Facebook uses bgsound to see if you have opened an email
plus.google.com
plus.google.com
Got a "DNS Prefetch - Anchor" on Gmail
Gmail does much much better - a counter-intuitive result.
For those interested: https://grepular.com/DNS_Prefetch_Exposure_on_Thunderbird_an...
I am surprised that you're seeing leaks in Thunderbird 10.0.2. That is my own client of choice so I'm always keeping an eye on it after updates and I am not currently seeing any leaks... If you have remote images disabled, are you still seeing leaks? If so, which ones?
I disabled preFetch in the config editor and my ship's running dry again.
webOS email client leaks data all over the place.
https://grepular.com/email_privacy_tester/lookup?code=gapz72...
If the address exists in Gmail, you get a response on "DNS Prefetch - Anchor", so it could be used to determine whether to send an email or not. I'm not a mail administrator but I can imagine how it might be useful to a spammer, e.g to stop mass bounce replies.
If you're using a tracking image or any similar technology, then you are exploiting a weakness in the system to take information that you don't have permission to.
I recognise that it's standard industry practice, but it's categorically not ok. If you want to track users, ask for their permission. If you haven't done so, then you have no right.
Incidentally, it's unfortunate that Sparrow doesn't have a 'force plain text' option. Even though I've checked 'prefer plain text', all Facebook e-mails are delivered in HTML. This might be a reason to switch back to Mail.app.
And it's the whole point of the article.
Took his karma negative, and once that happened his account was killed. As a new member you have to be careful about controversial statements until you build up a karma cushion.
It does? Someone mentions that they had loaded the image bug, leading to someone else making the show image comment. BGSOUND would not be filtered by that.
There was a time when the iOS email client (and Apple Mail too) would actually load content from the html audio and video tags, even when remote images were disabled.
http://www.clickz.com/clickz/column/1716214/disabled-images-...
Your point is right, that emailers are trying to get around the image blocking... But it's not that everyone turns off their images; some folks still keep them on. The question then becomes: what's the best way to block tracking pixels while still allowing consumers to experience attractive emails if they wish?
Putting img tags that link to your server doesn't sound like a very good way to get attractive emails anyway. What if your server goes down? What if the user disconnects from the internet before reading their inbox? What if the user rereads your message after several years and it's suddenly not so attractive anymore?
There is also the issue with referencing the inline images, though I've been told that it's not such a big deal (I've never tried it myself).
As for the "going down", most reputable email vendors have pretty well done image servers, for this very reason. But yes, if the user disconnects, the images won't be available. But same with the web site that the email is linked to, so users couldn't necessarily click for more info either.
But commercial emails usually aren't designed to be saved and re-referenced like mails from friends. Instead, they expect to be read while online, and either reacted to quickly or discarded. I guess it's similar to the mindset with paper mail.
Too bad there isn't more effort on making better mails that don't rely on images but instead make better experiences... instead of better tracking tech.
But wouldn't the sender have to serve the images over HTTP anyway? Unless you expect a big percentage of those emails to never be opened, but then I have to wonder if you should be sending them in the first place.
Considering it's an IE specific tag, I tried with IE and gmail, I couldn't get it to download anything, even when allowing remote images. IE was too bugged out trying to render gmail (not hating, stating).
On the tablet Google actually wants me to create a Google Profile before I can read the article.
I've never run into this before today. I wonder if its new.
Sorry if I sound annoyed, but it's a pet peeve.
Tracking users in ways they don't actually know about and understand, well, the usual terms normal people apply to that sort of behavior are "underhanded", "antisocial", "betraying trust", etc.
This isn't a rhetorical question; I'm sincerely curious. Thanks.
For websites, it's the same risk I take when leaving my house to visit any public place.
I use Piwik on my own sites and will never share that data with anyone.
But most email marketing tools provide some metric called "% of emails opened" or something similar.
Now assuming that the marketing emails you send out are mostly text (as they should be), it seems unlikely that many recipients will bother clicking the "Show Images" button since there is no reason for them to do so (not to mention that it often brings up a privacy warning or the function may have been entirely disabled by IT for unknown sources).
So in that case, that metric must be enormously unreliable. So much so as to be basically meaningless?
I have also heard statistics from business types who say things like "Email marketing is useless, only x% of people even open the emails" and I have also seen such things repeated on websites about internet marketing.
Something doesn't seem quite right here.
How many people complaining about email open tracking are also Sendgrid customers? Use email newsletter service? Your emails may have open tracking (including who opened it) without you even knowing.
As for why plain text only is not good enough, here's a simple thought experiment. Imagine that we did not have any kind of email. We invented computers, and computer networks, but somehow, incredibly, overlooked inventing email.
In this hypothetical world, people still communicate by writing letters, and sending them through the post office. Of course they write the letters on computers in word processors, and then print them, and it is the print outs that they mail.
Now, imagine in this hypothetical world that someone finally comes up with the idea of email, and pitches it as an electronic equivalent of regular mail that is faster and more convenient. Is he going to make it plain text only? Of course not. It will need to be as capable as physical mail, which means it needs to support sending anything that people can print on paper. That means some kind of rich format that can handle different typefaces and fonts, colors, inline images, and attached documents.
Email started off plain text only simply because when it was invented the technology wasn't up to the challenge of handling the presentation features of real mail. The technology has improved, and rich email is the natural, inevitable outcome.
Perhaps I should be more explicit.
My problem is not with the abilities to assign pixels to an output device. Email should not be an interactive proposition and should have no ability whatsoever to run code.
Agreed, but HTML isn't runnable code. It's a declarative document format.
This is the same practice as any tracking done on a web page even going back to the pixels that AWStats used to use.
I work for an ESP and we've been doing something similar since 2003.
It doesn't matter how many organisations are doing it, or how long they've been doing it, or how much money they make from it, or how useful the information is, or how good the "services" you provide are. It's still an attack on peoples personal privacy.
I don't expect to be able to convince you though. After all, you work for an ESP so you have to justify it to yourself somehow.
(1) hiding something away in the T&C's doesn't count.
EDIT: Oh, are you talking about tracking someone on your website, or tracking people across websites?
EDIT2: When people visit a website, they expect that website to be able to see their IP address and track their movements across it. What people don't expect is that websites (without their permission) can track their movements across other websites.