7 ms·
"This stressed out a lot of email marketers, who quite rightly realised that the new regulations would have a significant effect on their ability to acquire and
by isostatic 7y ago
"This stressed out a lot of email marketers, who quite rightly realised that the new regulations would have a significant effect on their ability to acquire and market to customers via their email address"
"The overwhelming majority of commercial email sent today contains tracking pixels and tracking links, these are used to uniquely identify individuals so that opens and clicks can be correctly attributed to them"
Good.
While spammers may have a problem, people don't.
If I want your tracking pixels and emails then I'll opt in.
- Phenix88be 7y agoI agree, this is a good thing, the GDPR was design to stress those people and give the control back to the user.
- microcolonel 7y agoWhat surprises me more is that tracking pixels even work anymore. What email clients don't bother to filter them out?
- giancarlostoro 7y agoDo any email clients block tracking pixels? My understanding is that they block images by default but if you choose to view them you will load all the tracking pixels.
- iamacyborg 7y agoArticle author here - Tracking pixels aren't blocked per se in most email clients but you're correct that they rely on images being loaded.
- giancarlostoro 7y agoThanks for answering, it's curious enough that I'm now looking into Thunderbird plugins to see if there's one to block (or try to) tracking pixels.
- microcolonel 7y agoI guess I'm just not that familiar with HTML email anymore in general, and when I do read it I generally do not have images regardless. I always assumed that disabling 1x1px images would be first on the list of mitigations against this technique. I was under the impression that email clients, in addition to an option to block images in general (usually on by default for an address or origin), generally prevented the loading of remote images. Embedding images directly into emails is fine, isn't it?
- iamacyborg 7y agoDepending on the platform used to send the email, it's trivial to change that pixel to any other image, ie a brand logo in the template. On the whole, disabling images entirely is the only real defence against email tracking.
- microcolonel 7y agoOr I guess the mail server could just always precache all images at the time of receipt. Then nothing new happens when the mail is read. I think somebody here is describing GMail's approach that way.
- iamacyborg 7y agogmail's cache hides a users location but you can still tell when they've opened an email, and you can still get a ton of information if they click a tracked link within the email as well.
- accatyyc 7y agoThen email servers would have to download billions of images of which 99% the corresponding email won't even be opened
- giancarlostoro 7y agoThe easiest way is to disable them by default which is why Thunderbird defaults to not loading from senders not yet whitelisted, which thankfully most HTML email has the text on the email, it's those darn emails that have all the text in an image that I get suspicious of and delete (usually spam / probably malware). It would be nice to see plugins to block them for sure. I use Thunderbird for work, keep forgetting to use it for regular email. At least even webmail email services block pictures by default now, probably to prevent browser exploitation, never know when someone finds some rogue PNG exploit.
- dessant 7y agoGmail, among others. Gmail proxies remote content when the email is opened, so the IP address of the user is not disclosed, but the time and number of opens can be tracked. Google could proxy and cache remote content in emails when they are accepted by Gmail servers, and that would render Gmail users untrackable by third-parties.
- sempron64 7y agoThe decision to not cache was a compromise with email marketers after many years. Originally, gmail would not show embedded images by default at all: https://nakedsecurity.sophos.com/2013/12/16/gmail-takes-image-loading-out-of-users-hands-heres-how-to-take-it-back/ https://nakedsecurity.sophos.com/2013/12/16/gmail-takes-imag...
- Nextgrid 7y agoI am surprised that Apple's built-in email clients on both macOS and iOS load remote content by default. One of the first things I disable when I set up a new machine.
- isostatic 7y agoDo they? I've just loaded a gmail email on my phone, it says "This message contains unloaded emails", with an option to load them.
- Shivetya 7y agoWell recently they were used in an underhanded means by the DOJ against a Seal team member they were prosecuting, they did it to his lawyers https://www.theguardian.com/us-news/2019/may/13/navy-seals-lawyers-received-emails-embedded-with-tracking-software https://www.theguardian.com/us-news/2019/may/13/navy-seals-l...
- giancarlostoro 7y ago> While spammers may have a problem, people don't. Marketing spammers maybe, but now scammers and malware spammers have the floor instead. Laws only stop the law abiding citizens from doing their thing, it sure doesn't stop the criminals from.... being criminals.
- satanspastaroll 7y agoNot having marketing spammers is still better than having spammers and scammers
- giancarlostoro 7y agoThere's usually an unsubscribe button for marketing spam, and if there isn't I usually block their email. You can't do that with scammers / illegal spam.
- martin_a 7y agoHave you ever clicked one of those? I've never been sure if that wouldn't have worsened the situation by giving feedback that this is an active mail address managed by somebody.
- giancarlostoro 7y agoI click it all the time when I feel I'm getting way too many emails. If I feel like it's not some malware spam at least but genuine marketing trying to sell me something. Every now and then I go back to all those "rewards programs" emails and unsubscribe to the least relevant ones to me.
- ses1984 7y agoIf it's from a legitimate company in American jurisdiction they are legally obligated to stop sending emails if you click unsubscribe. I suppose that piece of information has some nonzero value that you are giving up in exchange to not be contacted by that company. If you filter just a single address that address can change. If you filter their domain you might lose legitimate correspondence.
- mytailorisrich 7y agoIf they send you an email it means that they obviously have your email address, which I believe is considered personal data. Now, what additional personal data are collected by tracking pixels? > these are used to uniquely identify individuals I would say that this isn't the case. It is to check that the email was read.
- number6 7y agoThats correct. But Tracking or Profiling is Opt-In too
- lmkg 7y agoYou can tracking pixels to track per-user engagement. You can also use tracking links to connect the email address to website activity. As you say, it's possible to use these to track in the aggregate, but many platforms allow tracking by individual. You are correct that the email was already personal data. But, GDPR requires that each new use of data be transparently communicated and legally justified (which may or may not mean consent), even if it's only using data you already have. The fact that they have already identified the user does not resolve the issue--GDPR still cares when you collect more data about a known user. Meaning, even though you are justified using the email address to send the newsletter, you may not be in the clear building an engagement profile associated with that email. Which, apparently, some email marketers do.
- iamacyborg 7y agoNot some, all email marketers do. There's nothing stopping them either, they're entitled to do so, given they obtain consent for that data processing.
- icebraining 7y agoDo they? Remember that under the GDPR, a five-page ToS with a "I consent" button at the end is not considered valid. In particular, the user must consent for each use of the PI separately. I don't remember ever seeing a specific consent box for building an engagement profile.