Gmail/G Suite now editing URLs in mail message bodies to use Google URL redirect
twitter.com
twitter.com
- Sending a message from a gsuite account user to an external party DOES NOT show the issue
- Sending a message from an internal gsuite account user to another user in the same gsuite account + another user outside of the gsuite account DOES show the issue
- Sending a message from a gsuite account user to another gsuite user in the same account DOES NOT show the issue
- Sending a message from an external account into a gsuite account user DOES SHOW the issue (this might be tied to admin settings in G Suite > Settings for Gmail > Safety - still needs to be tested more)
- The same messages that DO SHOW the issue only show it in Mail.app on macOS & iOS when the gsuite user account is setup as "Google" vs. "IMAP". It DOES NOT show up in the GMAIL iOS app nor does it show up in the gmail.com web interface.
Google support has been effectively useless. Apple support has honestly done more to shed light on the issue. However, both companies are blaming the other and refusing to escalate to engineering or get on a call with the other company to sort this out together. Of course, Google support claims nobody else is reporting this, while Apple support alerted me to this thread. Super frustrating all around. If you are a Gsuite user please report this so I'm not yelling into the wind here. I can also confirm for my account the issue started on October 6, 2020.
Google seems to hide this via Javascript.
To reproduce in Chromium:
Enable dev tools, enable "Preserve log", go to settings and enable "Auto-open DevTools for popups".
Then click on a link in a mail.
Now you can see under the Network tab, that the new window did not go to the link you clicked but to a Google redirect url.
I guess Google outputs a normal link in the html but then intercepts the click and sends you to their tracking url.
As nobody seems to be able to reproduce it for IMAP, I guess that either A) the author is in an a/b test group that got targeted with the tracking links or B) he uses an email client that uses some other protocol or C) He is outright lying or D) Something else.
My money is on B. The author says on Twitter he uses mail.app on a Mac. I would not be surprised if the developer of a hip shiny Mac app happily used the newest shiny API from Google.
Can someone with a Mac and that app reproduce it?
I have an email generated by one of our internal systems with a link to it, fetched via IMAP using Apple Mail, and the link is edited to be like so:
https://www.google.com/url?q=<ORIGINAL-URL>&source=gmail...
We're on GSuite Business, and under "Spoofing and Authentication", have "Apply future recommended settings automatically." enabled. Probably some other options, too. I happen to have "Advanced Protection Program" enabled for my account; so this may be happening because of that.
Given the phishing attempts I've seen in my career, having this as an opt-in option for certain users ... well, let's just say I've personally had users I would have had this turned this on for and we would all be happier. I can also see the privacy concerns.
Perhaps we'll learn more about the opt-in / opt-out details in the coming days, so that users can make the appropriate choices for themselves?
- Sending a message from a gsuite account user to an external party DOES NOT show the issue
- Sending a message from an internal gsuite account user to another user in the same gsuite account + another user outside of the gsuite account DOES show the issue
- Sending a message from a gsuite account user to another gsuite user in the same account DOES NOT show the issue
- Sending a message from an external account into a gsuite account user DOES SHOW the issue (this might be tied to admin settings in G Suite > Settings for Gmail > Safety - still needs to be tested more)
- The same messages that DO SHOW the issue only show it in Mail.app on macOS & iOS when the gsuite user account is setup as "Google" vs. "IMAP". It DOES NOT show up in the GMAIL iOS app nor does it show up in the gmail.com web interface.
Google support has been effectively useless. Apple support has honestly done more to shed light on the issue. However, both companies are blaming the other and refusing to escalate to engineering or get on a call with the other company to sort this out together. Of course, Google support claims nobody else is reporting this, while Apple support alerted me to this thread. Super frustrating all around. If you are a Gsuite user please report this so I'm not yelling into the wind here. I can also confirm for my account the issue started on October 6, 2020.
Do you have a link to that twitter?
I'm like 200% sure Google can't "hide this via JavaScript" (whatever "this" means) in my native mail client if they have actually rewritten the URLs, which is the accusation here.
I mean, given the linked screenshots, the accusation is very clear, and no one has thus far reproduced anything close to that.
