Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Uh... clever? I had to scroll back up and double-check the date to make sure this article wasn't 10 years old.

Is the author not aware that for the last decade or so every email program/service in the world prompts the user to load images to purposely thwart image tracking?



Also, didn't Gmail start caching images on google servers such that tracking can't happen even if you display images? (Of course, google could track you but they already run the client so no big loss there.)


They started caching images, but since open tracking pixel URLs are unique (after all, that's how they track an individual recipient) and Google only caches the image if you open the mail, essentially you still get tracking. You just don't get to count how many times the email is opened or the length it's opened (a common trick is to leave the connection open to see how long the client keeps the request open).


Do you evidence for your claim that google only caches the image if you open the mail? That seems to defeat the entire purpose of the feature.


Yes, that I don't have 100% Gmail open rates reported in Mailchimp. Indeed, open rates barely changed at all (they went up just slightly since I guess everyone now has images enabled by default).


> Is the author not aware that for the last decade or so every email program/service in the world prompts the user to load images to purposely thwart image tracking?

While that is true, people say "yes" because things don't display properly. Often elements like emoticons and whatnot are also remote images!

"Display remote images? Yes/No" is an all or nothing proposition, in other words.

The e-mail client, rather, should determine which images will display in a visible way and reject all others even if the users says Yes. It should not fetch images whose tags don't specify a width or height, or that specify one less than 16x16 pixels, and those that are positioned such that they will be clipped, or clipped by something else, so that even if filled with fetched content, they will not be visible. Basically: calculate the set of image tags that refer to images which will be obviously visible to the user. Prompt for those, and do not fetch the rest regardless of the answer.


At least recent versions of Thunderbird do allow domain-by-domain loading.

Of course, the standard user has no idea what that means, how to judge where the email comes from, or what any of the options mean beyond "see the pretty pictures", but, hey, one step at a time.


Gmail controls this permission per sender. Nobody savvy enough to read Wired would use a mail system that was broken in the described way.


When I checked last, there are some popular email apps that don't provide an option to disable automatic attachment downloading - like Dropbox's Mailbox and Google's Inbox.


Doesn't google pre-download all images before hand and serve the user a cached copy?


Google apparently still leaks the initial opened and time data.


For those who care, the Gmail app still has the option to not load images. It's why I still use it over Dropbox Mailbox, Google Inbox, and Microsoft Outlook (Acompli).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: