Images Now Showing in Gmail
gmailblog.blogspot.com
gmailblog.blogspot.com
[Update: I'm not sure when this feature will actually be rolled out. I think my test below automatically displayed the image because my own email address appears to be implicitly a whitelisted sender (even though "images from this sender are always displayed" doesn't appear for it). Whether Google will alter the behavior when they actually deploy this feature, I don't know.]
[Original message:]
I just tested and, yes, Gmail only loaded the referenced image when I clicked on the message to open it within Gmail. I can't be sure, because perhaps if I had waited an hour without opening the message, Gmail would have automatically loaded the image anyway. But in reply to mherdeg below, the evidence suggests that, yes, Gmail plans to opt everybody in to sending "read receipts" by default for HTML messages that reference images.
I'm surprised by Google's statement that the previous behavior of prompting was "to protect you from unknown senders who might try to use images to compromise the security of your computer or mobile device."
I realize this was a benefit, but I always thought the main purpose was for privacy --- not to betray to the email sender when I opened the email. My guess is that Google did not view this as a privacy setting, or they probably would not have forcibly changed everybody's setting.
It's doubly strange that they did so without a notice inside Gmail that they did so -- just a blog post.
I don't use any Google services outside of small tests like this, but it still makes me concerned for how this will affect the privacy of people I know.
On the flip side, those same solutions can no longer set a persistent cookie with the image, so persistent tracking based on the initial email open will stop working.
Has it? If Google's proxy is caching images, then "email open" tracking might have broken entirely. All the sender would see is that their email has been opened once by the proxy -- for all gmail addresses put together.
Or, if they snip the GET variable for whatever reason (I don't see them doing this):
http://example.com/gmail/{yourusername}/trackingimage.php
Or even:
http://example.com/{emailidfromadatabase}/trackingimage.php
This tactic is already in use by most mass email companies.
A solution would be 1-pixel high tracking lines - a 1 x 128 pixel wide image that encoded 0 and 1 as two RGB colors adjacent to the mail's background color in the visual spectrum so the difference isn't noticeable would encode a sha-1 hash placed in the url.
http://example.com/tracking-line/{hash}.pngThat would essentially render open statistics meaningless and would let Google cripple another industry after the promotions tab and 'not provided.'
I really hope they don't because it's such valuable information when creating email copy...
first one = Google
second one = user
No, it didn't. If you had chosen the option to ask before displaying external content -- which existed and applied to non-image content and, without which selection, email-open tracking by external non-image content was already reliable -- then the new setting to ask before displaying external images is selected for you by default.
If you hadn't selected that option before, you weren't protected from "email open" tracking.
If you didn't have the "ask before displaying external content" option set before this change, you were "opted-in" to read receipts already -- its just that, due to protections designed to stop other malicious use of images, you were incidentally protected against images as the vector for silent read receipts.
With this change, you are better protected against the malicious uses of images the default-not-to-display option was designed to protect against, but exposed to external images as a vector for read receipts if you hadn't chosen to display external content only after confirmation. If you did choose that previously, then you also got the new "ask before displaying external images" chosen by default -- so if you were protected from senders injecting read receipts before, you still are now. If you weren't before, you aren't now, but then that's not really a change.
> Instead of serving images directly from their original external host servers, Gmail will now serve all images through Google’s own secure proxy servers.
In most cases, the unique identifiers are embedded in the URLs themselves, so simply serving through a proxy is ineffective. Should I blindly trust that you, Google, did the right thing?
Edit: looks like Google isn't stripping out the query parameters AND it isn't proxying for iOS devices! This is by far the least effective set of decisions... http://blog.movableink.com/gmails-recent-image-handling-chan...
I wonder if this change is a result of backlash over the promotions tab. These type of referenced images are most commonly used in marketing campaigns and were from businesses likely to pay good money to AdWords. As a concession for fewer overall impressions, perhaps, these groups got Google to let them track easier? The whole thing smells fishy.
How this plays out will be interesting to watch.
Are you saying squash the sender or squash the tracking images?
I hope gmail doesn't start squashing my emails because it contains a tracking pixel.
FTA: This new improvement will be rolling out on desktop starting today and to your Gmail mobile apps in early 2014.
See how marketers are scrambling to adjust to this change:
a.) Gmail is now requesting all images from proxy servers (googleusercontent.com), which incorrectly situates users in its headquarters in Mountain View, California when images are downloaded. This impacts the ability to geo-target image content for those Gmail users who are affected by the changes. (Note: Local Maps using zip codes appended as query parameters are unaffected.)
b.) Gmail is stripping the user-agent headers from the client request, which eliminates the ability to determine the Gmail user’s device and target image content appropriately.
c.) Gmail is removing the cache-control headers from the responses, which forces the user’s images to be stored in their browser’s cache for up to a day. This only impacts live image content if a Gmail user re-opens the email after the first open.
