped they'll probably find the quality of their internet experience reduced. There are lot of things companies do that privacy people dislike but is only there to improve user experience.

Tracking is already stopped for lots of people through plugins, containers etc., and we like it. It doesn't actually change the user experience, except maybe to stop some of the creepier features working, and speed things up in general.

But you haven't actually felt the effects because they're able to do enough of it to improve UX. And this thread is full of people complaining that once they stopped tracking in emails they were getting unsubscribed from newsletters they were reading. So, not everyone is enjoying it.

Re: Spy pixels in emails 'have become endemic'

#154
post #31

Earlier quoted context omitted.

Isnt the proxy downloading and caching the image before the user opens the email? If so doesnt that prevent tracking if/when the user actually opens the email?

It does not. That's how it should work, but it does not work that way. It downloads them on demand if and when the user views an email. So it protectes the users IP address from the spammer/marketter, but not the fact that the message was viewed nor when it was viewed.

The amount of email that is sent and not opened would probably destroy the origins - might be ok. But it would waste a huge, huge amount of bandwidth and CPU to download them which would open up an attack vector (DoS) on any email service that did this. Images can be legitimately very big...

Re: Spy pixels in emails 'have become endemic'

#155
post #50

If you're running a mail newsletter, this tracking is pretty important. You're supposed to stop sending emails to someone who's not interacting with them, or you get an extra point towards being flagged as spam. Since people are already weary of clicking the unsubscribe link and instead casually mark everything as spam, every little bit towards keeping your reputation counts. It's a damned if you do, damned if you do…

Wait, does this mean that if I legitimately subscribe to a mailinglist I want, but I use a mailreader that doesn't load these tracker pixels, I will get kicked off the mailinglist? That is terrible.

I'm surprised that people still press spam for a double opt-in mailinglist. Double opt-in is the right way to subscribe, click unsubscribe is the right way to unsubscribe.

People reporting that as spam should probably have their spam reports ranked as illegitimate.

However, plenty of mailinglists are spam. Sometimes I get newsletters in a language I don't even know. Maybe someone entered a wrong email somewhere and the list never verified that it's correct. Sometimes you subscribe to a bunch of spam if you forget to uncheck a checkbox somewhere. That stuff is not something the user explicitly asked for, and the user may have a hard time distinguishing it from spam or phishing, so I can understand reporting that as spam.

Re: Spy pixels in emails 'have become endemic'

#156
post #50

If you're running a mail newsletter, this tracking is pretty important. You're supposed to stop sending emails to someone who's not interacting with them, or you get an extra point towards being flagged as spam. Since people are already weary of clicking the unsubscribe link and instead casually mark everything as spam, every little bit towards keeping your reputation counts. It's a damned if you do, damned if you do…

> You're supposed to stop sending emails to someone who's not interacting with them, or you get an extra point towards being flagged as spam. It's a bit more complicated than that. There are many reasons why a pixel may not fire but the email is still read, and there are many ways pixels can record false positives. Relying on email opens is really not a good measure of engagement. Sadly, inbox placement is almost imp…

Relying on email opens is really not a good measure of engagement.

It's not, but it's what we have. It's a bit like how counting podcast listeners based off of downloads is a terrible system too but it's all they have to go on (I'm subbed to hundreds and don't listen to 99% of episodes).

Re: Spy pixels in emails 'have become endemic'

#157
post #108

For anyone using pixels: Under the GPDR tracking pixels require explicit consent as they monitor user behaviour. This _cannot_ be covered with any implicit forms of consent like 'you subscribed to the newsletter'.

How many complaints have you filed with your local data protection authority about this?

Re: Spy pixels in emails 'have become endemic'

#158

Earlier quoted context omitted.

And also because of this, if you're blocking tracking pixels in a privacy conscious way you often get removed from the mailing list without any notice, which is very frustrating. Or you get one of those mail saying "We are removing you from the list because you don't read our newsletter", often without offering any other confirmation signal. Basically they says "Let us track you or you are out of this list". And this…

Counter-anecdote: I’ve heard of people saying this, but never experienced it, except for the Daily UI mailing list that I once signed up for and received one email, but no more—until over a year later I tried loading remote images on that first email, then it switched to the daily progression.

Terrible. Just send a verification email that says explicitly that you need to either respond to it, click a button or load the images on that email to receive further mails.

Leaving people in the dark about this sort of requirement should be considered an anti-pattern.

Re: Spy pixels in emails 'have become endemic'

#159

Earlier quoted context omitted.

There should be an unsubscribe email header for newsletters. Then it could even be a feature for mail clients.

I can't tell if it's sarcasm. Just in case it is not: there is already such a standard header, it's List-Unsubscribe and it's a used by all mailing lists and "legit" ads I can think of. (And may of the "high quality" spam too.) https://tools.ietf.org/html/rfc8058 It is unfortunately not implemented by most email clients.

Maybe email clients should show that unsubscribe button then. And also, when someone reports something as spam that has a legitimate unsubscribe link, offer to unsubscribe instead.

Re: Spy pixels in emails 'have become endemic'

#160
post #158

Earlier quoted context omitted.

Counter-anecdote: I’ve heard of people saying this, but never experienced it, except for the Daily UI mailing list that I once signed up for and received one email, but no more—until over a year later I tried loading remote images on that first email, then it switched to the daily progression.

Terrible. Just send a verification email that says explicitly that you need to either respond to it, click a button or load the images on that email to receive further mails. Leaving people in the dark about this sort of requirement should be considered an anti-pattern.

People hate that as well, as can be clearly seen in the comments on this story. It's basically impossible to do right for everyone.
Post reply on HN