Privacy implications of email tracking [pdf]
senglehardt.com
senglehardt.com
The code and data for the study is available here: https://github.com/citp/email_tracking (measurement platform here: https://github.com/citp/OpenWPM).
We also just released a blog post that highlights the main results (and is a quicker read): https://freedom-to-tinker.com/2017/09/28/i-never-signed-up-f...
I warmly recommend you turn it on. There is no need to switch to text-only email clients just because of tracking.
The only option at that point is using the PixelBlock extension:
https://chrome.google.com/webstore/detail/pixelblock/jmpmfcj...
Still, would be nice if there was an overview in the settings page, and a possibility to wipe the entire whitelist at once
I've used Airmail for a long time with "Autoload Remote Images" off and thought it worked. Then couple months ago I installed Little Snitch and saw the client contacting all kinds of places. I had to explicitly deny connections to all other domains except my email provider's.
> senders may be able to know whether you've opened an email that has an image attached to a unique link
My limited understanding is that the load happens on first open, from Google's servers.
https://news.ycombinator.com/item?id=9237550
> mike-cardwell: a web app I wrote [...] Sends an email to you which checks to see how much stuff your email client is leaking
As eve-online has a shit ton of spies(and some people take this game very seriously) a large alliance was using self hosted images and logging ips that we're viewing those images. Through matching posts they were able to scout out alternate accounts and catch spies.
That's how we all heard about it at the time anyway, while technically fesable, I don't have first hand knowledge either way.
Although it did make me start to think about those emails with images and convinced me to turn them off by default ;-)
I do realise clicking tracking links still works but they are way more visible in plain text mode and it's not that hard to copy & paste the relevant part of the link.
Too bad most email clients have removed plain text rendering these days. I also haven't found a good mobile plain text email client yet.
MailMate has a really nice feature when you can read your mails in plain text by default and toggle the HTML version on a per mail basis with a shortcut.
eul [1] only has plain text rendering. It only supports Gmail right now, but a full-fledged email client is coming soon. A mobile app will be released in early 2018.
[1] https://eul.im
Same on GMail app.
Not too many metions of email clients except mutt and alpine.
But this is maybe what we get when most read emails in web apps from companies that want to track everything everyone do and think so they can show the adds that are least relevant
heaven.
2) Marketers should not rely on opens alone to determine who is inactive. Also look at clicks, and site activity from the past 6 months.
I occasionally do fire up Thunderbird but only for those extremely rare cases where I actually do need to be able to read an HTML e-mail.
text/html; elinks -no-connect -dump -dump-charset UTF-8 -dump-width 140 -default-mime-type text/html %s; needsterminal; copiousoutput;
For instance, why do we not see in every client a big warning at the top saying something like: “NOTE: YOU HAVE NEVER RECEIVED E-MAIL FROM THIS INTERNET LOCATION BEFORE.”? Heck, such messages should even be auto-quarantined to specific folders. It would go a long way to protect people from constantly opening spam.
And, why by default do they insist on making everything look “simple” and “clean” at the expense of helping users to do even the most basic validation? They show senders as short names like “Facebook” when CLEARLY the message is coming from facebook.spammer.com or whatever when you do even the slightest digging into the original message.
Why are “rules” so complex, since damn near everybody needs them for basic sanity? There ought to be a button in every message saying something like “Mark Every Future Message From This Sender as Junk”, and similar short-cuts.
Because that is way too dangerous a policy. Recently, I moved, and in creating online accounts for online bill pay, I got confirmation emails from each of my utilities. Saying that they're spam just because you've never received email from them would cause most people to be unable to find these confirmation messages.
> And, why by default do they insist on making everything look “simple” and “clean” at the expense of helping users to do even the most basic validation? They show senders as short names like “Facebook” when CLEARLY the message is coming from facebook.spammer.com or whatever when you do even the slightest digging into the original message.
Uh, my email client doesn't do that. If the email address isn't priorly known, it shows the email address instead of the display name.
> Why are “rules” so complex, since damn near everybody needs them for basic sanity? There ought to be a button in every message saying something like “Mark Every Future Message From This Sender as Junk”, and similar short-cuts.
Most spammers don't reuse the same email addresses. You end up with a lot of useless rules. Bayesian spam filtering is much more effective, for example, and requires very little user action.
It's not saying that they are spam. It's just saying that you never received a message from them. That account confirmation email you are expecting will be obviously marked, but that phishing email claiming to be from your bank will be marked too. You look at the mark and decide what to do.
Email clients probably don't do it because it is not as useful as it sounds. Impersonating email senders is not hard, so phishers will just do it.
> If the email address isn't priorly known, it shows the email address instead of the display name.
The only email client that I have ever seen doing that is the roundcube instance I configured on my VPS. I use several clients, nearly all of them either hide the sender address or decrease its relevance enough so that nobody sees them.
I'm in complete agreement with your comment about spam filtering. The only thing is that somehow, it feels like it worked better at the earlier 00's. Nowadays the training for your account will be dissolved in a huge set of unreleated data, so that anything specific for the spam you are receiving will never be reflected on the filter. That is both for marking things as spam and as not spam.
Inexperienced users want to be told what to do. You can't just throw information or warnings at them without giving them a way to act on it.
Combine that with the fact that if the users even read the warnings they are going to only read a sentence at most, or just the first option.
So when you show a warning like"you have never received email from this address before" users are going to ask what they should do. Is this dangerous? Did it come from my bank? I've had this bank for years! Does this mean the email is a hacker!?
If you say "it can be dangerous, but it also can be just a new email" that will be read as "yes this is dangerous" and now they will learn the hard way that it is safe, and your warnings will have less weight in the future (they were wrong about this being "a hacker" once, they might be wrong this time too!)
It's a really hard problem to solve, and the "easy way out" is to not show the information at all (no confusion if you just don't show it!) But that kind of just kicks the can to the user leaving them to determine if an email is "good" or "bad".
I'd still recommend disabling remote content by default since the tracking identifiers (the hash of your email address, etc) are present in the image URL. That's enough to continue to track the read and serve targeted content. See: https://web.archive.org/web/20170922213846/https://support.l...
The paper goes on to say that then you don't get to look at those e-mails. Yes. That's OK.
[edit] Yes, I have just confirmed this by using emailprivacytester.com
Actually I suspect image proxying will also interfere with request blockers like ABP or uBlock Origin, which may have otherwise blocked all requests to that third-party domain.
I guess we didn't need further evidence that Google cares more about third party marketers than users' privacy.