Live data from Hacker News

Spy pixels in emails 'have become endemic'

bbc.co.uk

171–180 of 341 posts

Re: Spy pixels in emails 'have become endemic'

#171
post #160
post #158

Earlier quoted context omitted.

Terrible. Just send a verification email that says explicitly that you need to either respond to it, click a button or load the images on that email to receive further mails. Leaving people in the dark about this sort of requirement should be considered an anti-pattern.

People hate that as well, as can be clearly seen in the comments on this story. It's basically impossible to do right for everyone.

Honesty is always the best solution in my opinion. Send a verification email when someone subscribes. In the verification email, put a "yeah, I want this" link, and explicit "unsubscribe" link. If you also want to consider loading remote images to be valid verification, then say so explicitly in the verification email, and explain they may get unsubscribed if they don't either click the link or load the images. Explicitly unsubscribing will always override the other options.

Unspoken assumptions are always going to be wrong for some people.

Re: Spy pixels in emails 'have become endemic'

#172
post #9

I can't think of any email clients that automatically download external images by default. The article seems to be over-blowing the issue a bit.

GMail displays them. It uses a proxy for downloading, but I don't think that matters unless they're preloading all images unconditionally upon server-side receipt of the message. Apple's macOS Mail.app client displays external images by default, as does their iOS app.

You can disable the displaying in GMail.

Settings > Images > Ask before displaying external images

Re: Spy pixels in emails 'have become endemic'

#173
post #50

If you're running a mail newsletter, this tracking is pretty important. You're supposed to stop sending emails to someone who's not interacting with them, or you get an extra point towards being flagged as spam. Since people are already weary of clicking the unsubscribe link and instead casually mark everything as spam, every little bit towards keeping your reputation counts. It's a damned if you do, damned if you do…

So, you are saying that a blind person has to enable images that he can not see, but that can mess with his screen reader, in order to continue receiving your newsletter. There ought to be a law against such discrimination!

Re: Spy pixels in emails 'have become endemic'

#174
post #159

Earlier quoted context omitted.

I can't tell if it's sarcasm. Just in case it is not: there is already such a standard header, it's List-Unsubscribe and it's a used by all mailing lists and "legit" ads I can think of. (And may of the "high quality" spam too.) https://tools.ietf.org/html/rfc8058 It is unfortunately not implemented by most email clients.

Maybe email clients should show that unsubscribe button then. And also, when someone reports something as spam that has a legitimate unsubscribe link, offer to unsubscribe instead.

The macOS mail client shows an unsubscribe button.

Re: Spy pixels in emails 'have become endemic'

#175
post #50

If you're running a mail newsletter, this tracking is pretty important. You're supposed to stop sending emails to someone who's not interacting with them, or you get an extra point towards being flagged as spam. Since people are already weary of clicking the unsubscribe link and instead casually mark everything as spam, every little bit towards keeping your reputation counts. It's a damned if you do, damned if you do…

> You're supposed to stop sending emails to someone who's not interacting with them, or you get an extra point towards being flagged as spam Can you give a source/reference for this? I'd like to understand it more. I don't allow any remote content when I read emails, and I get quite a lot of regular newsletters. Why am I not being unsubscribed?

Here for example is Gmail's explanation:

https://support.google.com/mail/answer/81126?hl=en

CTRL-F "Send email to engaged users"

Some choice quotes:

- "Consider unsubscribing users who don’t read your messages."

- "Periodically send a confirmation message to users to make sure they still want to get your messages."

Re: Spy pixels in emails 'have become endemic'

#176
post #50

If you're running a mail newsletter, this tracking is pretty important. You're supposed to stop sending emails to someone who's not interacting with them, or you get an extra point towards being flagged as spam. Since people are already weary of clicking the unsubscribe link and instead casually mark everything as spam, every little bit towards keeping your reputation counts. It's a damned if you do, damned if you do…

> Since people are already weary of clicking the unsubscribe link Can you please elaborate on this? Do you mean people intentionally avoid this because it leads to the advertisers marking that as "read" and therefore a live user? Asking because I recently purged my old emails which had thousands of emails, they obviously never stopped sending even with zero interaction. But my method was to click the unsubscribe link…

