Live data from Hacker News

An easier way to get your logo in the inbox: Google's latest BIMI changes

valimail.com

1–10 of 25 posts

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#2
So, where a VMC was equivalent to an EV X.509 certificate, CMC is basically a normal certificate. I guess nobody wanted to buy VMCs, just like with EVs. But the mere existence of CMCs now lowers the value of a BIMI logo; if almost anybody can get a CMC, the logo can not be trusted. Might as well use X-Face, which is free.

(BIMI is still a tracking pixel in every mail, BTW.)

Previously: https://news.ycombinator.com/item?id=40873830>, https://news.ycombinator.com/item?id=32717105>, https://news.ycombinator.com/item?id=28196403>

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#4
post #2

So, where a VMC was equivalent to an EV X.509 certificate, CMC is basically a normal certificate. I guess nobody wanted to buy VMCs, just like with EVs. But the mere existence of CMCs now lowers the value of a BIMI logo; if almost anybody can get a CMC, the logo can not be trusted. Might as well use X-Face, which is free. (BIMI is still a tracking pixel in every mail, BTW.) Previously: https://news.ycombinator.com/it…

Nobody wanted to buy them because the pricing was just ridiculous. I’m sure as hell not dropping 1.5 grand per year to display a freaking logo next to our mails. Had they been less greedy, this could have actually worked. But the way it is, it’s just a money grab from the same guys that used to sell you overpriced SSL certificates.

> (BIMI is still a tracking pixel in every mail, BTW.)

It doesn’t have to be. Email platforms and clients should have servers in place to fetch logo images and cache them for their users; no direct correlation between users and requests in that case.

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#5
post #4
post #2

So, where a VMC was equivalent to an EV X.509 certificate, CMC is basically a normal certificate. I guess nobody wanted to buy VMCs, just like with EVs. But the mere existence of CMCs now lowers the value of a BIMI logo; if almost anybody can get a CMC, the logo can not be trusted. Might as well use X-Face, which is free. (BIMI is still a tracking pixel in every mail, BTW.) Previously: https://news.ycombinator.com/it…

Nobody wanted to buy them because the pricing was just ridiculous. I’m sure as hell not dropping 1.5 grand per year to display a freaking logo next to our mails. Had they been less greedy, this could have actually worked. But the way it is, it’s just a money grab from the same guys that used to sell you overpriced SSL certificates. > (BIMI is still a tracking pixel in every mail, BTW.) It doesn’t have to be. Email pl…

> Email platforms and clients should have servers in place to fetch logo images and cache them for their users; no direct correlation between users and requests in that case.

So, all email servers and clients should be rewritten to avoid user tracking. Got it.

This will never happen. If it came even close to happening, BIMI would magically and coincidentally grow a new user-tracking feature.

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#6
post #5
post #4

Earlier quoted context omitted.

Nobody wanted to buy them because the pricing was just ridiculous. I’m sure as hell not dropping 1.5 grand per year to display a freaking logo next to our mails. Had they been less greedy, this could have actually worked. But the way it is, it’s just a money grab from the same guys that used to sell you overpriced SSL certificates. > (BIMI is still a tracking pixel in every mail, BTW.) It doesn’t have to be. Email pl…

> Email platforms and clients should have servers in place to fetch logo images and cache them for their users; no direct correlation between users and requests in that case. So, all email servers and clients should be rewritten to avoid user tracking. Got it. This will never happen. If it came even close to happening, BIMI would magically and coincidentally grow a new user-tracking feature.

Some email platforms already cache images to prevent tracking.

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#7
post #4
post #2

So, where a VMC was equivalent to an EV X.509 certificate, CMC is basically a normal certificate. I guess nobody wanted to buy VMCs, just like with EVs. But the mere existence of CMCs now lowers the value of a BIMI logo; if almost anybody can get a CMC, the logo can not be trusted. Might as well use X-Face, which is free. (BIMI is still a tracking pixel in every mail, BTW.) Previously: https://news.ycombinator.com/it…

Nobody wanted to buy them because the pricing was just ridiculous. I’m sure as hell not dropping 1.5 grand per year to display a freaking logo next to our mails. Had they been less greedy, this could have actually worked. But the way it is, it’s just a money grab from the same guys that used to sell you overpriced SSL certificates. > (BIMI is still a tracking pixel in every mail, BTW.) It doesn’t have to be. Email pl…

To abuse the email system even more, wouldn't it be possible to add a header to the email with a base64 encoded image? I suppose with HiDPI, the image might need to have quite a high resolution. And then someone will find an exploit involving image decoding/displaying.. like one Outlook had years ago while parsing manipulated timestamps.

Edit: reading one example, the hosted image can be an SVG, so that would not be so heavy to be embedded into the header..

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#8
post #7
post #4

Earlier quoted context omitted.

Nobody wanted to buy them because the pricing was just ridiculous. I’m sure as hell not dropping 1.5 grand per year to display a freaking logo next to our mails. Had they been less greedy, this could have actually worked. But the way it is, it’s just a money grab from the same guys that used to sell you overpriced SSL certificates. > (BIMI is still a tracking pixel in every mail, BTW.) It doesn’t have to be. Email pl…

To abuse the email system even more, wouldn't it be possible to add a header to the email with a base64 encoded image? I suppose with HiDPI, the image might need to have quite a high resolution. And then someone will find an exploit involving image decoding/displaying.. like one Outlook had years ago while parsing manipulated timestamps. Edit: reading one example, the hosted image can be an SVG, so that would not be…

Such standards exist already:

1. The ancient “X-Face” header: 48×48 black or white pixels: https://en.wikipedia.org/w/index.php?title=X-Face&oldid=1220...>

2. The “Face” header, from 2005: 48×48 PNG image https://quimby.gnus.org/circus/face/>

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#9
post #6
post #5

Earlier quoted context omitted.

> Email platforms and clients should have servers in place to fetch logo images and cache them for their users; no direct correlation between users and requests in that case. So, all email servers and clients should be rewritten to avoid user tracking. Got it. This will never happen. If it came even close to happening, BIMI would magically and coincidentally grow a new user-tracking feature.

Some email platforms already cache images to prevent tracking.

Let me guess: Those platforms just happen to be web-based, so the platform owners can track users there anyway?

Re: An easier way to get your logo in the inbox: Google's latest BIMI changes

#10
I've read Google's announcement and I'm not sure why it's a Google announcement, the BIMI group published this change here:

https://bimigroup.org/announcing-common-mark-certificates/

But that document seems unfinished. It refers to there still being requirements to get a CMC, at at this time it tells you to go refer to a PDF where those requirements are documented. But that PDF is the old VMC documentation.

Post reply on HN