...
http://blog.movableink.com/gmails-recent-image-handling-chan...
Basically their only avenue for now is mobile email which will soon follow in adopting this method.
And, as such, OP's claims are exactly correct.
The only way this would not be true is if GMail pulled every image in every email, even if it's not read by the recipient. Given GMail's usage of the term "proxy server" in their blog post, as well as the tests by the OP and others on this thread, this appears not to be the case.
http://marketer.com/4b3403665fea6.jpg
where that hash is used to link to my email address
It will protect you from it being as a read receipt if (and I'm not sure if this is the case, though it should be trivial to test by sending email with images served from a site you control to an email you control without opening it) Google requests the image once it has received the email.
I'm sure they built-in rate-limiting to prevent DDOSing the sender's image server...
It protects you from the guys at marketer tracking your user-agent, your ip address (which gives a rough geo-ip), the number of times you opened the email, etc. It's unclear to me whether the images could set cookies before (they probably did), but even without that, they could just use etag-tricks, or stuff like that, to track you cross-sites.
Marketers might now know when you open the message, but proxying the image prevents them from getting more precise information.
(No idea exactly how much of this and more Google does, obviously, but they put themselves in position to do it)
Here's what we've learned:
- the proxying of requests only happens when a user is viewing the mail inside Gmail (i.e. gmail does not actually affect the message body, its just proxying at render time)
- gmail only caches in the image for a few minutes. So for email marketers, if your recipient views the email then views it again a few hours later, the marketer will see two requests for the image
- there is basically no personally identifiable information in the request that Google's proxy sends to the server hosting the image. So from that perspective this is actually a boost in privacy than the previous state of the world. None of the headers, cache controls, cookies, ip addresses, referrers or user agents are passed to the original image server
- obviously you can encode some ID into the image URL itself but all that lets you do is identify the email address of the user that opened the email. But you already had their email address because you sent them an email - so again, no PII gets disclosed
- it is true that marketers will see a more accurate count of opens (because displaying images is on by default)
- there seems to be several ways to get gmail's proxy to NOT cache the image and simply proxy the request every time the user opens the emails
This functions as a read receipt (like the tracking pixels).
The image might be cached later, but since it is initially loaded the first time an email with it is is opened, this means that implementing read receipts on all outgoing emails is as simple as making the URL for each image unique to the user.
Thus, the marketer knows:
1) That the email was opened 2) When the email was opened
along with whatever information they already have about the user.
This is a HUGE privacy implication. Even if "no [further] PII gets disclosed", it discloses a lot of information that is both sensitive and easy for marketers to join with existing identifying information.
And I would say you don't know what PII means.
You might consider this to be a violation of privacy but you're not disclosing any PII that the sender didn't already have. And in fact it's decreasing the amount of PII that's being disclosed because you're not longer sending any browser information when the image is loaded.
All that lets you do is...confirm that the email address exists. Until this change, that was a very difficult thing to do; now, its equivalent to getting a message through a spam filter. This is going to help spammers _a lot_.
You just have an email address. Once that image is downloaded, you know it's active the sky basically falls down.
What are those ways?
Or are these images pre-cached when mail is delivered (so that the fact that an image was loaded is just proof of delivery, which you should be able to get anyway?)
The e-mail spam/list creators are a different kind of adversary than, for example, web trackers.
They will do something like this: http www theirimageserver com/images/img53.jpg?to=you@email.com (Obviously they will obfuscate and use some kind of hash instead of cleartext e-mail to disguise their tracking ways).
Regardless of whether some.google.ip loads it, or your.home.ip loads it, it won't change the fact that you@email.com loaded it and your email is very active, not just active in that it didn't bounce, but active in that you actually read it.
Once again, it's a step in the right direction though, and I'm looking forward to seeing greater innovations from Google in the privacy space, because I'm confident that there are Googlers who understand that privacy is not a feature nor a PR thing... it's the difference between the preservation of humanity and society versus not.
For that scenario, Google could ignore the arguments and just request the file. However, I'm not sure I get Google's implementation of the proxy, but if the images are grabbed only when the email is read, it's easy to track by adding a hash to the filename itself.
So, in the email company's server, they'd have a canonical file, for instance, acme-co/dec2013news/img53.jpg. For each subscriber, they'd have something like a symbolic link to img53.jpg specific to the subscriber, for instance img53-5baa61e4c9b93f3f0682250b6cf8331b7ee68fd8.jpg.