I will tell you about my scam anecdote. I had been receiving an email once every few months for several years about the possibility to create an account on the website of my electricity provider. All of these emails were suspicious because of the very diverse and weird emails used by the sender, usually a slightly different one for each email. After a few years, I thought that these might be legit and clicked on the link provided in the email. I did not put in any personal information, and did not end up creating an account on their website. The week after, I received phone-text messages about some debt payment for electricity bills. I even received phone calls about it. Unless it is a coincidence, the people on the other side of this well-elaborate scam had to know my email and my phone number, and started the phone scam after they noticed I fell through the email scam. They tried to get me to pay their fake debt, which had always the same ID number, but a different amount of money to pay each time (sometimes lower than before). And they did not know my name: I know this for a fact thanks to the brief amount of time I spent on the phone with one of them. They thought I was someone else. They kept spamming my phone with text messages and phone calls around 8 a.m. or noon, once or twice per week. After ~9 months of them being blocked by me (I could only block the phone calls, the text message still went through, because they went through some kind of public advertising proxy with 5-6 digits), they completely stopped.

So yeah, rule number 1 of email protection should be: do not tell the scammer/spammer that you actually use this email address. In case of a doubt, click the "spam" button, block the address, but do not click "unsubscribe." Only click "unsubscribe" if you trust the sender, because once you have done it, your email address is suddenly worth a lot more, especially to bad actors.

Re: Spy pixels in emails 'have become endemic'

#177
post #50

If you're running a mail newsletter, this tracking is pretty important. You're supposed to stop sending emails to someone who's not interacting with them, or you get an extra point towards being flagged as spam. Since people are already weary of clicking the unsubscribe link and instead casually mark everything as spam, every little bit towards keeping your reputation counts. It's a damned if you do, damned if you do…

> Since people are already weary of clicking the unsubscribe link and instead casually mark everything as spam, every little bit towards keeping your reputation counts.

These slackers are the worst. Not only they cause trouble to legit email newsletters, they also affect the subscribers who want to read the email. Every time I check my gmail spam folder, I'll find at least 2-3 legit newsletters classified as spam because "It is similar to messages that were identified as spam in the past." At least gmail makes it easy to tell them apart from email marked as spam because they were deemed malicious.

Re: Spy pixels in emails 'have become endemic'

#178
post #171
post #160

Earlier quoted context omitted.

People hate that as well, as can be clearly seen in the comments on this story. It's basically impossible to do right for everyone.

Honesty is always the best solution in my opinion. Send a verification email when someone subscribes. In the verification email, put a "yeah, I want this" link, and explicit "unsubscribe" link. If you also want to consider loading remote images to be valid verification, then say so explicitly in the verification email, and explain they may get unsubscribed if they don't either click the link or load the images. Expli…

For subscribing, you just described double opt-in and that already happens.

When unsubscribing, users are very sensitive to any subsequent emails (just read the other comments in this thread). Sending an email to confirm their unsubscription might annoy a lot of the users, or will make them doubt that you're above board ("legit" newsletters boast about not sending any emails after unsubscribing, so this is a little red flag) - they will then flag that email as spam, and then we're back at square one.

They also get annoyed when you ask them to confirm that they still want to read the emails.

And Gmail will flag you if you keep sending the emails when they're not opening the emails.

I think there really is no good solution here.

Re: Spy pixels in emails 'have become endemic'

#179
post #171
post #160

Earlier quoted context omitted.

People hate that as well, as can be clearly seen in the comments on this story. It's basically impossible to do right for everyone.

Honesty is always the best solution in my opinion. Send a verification email when someone subscribes. In the verification email, put a "yeah, I want this" link, and explicit "unsubscribe" link. If you also want to consider loading remote images to be valid verification, then say so explicitly in the verification email, and explain they may get unsubscribed if they don't either click the link or load the images. Expli…

Part of the problem is that so many of the 'actions' people take with email are invisible to the sender: If the recipient marks you as spam, filters you to junk, blocks you as a sender or their client/provider auto-files you away somewhere, you as the sender get no indication of that. People won't click links in emails they've never opened, let alone read. 'Verification' tends to decay over time - even if I clicked that "yes, I definitely want this" link 6 months ago, it doesn't mean I haven't junked you since.

The reason "You haven't loaded images for n months" is used as a signal is that there's a cost in sending unwanted email to people, and there's often no other way to know if you're wanted or not.

Re: Spy pixels in emails 'have become endemic'

#180

Earlier quoted context omitted.

Redirecting through your own domain sounds like a good solution - not sure how I would do that with my Netlify/Nuxt based site though.

you'd have to control the domain DNS MX records. most registrars allow this unless you have an email package attached. i doubt these template sites allow for such control if your site is just a subdomain of theirs

Yeah, I use GSuite so have email too. Netlify is a host not really a template.
Post reply on HN