Webmail providers can implement read receipt privacy by requesting images from every email automatically on-delivery instead of on-read. Doing this for non-existent mailboxes also prevents mailbox enumeration.
Webmail providers can implement read receipt privacy by requesting images from every email automatically on-delivery instead of on-read. Doing this for non-existent mailboxes also prevents mailbox enumeration.
"hey look this server blindly downloads images".. Sends a million emails with a bunch of tiffs.
99% of the time, the image is just a company logo in someone's email signature and takes essentially zero storage space or bandwidth to retrieve at receive time. For the special cases, just warn the user about the implications of downloading the image, and go do it if they ask.
There are no unsolved technical reasons preventing this from being enabled in Gmail, only political reasons.
I think those two things put together create a very, very niche use case. If I'm concerned about privacy, I don't turn on loading images by default. I'd be really curious to see the overlap in users who do.
The point is that you shouldn't have to do this, and can be afforded the same privacy while improving your user experience.
Even if the image itself is proxied through a CDN, the time the image is accessed is still exposed.
why cache time discussions, after initial download there is no need to download it again, email is not the browser, there is no expectation that the image in email will be the actual at the time of opening, the expectation is that the image is actual at the time of sending. and for storage you can use hash to not store duplicates, and probably save bandwith with optimization.
They do have the Bridge now to use it on the desktop.
So have the mail server download the image immediately upon getting the message, so that the timestamps (and boolean of being accessed) means nothing?