Live data from Hacker News

Spy pixels in emails 'have become endemic'

bbc.co.uk

321–330 of 341 posts

Re: Spy pixels in emails 'have become endemic'

#321
post #70
post #32

Earlier quoted context omitted.

Apple mail will load them if you forward an email, even if you have remote images turned off. (last I checked)

Can Little Snitch and similar software be used to stop images, pixels, from loading and from being sent on a reply or forward?

yes, but although little snitch has managed to survive on macos, on ios you have no thing to verify or protect you.

Re: Spy pixels in emails 'have become endemic'

#322

Earlier quoted context omitted.

> Clicking a link confirms your address reaches a person and is therefore worth spamming I think this is received wisdom that might have been true 20 years ago, but doesn’t stand up to scrutiny.

I use unique email addresses for everything, so I know where emails come from. More than once in the last two years I have unsubscribed from lists using the unsubscribe link, only then to have that email address received emails from new sources. So for me, it does stand up to scrutiny, it still happens.

I don’t think you’ve proved implication here though; as plausible an explanation is simply that the original source has sold your information on regardless?

Re: Spy pixels in emails 'have become endemic'

#323
post #320
post #317

Earlier quoted context omitted.

Most people want images in their email to work

It's as easy as doing it the exact same way Hey does. "We blocked external trackers in this email, click here to learn more."

I'm curious how they're doing it. Without having used their product, I gather that they're blocking certain known trackers and/or checking for tracking pixels directly. But it's not hard to put a unique tracking link on any arbitrary image which is part of the email's content. The only full defense is turning off all images.

edit: apparently they automatically cache the images on delivery, which should work. This is really a change that needs to come from the mail providers so good on them. As long as they don't try and assume what the user is interested in like Gmail does, they can drop tracking all they want.

Re: Spy pixels in emails 'have become endemic'

#324

Earlier quoted context omitted.

I use unique email addresses for everything, so I know where emails come from. More than once in the last two years I have unsubscribed from lists using the unsubscribe link, only then to have that email address received emails from new sources. So for me, it does stand up to scrutiny, it still happens.

I don’t think you’ve proved implication here though; as plausible an explanation is simply that the original source has sold your information on regardless?

It's the timing that makes it suspicious. It's exactly for this reason that I usually don't click the "unsubscribe" link for the first few emails I get. After all, if it's a one-off, why bother?

But I have scripts that count them, and when they get to five I then make the decision. Again, sometimes I continue simply to bin them, but sometimes I click the unsubscribe link. Mostly then they stop and there's no additional problem, but more than once that address has been used on other spam emails, and only after the unsubscribe.

Do you have actual evidence that it doesn't happen? You might, as others have, be arguing that it's not worth the spammers' effort. But setting up a script triggered by an unsubscribe is pretty trivial, and emails can then be sold at a premium, accompanied by a certificate of sorts that the address is valid.

So maybe it is worth their while.

Re: Spy pixels in emails 'have become endemic'

#325
post #254

Can someone explain how a tracking pixel works? How is it different to simply a unique image href url for each client? Why does the image itself need to be different?

If I understand this correctly, the unassuming image/jpeg/png/gif/pixel is embedded in the email, it's the same color as the background so the user wont notice it. The image itself which has a unique link for each recipient, is hosted in the senders servers, so when they receive the request for the image, they read the HTTP headers for information such as IP address for location, depending on how many requests they g…

Right. I somehow interpreted it to mean a pixel in an existing image on the email, not some random pixel image.

Which makes me wonder why they don't just embed normal images that the user would see, but add something to the href that the server can interpret as a unique id. Either way, email clients that block images will break the technique.

Re: Spy pixels in emails 'have become endemic'

#326
post #317
post #313

Earlier quoted context omitted.

All it would take is a single default configuration change by Apple, Microsoft, or Google. It is not crazy at all to think that Apple would change the default setting to block loading remote content.

Most people want images in their email to work

Inline images. Faster loading, and will still work when I look at the email years later when all the img links have rotted.

Re: Spy pixels in emails 'have become endemic'

#327
post #320

Earlier quoted context omitted.

It's as easy as doing it the exact same way Hey does. "We blocked external trackers in this email, click here to learn more."

I'm curious how they're doing it. Without having used their product, I gather that they're blocking certain known trackers and/or checking for tracking pixels directly. But it's not hard to put a unique tracking link on any arbitrary image which is part of the email's content. The only full defense is turning off all images. edit: apparently they automatically cache the images on delivery, which should work. This is…

That is going to lead to it appearing that people have high email engagement which will cause them to be on more mailing lists and at higher frequency than they otherwise would be.

Re: Spy pixels in emails 'have become endemic'

#328
post #325

Earlier quoted context omitted.

If I understand this correctly, the unassuming image/jpeg/png/gif/pixel is embedded in the email, it's the same color as the background so the user wont notice it. The image itself which has a unique link for each recipient, is hosted in the senders servers, so when they receive the request for the image, they read the HTTP headers for information such as IP address for location, depending on how many requests they g…

Right. I somehow interpreted it to mean a pixel in an existing image on the email, not some random pixel image. Which makes me wonder why they don't just embed normal images that the user would see, but add something to the href that the server can interpret as a unique id. Either way, email clients that block images will break the technique.

There are certainly companies doing this already. The only advantage of a tracking pixel is if your email content doesn't have any images already. And I guess it sounds scarier for a headline.

Re: Spy pixels in emails 'have become endemic'

#329
post #301

Earlier quoted context omitted.

If it's allowing images it's allowing tracking, unfortunately.

Hey's solution is pretty smart. Their servers open the image and cache it as soon as the email goes through their servers. That way the pixel data is garbage. If you open the email multiple times it gets the images from Hey's cache.

Interestingly enough this is also what gmail does, however, then they notify the origin server on every email open even though they're serving the cached version, pure evil.

Re: Spy pixels in emails 'have become endemic'

#330

Earlier quoted context omitted.

And also because of this, if you're blocking tracking pixels in a privacy conscious way you often get removed from the mailing list without any notice, which is very frustrating. Or you get one of those mail saying "We are removing you from the list because you don't read our newsletter", often without offering any other confirmation signal. Basically they says "Let us track you or you are out of this list". And this…

Hell, my credit card company reverts to sending me paper statements if I haven't viewed their web bug in a long enough time. Doesn't matter that I use this advanced tool called a calendar to download the statement every month from their website. So my reward for protecting my electronic privacy is to have my privacy violated through the USPS.

>So my reward for protecting my electronic privacy is to have my privacy violated through the USPS.

You think the USPS is reading your credit card statements?

Post reply on HN