Like I said, even with HTTPS everyone in the cafeteria theoretically knows you're connecting to HBSC as well.
So I don't see the difference.
Like I said, even with HTTPS everyone in the cafeteria theoretically knows you're connecting to HBSC as well.
So I don't see the difference.
It's trivial to encode each tracking pixel with a personalized hash of some sort linking it to the intended recipient of that particular email.
This is...just how tracking pixels work.
HTTPS the attackers know a conversation is happening, but no idea what
But, I personally think the threat is being overblown (I am happy to be corrected though)
The main problem seems to be tracking pixel itself to deduce involvement. The suggested approach to send email to confirm email seem better, unless it contains link to login page (as it can be phished). So, the best seems to be that one should send email that explains user how to confirm e-mail by logging manually to the app.