Live data from Hacker News

Spy pixels in emails 'have become endemic'

bbc.co.uk

301–310 of 341 posts

Re: Spy pixels in emails 'have become endemic'

#301
post #97

Hey [1] blocks tracking pixels but is smart enough to still show images. https://hey.com

If it's allowing images it's allowing tracking, unfortunately.

Hey's solution is pretty smart. Their servers open the image and cache it as soon as the email goes through their servers. That way the pixel data is garbage. If you open the email multiple times it gets the images from Hey's cache.

Re: Spy pixels in emails 'have become endemic'

#302
post #220

The major email clients could easily fix this. Instead of having choices to not display images and display images, the choices should be no images, show embedded images, and show remote images. The latter should come with a big privacy warning and require dismissing the warning for every single email. Problem solved.

Problem is that a core part of the content of many emails is the images. Many emails I get are useless without them, I get the subject to guess what it's about, and if I only have the text to go on it becomes a mystery. I get emails from Nintendo or Steam when a game in my wishlist goes on sale. I think they just show an image of the game in question. Maybe the game name is in the raw source, but it is equally likely the only thing I'd find in there is some internal game ID that means nothing to me.

The way to solve it is for the email provider to download the images for you, not when you open the email, but as soon as they receive it, and then display the images from their local cache. That way your IP never hits the pixel's home server, and you can see the email as it was intended to be seen.

Re: Spy pixels in emails 'have become endemic'

#303

This seems like thinly veiled marketing for Hey? "There's a Big Scary Problem you probably didn't know about, according to the founder of a service that solves that problem." [Image of what it looks like when the Big Scary Problem is solved by the service.] [Flattering image of the service founder, and a reference to the service as 'premium.']

Unfortunately, Hey is only decent at catching tracking pixels. I have my mail apps set to not load remote content, and it is obvious when an email tries to load some tracking garbage. With Hey there is no option to block remote content, but they attempt to prevent tracking and let you know, quite proudly, when they have. However, during my (evaluation of Hey I've noticed many, MANY, instances where the same email in Hey won't show any tracking pixels, but my mail app has obviously refused to load them.

I'm unimpressed with Hey's ability to prevent tracking.

Re: Spy pixels in emails 'have become endemic'

#304
post #296
post #289

Earlier quoted context omitted.

gmail presumably doesn't need to use a tracking pixel to determine if someone opened an email in the gmail interface...

But as a newsletter publisher they don't share that information with me. If I don't track it myself, eventually my engagement metrics will fall below a certain (undisclosed) level and everything goes to the spam folder.

That is surprising, and unfortunate. I believe this will ultimately have to change. The percentage of people blocking remote content will only go up. I block ALL remote content in my emails, and there is nothing that will convince me to stop doing that.

Re: Spy pixels in emails 'have become endemic'

#305
post #276
post #158

Earlier quoted context omitted.

Terrible. Just send a verification email that says explicitly that you need to either respond to it, click a button or load the images on that email to receive further mails. Leaving people in the dark about this sort of requirement should be considered an anti-pattern.

This is exactly what we do on our newsletters, but to be fair "not loading images due to privacy concerns" is an edge case and I could understand a lot of mailers not thinking about it or not caring about it.

It is literally the default in Thunderbird and probably configured in a bunch of outlook settings. It is not the default in gmail, but it is not rare.

Re: Spy pixels in emails 'have become endemic'

#306
post #161

Earlier quoted context omitted.

Gmail has this, it's in one of the dropdown menus. If you mark something with the right email header as spam, it even ask if you wish to unsubscribe instead. Spam companies often use this to check if the email address they've targeted is real because they get callbacks from legitimate users. I've only seen one or two legitimate uses of the header as far as I can remember.

in one of the dropdown menus As if gmail ui wasn’t already obscure af. They could make “don’t want this anymore” button that uses unsubscribe header first and if it doesn’t work, mark it as spam automatically. Many shady practices would disappear at that same moment, but who cares when making six figures a year. If only email could work as a modern instant messenger - no spam, reacting to explicit and well-defined us…

This isn't exactly what you proposed, but if a sender did include the list-unsubscribe header and you click "Report Spam" instead, Gmail will ask you if you want to unsubscribe as well.

Re: Spy pixels in emails 'have become endemic'

#307
post #304
post #296

Earlier quoted context omitted.

But as a newsletter publisher they don't share that information with me. If I don't track it myself, eventually my engagement metrics will fall below a certain (undisclosed) level and everything goes to the spam folder.

That is surprising, and unfortunate. I believe this will ultimately have to change. The percentage of people blocking remote content will only go up. I block ALL remote content in my emails, and there is nothing that will convince me to stop doing that.

Can you imagine the comment threads if google was secretly sharing inbox engagement data with marketers?

Anyway, it's been like this for years and the overwhelming majority of email clients load images by default so everyone mostly works around it. I don't think it's changing any time soon.

Re: Spy pixels in emails 'have become endemic'

#308

Earlier quoted context omitted.

Tracking is already stopped for lots of people through plugins, containers etc., and we like it. It doesn't actually change the user experience, except maybe to stop some of the creepier features working, and speed things up in general.

But you haven't actually felt the effects because they're able to do enough of it to improve UX. And this thread is full of people complaining that once they stopped tracking in emails they were getting unsubscribed from newsletters they were reading. So, not everyone is enjoying it.

And this is an example of worsening the user experience, where the previous comment is claiming that tracking improves it. There is absolutely no benefit to the user experience with the tracking here, only downsides; it is a punishment for disabling tracking. The only actual reason to track mail opens is pay-per-view advertising, everything to do with monetization and nothing to do with improving the UX.

Re: Spy pixels in emails 'have become endemic'

#310

Earlier quoted context omitted.

A trivial point, but I don't see that anyone's made it yet: one reason it's easier to report spam than to unsubscribe is that the UX for reporting spam is a lot better in Gmail. If I want to politely unsubscribe from a newsletter I have to: switch from the keyboard to the mouse, hunt for the link in the email and click it, switch contexts to the browser tab it opens, hunt for the primary action on the page, figure ou…

I'm honestly curious: are you talking about unsubscribing from a newsletter you explicitly subscribed to? The vast majority of "newsletters" I get today are from companies that assume that I want to keep hearing from them just because I once did a one-time transaction with them. And no, it's not because I forgot to uncheck the "I want to receive blah blah blah" checkbox. I'm careful to opt out whenever there's an opt…

A use case for manually unsubscribing is if you have an account on some site (say, an online retailer), and you don't want to run the risk that everything from them gets caught as spam, for example receipts or password resets that you do want to see.

Another is if you get signed up for multiple different streams of messages ("What's New!", "Tips to Get the Most out of X", "Company Communications", "Coupons", etc.) just by signing up for an account (and, as you point out, not actually opting in for any of them explicitly). Since Gmail does not always flag all of these different things as spam, it can be more efficient to go to the "unsubscribe" page and uncheck each of these streams yourself.

Post reply on HN