Yes. There was a bug a few years back though where they would display attached SVG images. These images could actually contain javascript, which left it vulnerable to XSS.
Why is zzz90210's post dead? Everyone knows about tracking via images. I never considered something like bgsound, probably a lot of other people did not as well. And it's the whole point of the article.
I've personally found loads of bugs in most of the major email clients and numerous webmail clients that cause them to make outgoing requests which can be detected (even with remote images disabled). Most of these are closed now. I have an automated tester which sends an HTML email with a bunch of tests like this bgsound one to your address which displays information about any callbacks. You can access it here: https…
yay, Gmail via Safari doesn't trigger any of the tests.
Yes. There was a bug a few years back though where they would display attached SVG images. These images could actually contain javascript, which left it vulnerable to XSS.
Why is zzz90210's post dead? Everyone knows about tracking via images. I never considered something like bgsound, probably a lot of other people did not as well. And it's the whole point of the article.
Took his karma negative, and once that happened his account was killed. As a new member you have to be careful about controversial statements until you build up a karma cushion.
That one used to trigger on Thunderbird and Apple Mail. It was fixed after I submitted the relevant bug reports.
Could you link to the fix/bug report? My mozilla-ppa(deb) Thunderbird 10.0.2 leaks like the Titanic after the iceberg. Gmail does much much better - a counter-intuitive result.
For me, Thunderbird had a dns-prefetch leak, but it's fixable via config.
Could you link to the fix/bug report? My mozilla-ppa(deb) Thunderbird 10.0.2 leaks like the Titanic after the iceberg. Gmail does much much better - a counter-intuitive result.
For me, Thunderbird had a dns-prefetch leak, but it's fixable via config.
An invasion of privacy does not cease to be an invasion of privacy just because a small group of deeply unethical people persist in it for years.
To win this fight, you need to convince users (and not just the techies on HN) to care. You aren't going to convince site operators to hamstring themselves over an issue their users don't care about. (Even if you do, unless you win over ever single site, all you will do is kill the ethical operators and leave the unethical one standing, let like antibiotic resistant bacteria. Is that really what you want? )
I think it would be pathetically easy to convince them to care, are you kidding? The problem is notifying them that it exists. Despite what many seem to think, people do care about their privacy and most people would find this extremely creepy. If your gmail alerted you that images could be used for this purpose then much more users would care. The problem is that users have no idea that this can occur and it is not fair to them in the least.
I just checked using a proxy -- there are no calls made to Facebook from gmail if you do not display images. (Checked using Chrome on a Mac.)
Did your proxy check DNS requests? Anyone who runs their own DNS could easily assign a unique subdomain for each email, embed links to that subdomain within the body of the email, and see if they get any DNS requests for those domains.