I don't use any Google services outside of small tests like this, but it still makes me concerned for how this will affect the privacy of people I know.
I don't use any Google services outside of small tests like this, but it still makes me concerned for how this will affect the privacy of people I know.
On the flip side, those same solutions can no longer set a persistent cookie with the image, so persistent tracking based on the initial email open will stop working.
Has it? If Google's proxy is caching images, then "email open" tracking might have broken entirely. All the sender would see is that their email has been opened once by the proxy -- for all gmail addresses put together.
Or, if they snip the GET variable for whatever reason (I don't see them doing this):
http://example.com/gmail/{yourusername}/trackingimage.php
Or even:
http://example.com/{emailidfromadatabase}/trackingimage.php
This tactic is already in use by most mass email companies.
A solution would be 1-pixel high tracking lines - a 1 x 128 pixel wide image that encoded 0 and 1 as two RGB colors adjacent to the mail's background color in the visual spectrum so the difference isn't noticeable would encode a sha-1 hash placed in the url.
http://example.com/tracking-line/{hash}.pngThat would essentially render open statistics meaningless and would let Google cripple another industry after the promotions tab and 'not provided.'
I really hope they don't because it's such valuable information when creating email copy...
first one = Google
second one = user
No, it didn't. If you had chosen the option to ask before displaying external content -- which existed and applied to non-image content and, without which selection, email-open tracking by external non-image content was already reliable -- then the new setting to ask before displaying external images is selected for you by default.
If you hadn't selected that option before, you weren't protected from "email open" tracking.
If you didn't have the "ask before displaying external content" option set before this change, you were "opted-in" to read receipts already -- its just that, due to protections designed to stop other malicious use of images, you were incidentally protected against images as the vector for silent read receipts.
With this change, you are better protected against the malicious uses of images the default-not-to-display option was designed to protect against, but exposed to external images as a vector for read receipts if you hadn't chosen to display external content only after confirmation. If you did choose that previously, then you also got the new "ask before displaying external images" chosen by default -- so if you were protected from senders injecting read receipts before, you still are now. If you weren't before, you aren't now, but then that's not really a change.