(Incidentally I'm no stranger to Google redirects. I don't use webmail normally, but I did write an extension to remove the redirects from Google SERP...)
The end result is the same. Gmail is rewriting url in their web interface. While there isn't enough evidence yet to decide whether they're attempting to do the same for IMAP, the fact that they do it in the web interface is undeniably true.
0: https://docs.microsoft.com/en-us/microsoft-365/security/offi...
Advanced Protection is that ultra‐secure mode that requires hardware security keys to login and prevents third‐party apps. Here’s a quote from its advertising copy:
> Protection against malware is built into Google Chrome, but Advanced Protection performs even more stringent checks before each download. It flags, or even blocks you from downloading files that may be harmful.
Sounds an awful lot like what’s going on here. It would explain why nobody’s been able to reproduce it—almost nobody has AP turned on. I imagine the number of people
1) with AP turned on
2) using a third‐party mail client (mail.app)
3) viewing plaintext mails instead of HTML mail where the link rewriting is less obvious
must be close to zero.
Google already knows the bodies of emails and can do whatever analytics they please on them. The vast majority of users are also using it via their web client, meaning that Google can put arbitrary JavaScript on the page to record which links are being clicked on. They already have most of the metadata that they could scrape from a rewritten URL, since you're already on their property. It's possible that I'm missing something, but it feels like it's a lot of effort for information that Google already possesses.
When I use, say, thunderbird, Google does not know whether I opened an email, interacted with links on them or downloaded images/external resources in them.
With link-rewriting, when I click on e.g. shopping.example.com/product/1337 and not on shopping.example.com/product/42 in an email, google now knows that "berkes, thunderbird-user is more likely to like product 1337" and can offer that data to advertisers.
If Snowdens leaks didn't make you leave nothing will.
If I need to send something I actually care about I wouldn't use e-mail in the first place. It's a low-effort type of communication with normal people who don't care about security, so I'm not going to waste time making my end of that line of communication an impenetrable bastion.
Maybe get out now rather than waiting for the frog to get cooked.
Ff extension management is terrible which i find unusable in an age where I need extensions to prevent sites from removing usability features like select, copy, and paste.
I'm using brave but I don't fully understand how it's related to chromium and if it's a true fork that they are going to be able to maintain independently. I have many many extensions in brave and an extension manager that let's me toggle them right from a drop down. Any suggestions?
You've already decided that you are not willing to use it over issues you have with it: that choice is fine. Telling others in relevant discussions why you made that choise is, too.
No-one asked you why you chose not to use Firefox in a thread about Gmail. Yet you managed to inject your FUD here nonetheless: Firefox can handle 5+ addons just fine. But now some random passersby might get the impression that Firefox is a burning dumpsterfire based on random negative critiques that aren't even in the right place nor true at all. That helps exactly no-one.
Is Google rewriting the links in the message such that if I forward to someone's non-Gmail address, they still bounce through Google?
Or is the client 'rewriting' links dynamically? This same thing happens all over the web. Drop a link in your Medium-hosted blog, and they'll front the link with their own and then redirect.
What's the new, surprising bit here?
I'm not able to repro at the moment. I manage a few domains in G, I'll keep poking.
It's worth noting that this also happens on the "HTML version" of Gmail.
[1]: https://medium.com/@ohadinho25/googles-gmail-tracks-link-cli...
Why do links in gmail redirect?
One could argue that they have to do this to meet the law.
That's entirely solved by Referrer-Policy: no-referrer, so no.
https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Re...
(Unless you're talking about someone using another webmail client that doesn't set the header, which would be a stretch.)
If Google redirects you to a website, you’re still going to the website. Unless Google internally follows all the links in emails it won’t do anything to help spam. Not to mention all tracked links I’ve ever seen track primarily based on the URL itself.
Additionally, Google adding a redirection step won’t save anything, except show via HTTP Referer that you were linked to this page by Google. If you clicked the link from a desktop IMAP client you’d have no referer, so this is a net loss for privacy, not a gain.
Somewhere in the terms of service:
> This license allows Google to [...] modify your content, such as reformatting or translating it
Without debating the legality of this, surely you are aware that agreeing to something illegal does not make the thing legal.
