Spy pixels in emails have become endemic
bbc.com
bbc.com
Sure all (intrusive, privacy-violating) newsletters and email messages will turn into "click to read" links, but that's probably a better situation than what we have now.
[0] I don't actually know if it works that way. Just what I believe the GP is saying. I could maybe see this being done so they can run heuristics on the assets, or something like that.
https://blog.filippo.io/how-the-new-gmail-image-proxy-works-...
I would start a Twitter storm but I'm not famous enough on Twitter to do that. Here is the setting you want:
Tracking pixels go way back, they were used primarily for deliverability and engagement analysis.
The article says that now the sender can see what street you are on. I thought google proxied these so you got a google IP - how do they defeat google's proxy? Also you would think that most email providers would filter out spyware - I have not picked up any of these spy pixels through google so far.
Link a link shorter, but the URLs are not short :-)
You can know what link was clicked and who clicked it.
So even if the images are blocked, if you click a link it goes through the link shortener redirection server, and bingo! They know more about you! :-)
But these "spy pixels" that can see the street you are on. I've not been following this space, but google proxies the request, how does the spy pixels active spyware payload deploy even? And if they are using the ip address that is just a google IP (or a cloudflare IP if I'm going through WARP).
Politely sending and email to Company Foo? What are good arguments to write in there, so that _anyone_ working in Company Foo can understand the problem?
I don't expect companies to start using plain text in emails, although I'd love that...
I was reading them all along. They just didn't know, and assumed I wasn't opening them. I was, but not the tracking pixel.
If I may say so, the mnm project also deserves coverage like this. It prevents spy-pixels, and phishing, and provides unsubscribe (from threads, or senders, or whole sites). And a heck of a lot more :-)
mnm, an open source project to replace email & SMTP:
They use unique URLs for each e-mail and recipient, so when the proxy makes the request, they can trace it down to which exact e-mail was opened.
Always amazed me that some marketing emails still use images for all content, when I see that I just laugh at the empty email.
But the tracking pixels, aka, "spy pixels" -- are there to get around this earlier limitation...
The way it works: A link to an image, an image hosted somewhere else on the Internet, is placed in an email. Well, now the email system needs to display that image, so when the message is opened, the URL for the image is opened, and if that's a unique URL -- then it can be tied to a specific piece of email -- in effect letting the party on the other end know that you opened the email, when your email client went out to the Internet to fetch the graphics for the image...
Is that good or bad?
Well, it depends on one's point of view...
Certainly it's bad for privacy... but what about transactions in business where one party needs to know that the other party received something important?
You could compare this to asking UPS or the Post Office to put package tracking on a package, which is a very beneficial service to businesses, because it lets them know that a package they have sent is now in the customer's hands, and their responsibility (at least as far as shipping and getting it into their customer hands) is now over...
Certainly you would want to know if an intended recipient actually received Bitcoin, or other digital currency you sent, as part of an online transaction you were involved in...
Also, by reciprocity, if you wanted that, then by reciprocity you should also be OK with other senders/counterparties in digital currency transactions with you -- being able to know with certainty if you had received the Bitcoin or other digital currency that they had sent...
It's almost the same thing...
People should not blame the Internet for inventing this "creative work around" for tracking -- for the Internet's earlier invention of email which didn't know if anyone received an email or not...
A well-designed future email system -- permits message tracking as an option -- but doesn't force it down users' throats without consent.
Also, a well-designed future email system -- would permit a high degree of granularity on what the end user wants to allow others to track and what they don't...
For example, they might set the system so that their friends and family (or other whitelist of names) could receive automatic confirmation when their messages are received, opened, etc. -- but this wouldn't happen for unknown/unsolicited senders...
But anyway, that's "why" of the "spy"...
...pixel, that is... <g>