EDIT: Checked a newsletter's source and that's what they already do. Since I don't deal with email marketing much, I honestly had no idea.
Deleted comment
If google fires off a request when they get the email, the company has no way to track if you opened their email.
If google fires off requests to all emails they receive to @gmail.com then the marketers won't even know if it's active @gmail.com account, they'll just know that *@gmail.com is received, which isn't information, it's an easy assumption.
Also, remembering that Google has no obligation to protect non-American users, does that give the NSA access to them, to run things like facial recognition, etc?
If it's archived {immediately,on first request} permanently thereafter, there's now another copy outwith your control.
Edit: moreover, the images are requested locally by the user's browser. Google doesn't get a look at them at any point[1]. Whereas now, they get a permanent copy for free, because they're doing you such a favour!
[1] Directly, anyway. I guess they could use js to get the requests and headers and submit them back to the mothership, but on slow connections that could be pretty obvious.
(Of course, this doesn't rule out the possibility that Google is actually holding onto each version they cache. I imagine it's not actually worth it for them to do so.)
As comparison, Firefox has a 'save page' function which distinguishes between 'html only' (akin to the mail message), and 'complete', which would include all images, stylesheets, external js files, etc.
The work is obviously to sift through all the emails, remove the photos, and separate/store them on a separate server. Now all NSA needs to do is get a daily dump of all the pics, and then run their data collection/facial recognition on them.
With this I guess I can see emails with all the images and other goodies without that worry. Works for me.
On the other hand... There's a good chance Google is caching all this now. But seeing as they're running the mail system I don't feel like it's too major of an intrusion beyond what they already have.
[0] https://plus.google.com/+DanielWaisberg/posts/XDrRoh3GoVP
FWIW, they're partially funded by Google Ventures- perhaps there is some type of technical compromise that doesn't break geographic tracking completely: http://www.yesware.com/blog/2012/07/18/how-does-yesware-trac...
This change makes all of that impossible: Google will (presumably) always request your image URL, whether the user opens the email or not, and the request will come from Google, with their metadata, not your target.
Why presumably?
If you want to be cynical, you can note that Google will still know which emails you opened and which you did not. Does the current Gmail TOS restrict them from selling that information to advertisers, or (more likely) using it to target ads? Probably not!
I suppose if they're clever, they'll figure out when a sender is serving a million copies of the same image to slightly altered URLs in the same email template, and forgo the requests, but either way, the sender loses the analytics.
I doubt any of this is done with the privacy of users in mind.
I used it so that images like /verifyRealEmail.php?email=$myaddress wouldn't work.
Mozilla/5.0 (Windows; U; Windows NT 5.1; de; rv:1.9.0.7) Gecko/2009021910 Firefox/3.0.7 (via ggpht.com)
I viewed the email using Firefox 26 on Debian.
"Google’s own secure proxy servers"
will that mean that people who track me opening their email with 1px images won't be able to track that? I hope this is the case...So, what's the upside vs. just having the option to display images as desired and NOT have Google cache them?
So trusted messages are now leaking read receipts.
In some cases, senders may be able to know whether an individual has opened
a message with unique image links. As always, Gmail scans every message for
suspicious content and if Gmail considers a sender or message potentially
suspicious, images won’t be displayed and you’ll be asked whether you want
to see the images.
https://support.google.com/mail/answer/145919Mailer can setup url that is composed of random words and is unique per email.
Ex: www.tracker.com/weather-dog-city-nice.jpg could identify you + timestamp of request and bam, you have record of: valid email, address isn't blocked and that user reads emails from recipient. No proxy in a world would be able to make this request anonymous.
No idea what advantage of this is apart from google eventually offering an alternative to gmail (think of comment system being replaced on youtube)
> Of course, those who prefer to authorize image display on a per message basis can choose the option “Ask before displaying external images” under the General tab in Settings. That option will also be the default for users who previously selected “Ask before displaying external content”.
However, one interesting question is how can third-party analytics will workaround this? Is there a way? Given that gmail holds a large market share of email users, this is really going to negatively affect the usefulness of such services.
From https://support.google.com/mail/answer/145919?p=display_imag...
I don't want to lose the ability to track email opens to gmail users through Mandrill/SendGrid/whatever...
Also, a postmaster's version: http://emailexpert.org/gmail-tracking-changes-the-fix-what-y...
Disclosure that I'm from Campaign Monitor and wrote that first post. As you can imagine, we've been getting a fair few enquiries about image tracking and opens today...!
It's crazy that email clients ever provided that vulnerability in the first place.