Live data from Hacker News

Spy pixels in emails 'have become endemic'

bbc.co.uk

311–320 of 341 posts

Re: Spy pixels in emails 'have become endemic'

#311
post #50

If you're running a mail newsletter, this tracking is pretty important. You're supposed to stop sending emails to someone who's not interacting with them, or you get an extra point towards being flagged as spam. Since people are already weary of clicking the unsubscribe link and instead casually mark everything as spam, every little bit towards keeping your reputation counts. It's a damned if you do, damned if you do…

>If you're running a mail newsletter, this tracking is pretty important. You're supposed to stop sending emails to someone who's not interacting with them In my experience, that's not what happens. My most recent experience with this was when I had gotten about half way through filling out my info for a service, I was sent an email with a price list, I opened it, looked at the email and decided to wait and compare pr…

You made the fatal mistake of being human in a spam-filled world.

Re: Spy pixels in emails 'have become endemic'

#312
post #50

If you're running a mail newsletter, this tracking is pretty important. You're supposed to stop sending emails to someone who's not interacting with them, or you get an extra point towards being flagged as spam. Since people are already weary of clicking the unsubscribe link and instead casually mark everything as spam, every little bit towards keeping your reputation counts. It's a damned if you do, damned if you do…

>If you're running a mail newsletter, this tracking is pretty important. You're supposed to stop sending emails to someone who's not interacting with them In my experience, that's not what happens. My most recent experience with this was when I had gotten about half way through filling out my info for a service, I was sent an email with a price list, I opened it, looked at the email and decided to wait and compare pr…

your problem is that you gave them your email address, not that they have tracking pixels in their emails

Re: Spy pixels in emails 'have become endemic'

#313
post #307
post #304

Earlier quoted context omitted.

That is surprising, and unfortunate. I believe this will ultimately have to change. The percentage of people blocking remote content will only go up. I block ALL remote content in my emails, and there is nothing that will convince me to stop doing that.

Can you imagine the comment threads if google was secretly sharing inbox engagement data with marketers? Anyway, it's been like this for years and the overwhelming majority of email clients load images by default so everyone mostly works around it. I don't think it's changing any time soon.

All it would take is a single default configuration change by Apple, Microsoft, or Google. It is not crazy at all to think that Apple would change the default setting to block loading remote content.

Re: Spy pixels in emails 'have become endemic'

#314
post #9

Earlier quoted context omitted.

GMail displays them. It uses a proxy for downloading, but I don't think that matters unless they're preloading all images unconditionally upon server-side receipt of the message. Apple's macOS Mail.app client displays external images by default, as does their iOS app.

I'm somewhat disappointed that Apple doesn't offer better default privacy for Mail. Perhaps they can't figure out a good solution to differentiate between benign images and tracking images; it does seem like it would be nearly impossible to do so, but I wouldn't mind a) blocking external images by default, b) per-sender/recipient settings, and c) clearly displaying "invisible" images and warning about them. Perhaps s…

The problem is that it's easy to serve a company logo at example.com/images/${unique_tracking_id}.png that also logs the tracking ID.

How do you tell a unique tracking ID from PR-IMG20190312-023045-logo-MARKETING-COPY(5).png?

Yes, HTML e-mail is dumb. But even instant messaging assumes the ability to load/preview images from the web at this point, so probably no real options at this point.

Re: Spy pixels in emails 'have become endemic'

#315
post #177

Earlier quoted context omitted.

> Since people are already weary of clicking the unsubscribe link and instead casually mark everything as spam, every little bit towards keeping your reputation counts. These slackers are the worst. Not only they cause trouble to legit email newsletters, they also affect the subscribers who want to read the email. Every time I check my gmail spam folder, I'll find at least 2-3 legit newsletters classified as spam bec…

you can blame email spam from the past for this; it used to be that clicking "unsubscribe" indicated to the spammer that they had reached a valid email, and that they should sell it on to everyone else to use. Personally, I end up clicking spam on a lot of stuff - they get one chance at unsubscribe. If I get asked to log in, or it redirects to anything other than a confirmation page, then I mark it as spam and forget…

How has this changed? Clicking unsubscribe stop spamming me remains some of the strongest signal a marketer can get that it's an email that's regularly read.

Re: Spy pixels in emails 'have become endemic'

#316

Earlier quoted context omitted.

The amount of email that is sent and not opened would probably destroy the origins - might be ok. But it would waste a huge, huge amount of bandwidth and CPU to download them which would open up an attack vector (DoS) on any email service that did this. Images can be legitimately very big...

I'm not convinced that this would be as big a problem as you're suggesting. If somebody is sending thousands of emails with html containing embedded images, the receiving system of those emails only needs to download each of those images once, and cache them. Unless they're using different URLs for each image for tracking purposes. Which would become pointless if the images were downloaded immediately. They could pro…

> They could probably get away with applying size limits to images too, and simply have placeholder/broken images if the images are unreasonably large.

Or only allow inline images.

Re: Spy pixels in emails 'have become endemic'

#317
post #313
post #307

Earlier quoted context omitted.

Can you imagine the comment threads if google was secretly sharing inbox engagement data with marketers? Anyway, it's been like this for years and the overwhelming majority of email clients load images by default so everyone mostly works around it. I don't think it's changing any time soon.

All it would take is a single default configuration change by Apple, Microsoft, or Google. It is not crazy at all to think that Apple would change the default setting to block loading remote content.

Most people want images in their email to work

Re: Spy pixels in emails 'have become endemic'

#318
post #312

Earlier quoted context omitted.

>If you're running a mail newsletter, this tracking is pretty important. You're supposed to stop sending emails to someone who's not interacting with them In my experience, that's not what happens. My most recent experience with this was when I had gotten about half way through filling out my info for a service, I was sent an email with a price list, I opened it, looked at the email and decided to wait and compare pr…

your problem is that you gave them your email address, not that they have tracking pixels in their emails

Yet i hadn't seen their prices until the email i received and i didn't receive the message assuring me their prices were the lowest until i'd actually opened the email. Like within a half hour of opening the email.

Re: Spy pixels in emails 'have become endemic'

#319

Earlier quoted context omitted.

Does Gmail download by default, whether you open the email or not?

Gmail caches by default. The catch is that Gmail caches all the same images from the same servers, so email marketers get around it by serving tracking pixels with obscure, unique URLs per individual. Geotargeting fails because it loads on GMail servers.

Yes, I understand the caching part. If Gmail proactively loads/cache the unique pixel before users open the email, then the email reporting is garbage. If they wait for the person to open the email, it is very interesting (even if repeat are not tracked).

Re: Spy pixels in emails 'have become endemic'

#320
post #317
post #313

Earlier quoted context omitted.

All it would take is a single default configuration change by Apple, Microsoft, or Google. It is not crazy at all to think that Apple would change the default setting to block loading remote content.

Most people want images in their email to work

It's as easy as doing it the exact same way Hey does. "We blocked external trackers in this email, click here to learn more."
Post reply on HN