Live data from Hacker News

Facebook uses bgsound to see if you have opened an email

plus.google.com

31–40 of 99 posts

Re: Facebook uses bgsound to see if you have opened an email

#31
post #8

This is pretty standard practice really... many e-mails will have a "tracking pixel" or similar. Facebook has this in their e-mails too: https://www.facebook.com/email_open_log_pic.php?mid= =blah" style="border:0;width:1px;height:1px;" />

Yes, but about 100% of email clients now don't load images -- whether webbugs or actual content -- because of that. This BGSOUND tactic certainly isn't standard practice, despite being an extension of a prior technique, extended specifically to get around the existing filter.

Last time I checked, the iOS email client had loading of remote images enabled by default. It's been a while though and I don't have an iOS device to be able to check on.

There was a time when the iOS email client (and Apple Mail too) would actually load content from the html audio and video tags, even when remote images were disabled.

Re: Facebook uses bgsound to see if you have opened an email

#32

I've personally found loads of bugs in most of the major email clients and numerous webmail clients that cause them to make outgoing requests which can be detected (even with remote images disabled). Most of these are closed now. I have an automated tester which sends an HTML email with a bunch of tests like this bgsound one to your address which displays information about any callbacks. You can access it here: https…

Ooh thanks for this :)

Got a "DNS Prefetch - Anchor" on Gmail

Re: Facebook uses bgsound to see if you have opened an email

#33
post #22

These sorts of tracking pixels or tracking items are long-standing methods of analytics gathering in the email marketing and delivery space. This is not an attack of privacy. They also know every click you make in that email as well. And of course they track the number of times you do these things. They also track that traffic anonymously if you forward the email to a third party who interacts with it. This is the sa…

It is an attack on privacy. The recipients don't expect to be tracked in this way, and you don't ask their permission before doing it (1). You're exploiting a weakness in the system.

It doesn't matter how many organisations are doing it, or how long they've been doing it, or how much money they make from it, or how useful the information is, or how good the "services" you provide are. It's still an attack on peoples personal privacy.

I don't expect to be able to convince you though. After all, you work for an ESP so you have to justify it to yourself somehow.

(1) hiding something away in the T&C's doesn't count.

Re: Facebook uses bgsound to see if you have opened an email

#34
post #32

I've personally found loads of bugs in most of the major email clients and numerous webmail clients that cause them to make outgoing requests which can be detected (even with remote images disabled). Most of these are closed now. I have an automated tester which sends an HTML email with a bunch of tests like this bgsound one to your address which displays information about any callbacks. You can access it here: https…

Ooh thanks for this :) Got a "DNS Prefetch - Anchor" on Gmail

That one used to trigger on Thunderbird and Apple Mail. It was fixed after I submitted the relevant bug reports.

Re: Facebook uses bgsound to see if you have opened an email

#35
post #32

I've personally found loads of bugs in most of the major email clients and numerous webmail clients that cause them to make outgoing requests which can be detected (even with remote images disabled). Most of these are closed now. I have an automated tester which sends an HTML email with a bunch of tests like this bgsound one to your address which displays information about any callbacks. You can access it here: https…

Ooh thanks for this :) Got a "DNS Prefetch - Anchor" on Gmail

Erk.

webOS email client leaks data all over the place.

Re: Facebook uses bgsound to see if you have opened an email

#36
post #8

This is pretty standard practice really... many e-mails will have a "tracking pixel" or similar. Facebook has this in their e-mails too: https://www.facebook.com/email_open_log_pic.php?mid= =blah" style="border:0;width:1px;height:1px;" />

Yes, but about 100% of email clients now don't load images -- whether webbugs or actual content -- because of that. This BGSOUND tactic certainly isn't standard practice, despite being an extension of a prior technique, extended specifically to get around the existing filter.

You don't list a source, but I'll propose a different stat. A survey in 2010 implied that only 33% of folks kept images on... but that's a wide jump from 100%.

http://www.clickz.com/clickz/column/1716214/disabled-images-...

Your point is right, that emailers are trying to get around the image blocking... But it's not that everyone turns off their images; some folks still keep them on. The question then becomes: what's the best way to block tracking pixels while still allowing consumers to experience attractive emails if they wish?

Re: Facebook uses bgsound to see if you have opened an email

#37
Given that this is a community of entrepreneurs, I'm surprised how unsympathetic a lot of people here are to this technique. Operating a business online, analytics are a very important part of understanding how your users interact with with your service and improving the quality of your correspondence. Facebook is just trying to identify which emails people respond to (i.e. open) most.

Re: Facebook uses bgsound to see if you have opened an email

#39
post #22

These sorts of tracking pixels or tracking items are long-standing methods of analytics gathering in the email marketing and delivery space. This is not an attack of privacy. They also know every click you make in that email as well. And of course they track the number of times you do these things. They also track that traffic anonymously if you forward the email to a third party who interacts with it. This is the sa…

It is an attack on privacy. The recipients don't expect to be tracked in this way, and you don't ask their permission before doing it (1). You're exploiting a weakness in the system. It doesn't matter how many organisations are doing it, or how long they've been doing it, or how much money they make from it, or how useful the information is, or how good the "services" you provide are. It's still an attack on peoples…

You could say the same for any website. What's different?

Re: Facebook uses bgsound to see if you have opened an email

#40
post #7

Plaintext e-mail is awesome, not just because it's readable, but because it's not vulnerable to these sorts of attacks. Incidentally, it's unfortunate that Sparrow doesn't have a 'force plain text' option. Even though I've checked 'prefer plain text', all Facebook e-mails are delivered in HTML. This might be a reason to switch back to Mail.app.

attacks? Run for your life, is mute-sound-email-tracking attack!
Post reply on HN