Live data from Hacker News

An easier way to get your logo in the inbox: Google's latest BIMI changes

valimail.com

11–20 of 25 posts

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#11
post #9
post #6

Earlier quoted context omitted.

Some email platforms already cache images to prevent tracking.

Let me guess: Those platforms just happen to be web-based, so the platform owners can track users there anyway?

Any email provider can track you pretty successfully whether web based or using another protocol such as IMAP. Most email is at best protected by encryption only while in transit after all. For personal email you get to choose your email provider and whether you are ok with them tracking you or trust them not to track you.

But an example of a non web based email client which provides privacy protections regarding images in email is Apple Mail and its mail privacy protection features.

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#12
post #11
post #9

Earlier quoted context omitted.

Let me guess: Those platforms just happen to be web-based, so the platform owners can track users there anyway?

Any email provider can track you pretty successfully whether web based or using another protocol such as IMAP. Most email is at best protected by encryption only while in transit after all. For personal email you get to choose your email provider and whether you are ok with them tracking you or trust them not to track you. But an example of a non web based email client which provides privacy protections regarding ima…

And Apple Mail displays BIMI images? Does it cache them?

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#13
Emojis are an abomination in email subjects and authors but now you want to deliberately add more colors and corporate branding. Fuck you google. Good thing I say as far away from the web interface as possible. Too bad thunderbird renders emojis in color.

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#14
post #12
post #11

Earlier quoted context omitted.

Any email provider can track you pretty successfully whether web based or using another protocol such as IMAP. Most email is at best protected by encryption only while in transit after all. For personal email you get to choose your email provider and whether you are ok with them tracking you or trust them not to track you. But an example of a non web based email client which provides privacy protections regarding ima…

And Apple Mail displays BIMI images? Does it cache them?

Whether Apple Mail supports BIMI is not really relevant since my original comment was regarding email.platforms supporting caching of images and not BIMI specific. If an email client supoorts caching of images extending that to also include BIMI logos while adding BIMI support is minimal effort.

That being said Apple Mail has supported showing BIMI logos since iOS 16 and macOS Ventura. Do they use caching for doing so when mail privacy protection is enabled as they do for other images? I have not specifically done an in depth dive to determine but what exactly would the motivation be for Apple to bypass the image caching functionality for just this type of images?

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#16
post #15

BIMI needs an LetsEncrypt equivalent of VMC to take-off. It's prohibitively expensive for small businesses.

While I enjoy Google relaunching EV certs under another name to avoid it was just wrong about claiming they were useless and a bad idea... the cost is the point.

One of the biggest things people just don't get is that anything cheap and automatic is easily exploitable at scale, and things expensive and manual are much harder to exploit, and generally speaking not worth the cost.

The reason people got the idea the lock icon in the browser meant a site was legitimate is because malicious sites rarely ever paid for a certificate. Now that certificates are free, of course, all phishing sites use Let's Encrypt.

EV and VMC certs are not generally speaking exploited simply because it isn't worth the cost to do so.

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#17
post #15

BIMI needs an LetsEncrypt equivalent of VMC to take-off. It's prohibitively expensive for small businesses.

While I enjoy Google relaunching EV certs under another name to avoid it was just wrong about claiming they were useless and a bad idea... the cost is the point. One of the biggest things people just don't get is that anything cheap and automatic is easily exploitable at scale, and things expensive and manual are much harder to exploit, and generally speaking not worth the cost. The reason people got the idea the loc…

Now that certificates are free, of course, all phishing sites use Let's Encrypt. Evaluating a website's legitimacy using SSL should not have been initiated by browser vendors. The messaging was wrong for the non-tech folks. They do not have anything to do with the site is fake/fraud/malicious. It was just the data-in-transit is safe or not.

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#18
post #17

Earlier quoted context omitted.

While I enjoy Google relaunching EV certs under another name to avoid it was just wrong about claiming they were useless and a bad idea... the cost is the point. One of the biggest things people just don't get is that anything cheap and automatic is easily exploitable at scale, and things expensive and manual are much harder to exploit, and generally speaking not worth the cost. The reason people got the idea the loc…

Now that certificates are free, of course, all phishing sites use Let's Encrypt. Evaluating a website's legitimacy using SSL should not have been initiated by browser vendors. The messaging was wrong for the non-tech folks. They do not have anything to do with the site is fake/fraud/malicious. It was just the data-in-transit is safe or not.

That's not my point: My point is that it became a real world tendency because it was pretty accurate: The malicious websites weren't paying for certificates.

If even some legitimate businesses balk at the cost of a VMC, your average scammer isn't going to drop that kind of money to get one either, especially since that cost is per-attempt and the approval is somewhat manual and likely involves humans seeing that it is wrong. But Bank of America will and hence the BoA logo on your email is pretty effective proof of legitimacy.

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#19
post #5
post #4

Earlier quoted context omitted.

Nobody wanted to buy them because the pricing was just ridiculous. I’m sure as hell not dropping 1.5 grand per year to display a freaking logo next to our mails. Had they been less greedy, this could have actually worked. But the way it is, it’s just a money grab from the same guys that used to sell you overpriced SSL certificates. > (BIMI is still a tracking pixel in every mail, BTW.) It doesn’t have to be. Email pl…

> Email platforms and clients should have servers in place to fetch logo images and cache them for their users; no direct correlation between users and requests in that case. So, all email servers and clients should be rewritten to avoid user tracking. Got it. This will never happen. If it came even close to happening, BIMI would magically and coincidentally grow a new user-tracking feature.

Coming to think of it… How would you implement user tracking with an image that must be served from a static URL defined in a DNS record and no request parameters to go by? Other than applying heuristics to match the time frame between sending a mail and receiving a request for the logo endpoint, I don't see how that would even work.

Additionally, platform providers have a huge incentive to cache the logos on their end—otherwise, they'd be required to verify the cryptographic signature every single time the logo were required to be drawn on the screen.

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#20
Perhaps I'm missing it but where do you actually buy and/or generate a CMC? I can't find any information on it.

Personally VCM is far too expensive for me at this time which is the only reason I haven't gotten one. But I certainly realize that putting a cost barrier to entry makes it less accessible to bad actors.

Post reply on HN