A Clever Way to Tell Which of Your Emails Are Being Tracked
wired.com
wired.com
Is the author not aware that for the last decade or so every email program/service in the world prompts the user to load images to purposely thwart image tracking?
While that is true, people say "yes" because things don't display properly. Often elements like emoticons and whatnot are also remote images!
"Display remote images? Yes/No" is an all or nothing proposition, in other words.
The e-mail client, rather, should determine which images will display in a visible way and reject all others even if the users says Yes. It should not fetch images whose tags don't specify a width or height, or that specify one less than 16x16 pixels, and those that are positioned such that they will be clipped, or clipped by something else, so that even if filled with fetched content, they will not be visible. Basically: calculate the set of image tags that refer to images which will be obviously visible to the user. Prompt for those, and do not fetch the rest regardless of the answer.
Of course, the standard user has no idea what that means, how to judge where the email comes from, or what any of the options mean beyond "see the pretty pictures", but, hey, one step at a time.
https://emailprivacytester.com/
Sends an email to you which checks to see how much stuff your email client is leaking. Turns out some email clients load remote content even before you click "Load Remote Images"
IIRC it is disabled by default BUT I MAY BE WRONG.
Sorry for screaming.
It shows that with Gmail, you don't need a browser extension to block pixel trackers.
Gmail does that fine by default, just don't display images in the message.
How did you configure your gmail settings to pass the test? I don't think I changed the default.
"The email sent by this system contains numerous unusual tricks which will probably offend some spam filters. If possible, you may want to whitelist emails from sender addresses matching *@emailprivacytester.com before continuing."
If you don't have that level of control, I'm not sure what you can do about it.
But either the provider doesn't support wildcards or it is filtering it anyways.
For me Thunderbird didn't trigger any test. K-9 Mail triggered the Meta refresh test (but asked me to choose the browser, perhaps because I have multiple browsers installed).
But I use mutt, so I'm not worried. If I really have to read an HTML-only email, I have mutt configured to pass the HTML to links for rendering, but in a way that links runs confined and without access to the Internet (or anything else) in order to do so[1].
It's been a few years now, and I don't feel I've really missed anything by going back to a text-mode email client. By being able to optionally render HTML as text, I can still read the occasional HTML-only email that I need to (for example: order confirmations). The rest of the time, plain text works just fine.
[1] http://www.justgohome.co.uk/blog/2014/02/mailcap-html-apparm...
I guess they "new take on mail" by google is not designed for end-users privacy.
http://googlesystem.blogspot.ca/2013/12/google-uses-proxy-to...
Of course if Google wait to cache the image when you actually read it, then this isn't true. But I'm prepared to give them more credit than that.
You'll get a read-receipt, which SMTP doesn't offer.
I read my mail with Emacs, but according to https://emailprivacytester.com/ , when I click on a message, Emacs parses the HTML and inserts images into the buffer. This is default behavior with the `notmuch` mail reader
EDIT: Chat with dkg on the #notmuch IRC channel shows there's a patch to fix this that isn't in a release quite yet.
My point: Be careful, even if you're using a "dumb" mail client! :)
text/html; lynx -dump %s; nametemplate=%s.html; copiousoutput
Since lynx doesn't load images, that would be safe from this kind of tracking. But another configuration using a different renderer might allow it.Furthermore, it is also possible to prefer the plaintext version of an email if there's a choice. From my ~/.muttrc:
alternative_order text/plain text text/html
I can't remember ever being put out by not being able to read messages that fetch images from the web. Even if I have to open a URL, I do it in Firefox, where I run RequestPolicy.The "right" way of doing this (calling lynx in a network-restricted cgroup/chroot/container) sounds like a pain.
Doing
(setq gnus-blocked-images ".*")
will block all the images in the emails.I tested it using "https://emailprivacytester.com" and the it picked up only the DNS prefetch link/anchor which I assume are due to my ISP and not Gnus.
In my understanding, opening the image loads the image from Google servers so it never hits the tracking website...
Am I right?
Also of note: Fastmail also uses proxies in this fashion too now.
Not necessarily. Does Google cache the image when receiving the email, or when you view it?
http://blog.movableink.com/real-time-content-and-re-open-tra...
The clever way would be to discover ALL advertisers AND prevent spying on our emails.
If you open an html email, you are being tracked.
If you click on a link in an email, you are being tracked (plain text / html)
Is there any email clients someone can recommend that force plain text in multipart emails? Or convert html emails to be viewed as plain text if the email isn't multipart?
kmail used to be hugely anti html in emails so they may have more options than most for avoiding it.
In thunderbird, which is my current MUA, you can choose View > Message Body As ... > Plaintext and it will display everything it can in plaintext. There's also Simplified HTML and Original HTML as options.
>convert html emails to be viewed as plain text if the email isn't multipart? //
Not sure if that's what thunderbird is doing but it appears to be (if I send a HTML-only email to myself the thunderbird will display it as plaintext).
Personally, I would consider it, ugly, sneaky, disturbing and unsettling. But then it's ok on the Internet because this sort of tracking is easy on the Internet right?
Email is just a form of communication. I believe, ut's not that harmless that someone received the confirmation that his message was opened. Of course things get a bit complicated when someone gets too much information, but simple opening emails/clicking links is something we should accept. When we are walking down the street hundreds of people see us, see what we do. Most people do not have a problem with that. I really can't understand what is so different in case of online activity, despite the fact that we are familiar with other people seeing us in real world and the Interent is still a mentally new territory for us. And this distinction between the off- and online privacy is something what actually can inhibit the development of online society imho.
http://gmailblog.blogspot.ie/2013/12/images-now-showing.html
correct me if I'm wrong, but the tagging support page is for "creative pages" with doubleclick, not emails:
https://support.google.com/dfp_premium/answer/1347585?hl=en
EDIT: ok well, turns out i'm wrong and here's how to turn off automatic image loading
No they don't, I don't do HTML mail.
"every action IS a reaction"
Yep, every email sent from a company to you for marketing purposes has a beacon and link tracking.
If you're alarmed by this, you should also know that every website you visit can track your IP, your OS and version, and your browser and version.