4 ms·
From the article: "The Navy email to Navy Times contained hidden computer coding designed to extract the IP address of the Navy Times computer network and to s
by java-man 7y ago
From the article:
"The Navy email to Navy Times contained hidden computer coding designed to extract the IP address of the Navy Times computer network and to send that information back to a server located in San Diego. Under U.S. criminal law, authorities normally have to obtain a subpoena or court order to acquire IP addresses or other metadata. Not using one could be a violation of existing privacy laws, including the Electronic Communications Privacy Act."
"“It is illegal for the government to use [the emails] in the way they did without a warrant,” he said. “What this constitutes is a warrantless surveillance of private citizens, including the media, by the military."
"Hicks would not state for the record whether the Navy obtained a search warrant or subpoena in connection with the emails with tracking devices."
- deleted 7y ago[deleted]
- lwf 7y agoIt's just a tracking pixel: > “I am writing regarding your emails from yesterday, which contained an embedded image that was not contained in any of your previous emails,” Parlatore wrote. “At the risk of sounding paranoid, this image is not an attachment, but rather a link to an unsecured server which, if downloaded, can be used to track emails, including forwards. I would hope that you aren’t looking to track emails of defense counsel, so I wanted to make sure there wasn’t a security breach on your end. Given the leaks in this case, I am sure you can understand.”
- arkades 7y agoThe email came from a Navy prosecutor, not a marketing department.
- inetknght 7y agoTracking someone for marketing should be illegal.
- tgragnato 7y agoNonconsensual email tracking is illegal in Europe. > https://www.gdpreu.org/compliance/email-tracking/ https://www.gdpreu.org/compliance/email-tracking/
- inetknght 7y ago\o/ Unfortunately I do not live in Europe. :'(
- luckylion 7y agoDo you know of any anything more recent on that? It cites the German privacy working group which has no direct influence on the actual laws, and predates GDPR/DSGVO (local German version).
- tgragnato 7y agoThe working group expressed an opinion considering the draft of the GDPR ("In its current prevailing form, we expect email tracking to be categorically prohibited under the GDPR without express user consent."). I'm not aware of any major change in article 7 since that moment, so I'm fairly confident that opinion is still relevant. If you're asking if it's been tested/challenged in court or in a DP measure, I don't know.
- ryanmarsh 7y agoEvery email I send from Hubspot has these.
- givinguflac 7y agoWow, you’re a government and use hubspot for emails with defense counsel? Oh wait no your comment is irrelevant.
- JoshTriplett 7y ago> It's just a tracking pixel: So? The mechanism doesn't ameliorate the issue. The government is rightfully held to a higher standard when it comes to information collection. Particularly when it comes to collection of information from defense attorneys on an active case.
- jbob2000 7y agoThe tracking pixel doesn't provide any material information, it just tells you that a certain computer downloaded the image at a certain time. It doesn't tell you WHO downloaded the image (but you could deduce that if you had other information, such as who was using the computer at the time it was downloaded) and it doesn't tell you WHY that image was downloaded (was it because an email was opened? Or was it because the email was scanned for viruses?).
- inetknght 7y ago> The tracking pixel doesn't provide any material information https://www.dol.gov/general/ppii https://www.dol.gov/general/ppii Email addresses are considered Personally-Identifiable Information even in the United States (and certainly in the EU too). Deduction of who downloaded the image is obscene and a violation of that person's privacy. Any correlation of email address information with any other information at all could be considered a violation of that person's privacy: the IP address and user-agent information alone is sufficient enough to point in the direction of a malicious attack. And there are people who have some serious safety concerns: people who've been abused by significant others and are prone to being victim to stalking or hacking is just one example.