PixelBlock – Stop people from tracking your email opens
chrome.google.com
chrome.google.com
I speed through email with keystrokes and zero mouse movement, and I can use email with ease on even the slowest of satellite or 2G network access.
Finally - and this is my favorite part - since I use pine, and my engineers at rsync.net also use pine, not one single intra-company email has ever traversed the Internet. Ever.
All intra-company email is simply a local copy operation on a single mail server.
What does the mail client have to do with this? I use Thunderbird with Gmail, and, since all of my contacts use Gmail, not one single email has ever traversed the Internet, ever.
With TLS-enabled mail servers, this isn't very relevant a metric.
They still have the meta-data, the actually interesting stuff.
http://www.nybooks.com/blogs/nyrblog/2014/may/10/we-kill-peo...
Also increasingly, mail clients are sending only html without a text/plain part, and w3m on emacs renders those nicely.
I mean, one can legitimately want that they do not receive the tracking information. But are there any real security implications, like siphoning off any unauthorized data, facilitating spam, etc?
- Could be used for entrapment, that is to say, could send over potentially criminal information and argue that the user did in fact "receive" it since it was read.
- If you could inject your own tracker into someone else's email, you might also gleam when and potentially how they read that email.
- One funny thing that came to mind. In Australian contract law (likely similar to the UK from which the laws were adopted), if you email someone an your acceptance to a offer, that acceptance is deemed as received when the email is read (the person becomes aware of the acceptance). Where as with regular postal mail, the offer is accepted when posted (the "postal rule", a nice headache). If you had a tracking code, it would be harder to to argue you weren't aware of the acceptance by email. That is unless your email client pre-fetches images before the email itself is opened...
I don't really see why you'd care about tracking pixels 99% of the time. If you purchase something from us and we email you, it's super useful for both of us to know if you have read the email (purchase receipt or booking confirmation.)
I personally don't see much spam and what I do see I just delete, so tracking pixels in those aren't an issue for me.
Why? If I'm interested in the email, I'll request it (i.e. if I'm purchasing something from you, me receiving confirmation emails from you should be opt-in, either in my user settings on your site or on a per-purchase basis). If I'm not interested in the email, I'll click the "unsubscribe" link in the email (you do include unsubscribe links, right?) or otherwise specify such in - again - my user settings.
In other words, that's not your call to make. That's my call to make, and your explanation is sounding like a very weak excuse to pin my privacy to a table and give it a night it'll never forget.
I could imagine that geolocating my IP might be undesirable at times. I wonder what are other potential security (not privacy) implications.
I too don't understand what's to be gained from a tool like this. If the party collecting the data abuses it to spam you then you simply unsubscribe/block the emails altogether. And of course they know you know you can do this, which gives them incentive to not do that.
The proxy effectively prevents cookie setting, ip address determination and geolocation, and injection-type attacks.
Caching images immediately is probably an attractive engineering decision on its own merits. Whether spamming read receipts is good (because it makes them useless) or bad (because it makes people think the emails got read) is an interesting question.
On a serious note: just block remote content.
"[...] Google spokesperson I emailed said that’s not entirely correct. (The spokesperson declined to be quoted.) Instead, they said marketers who track open rates through images will still be able to do so — indeed, they suggested that the data might be more accurate now since open rates will count users who read the emails but don’t load the images."
Sounds like Google made sure tracking works even when users attempt to evade it.
But another quote in the same article still talks about pixels:
"MailChimp can still detect the first request for the open-tracking pixel."
EasyPrivacy is an optional supplementary subscription that completely removes all forms of tracking from the internet, including web bugs, tracking scripts and information collectors, thereby protecting your personal data.
http://gmailblog.blogspot.com.au/2013/12/images-now-showing....
Obviously if they downloaded any image linked to an email send to gmail that could lead to a DOS, and be very wasteful in any case. So they wait until you actually open the email. But at least it obscures your IP unless you click on the links.
Running your mail server on a VPS is not a very good solution, particularly when that VPS exists in a country that interpreted 1984 to be an instruction manual rather than a cautionary tale.