It very often does because much illegality has absence of consent as an essential criterion.
Why does all the SPDY nonsense matter when Google adds huge latency in other ways.
I would prefer a native email client coupled to a simple hosting solution.
Since then it's been pretty good. I keep my old gmail as an additional account on my email client to track things I've missed, but it's been surprisingly little.
For Calendar - you can have fastmail pull your gmail calendar. Keep that in place to help transition recurring meetings to fastmail, and then eventually you can sunset that too.
Do invest in your own domain name so that if you need to leave fastmail in the future you can do that more easily.
If I click on a link, my browser opens it. Done, right?
Tbh I'm struggling a little to understand what the threat model is here. You trust gmail to receive and handle your email. In the vast majority of cases, you're accessing the email through their web frontend, where they could easily detect hovers and clicks and log those with fair reliability, if they had nefarious ends in mind. But them using a redirector is a bridge too far? If you trust them to do the first two items, it seems a little far fetched to distrust the last.
Also, there is something very wrong when we're okay with Google rewriting parts of our emails. How long until they decide to start modifying other bits of our emails? Reading the contents of the email is one thing, modifying it from its original is a whole 'nother ball game.
That's not the claim. The claim is that they're rewriting urls you receive. I suppose if the imap claim is true, and you reply, and you quote the redirector url in your reply, and someone clicks that link, they could detect it. That seems a little annoying and presents a slight risk, but it doesn't seem like the type of thing that would be intentionally designed in, even if I model google as completely amoral and short-termist. There just doesn't seem to be much advantage in it.
> And not every gmail user uses the webmail interface either
That's why i said the vast majority of cases, not "all." :)
And after Google pay thought it was a good idea to send my phone number out to every online merchant (I now get nonstop spam texts and calls) I've had it with the company.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Hello, please visit my site at https://www.google.com/url?q=https://sneak.berlin&source=gmail-imap&ust=1603637677000000&usg=AOvVaw2HZaWQujRWlDNrZMKZIsed.
Best,
- -jp
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEVTmtAN5MQvOv4RV1BSRD9N8qVcIFAl+MVwwACgkQBSRD9N8q
VcLgzRAAln4mjtvlwqBIDKA8RFfTP/VwX4SuV1n7Ux5FrdNY1htde5Nkxu/wIcE7
hz5VbdclvUrKP8lpb6LTU7UuV73aaN48QfGKhDmRkokiflR6uoisr9CBnLooD6Iw
4KpU8Puqh+LgHRbP2AYZ3Qm//g9sJqdziC8/tATizE+yk8wcIqKihXzp+y9fYWNs
UYv92/k6MivxqvM4r6IELJ8tOBSRu1lYKFsuI4GuYmPlnk2UqodlCUpWByaETezO
NtkUvOVnIvt02hpliu36LSDeIquVio2eVjYJrvGvMpyWTW3MFG9BI0Tcgxbj3lsS
DL9wOxhNeRPLYG91DtP+eIYsYZWigkGNQ8PMRfXcpjDN49ei//iN6Pvopn6txSnQ
u9lELP8Td+tEXAlUnNzlE3d1WAARve9iG1SnAFDk+vfWEaEvEoZl9ZiHuH57jPF2
9ggAOeGKaEAlF74Ekjs0Xrct5WDzy2FF3d+TE5e1Nzx+vwLBaRuWLVJO+iPUlbLv
MHAwmCp5zNIB2r8sbBDATBUHaggFXV/k5H+wTjmB2kLALq/OD9tSfjNfjEUKcpM/
FGK/AOh8NjwR28n9f1uMutYBrs2KPqjZlW88zNu90Wg0OAk91L9jmz3trH2PYrKs
rlg2hQzBdOIY1/1LeUBoDkcQiqP2neg2ae/XF26qSarUVKcwAhM=
=jmVc
-----END PGP SIGNATURE-----
I'm also probably doxxing myself by posting those ust= and usg= values unredacted. :(How can I replicate this?
Perhaps some law enforcement agency has asked google to specifically track URLs in your messages and it's just you seeing this.