4 ms·
We offer a block remote content feature. There is no foolproof way to load any remote content without possibly exposing email open information.
by amilich 3y ago
We offer a block remote content feature. There is no foolproof way to load any remote content without possibly exposing email open information.
- mike-cardwell 3y agoMy point was that defaults matter, and your default is not privacy preserving. Yet you claim to be a "privacy first" service. There are many email clients which do not download remote content by default. I would argue that they preserve privacy better than Skiff does.
- amilich 3y agoWhat mail providers block all remote content by default?
- mike-cardwell 3y agoI don't have a list for you. I would have thought you'd have this data yourself given the business you're in.
- amilich 3y agoYes - privacy focused mail providers offer this as an option but do not enable it by default. Mainstream mail providers do not even have it as an option.
- mike-cardwell 3y agoAre you joking? I've never even come across an email client or provider that doesn't have options to toggle loading remote images. What mainstream mail providers don't have this option? The only difference between your option and other providers are: 1. Yours doesn't even work. It still loads the remote images. It just doesn't display them 2. Yours has the wrong default. Your "block remote content" option is even worse than just forcibly loading remote images and not even having the option in the first place, because it tricks the user into thinking that it will preserve privacy, like it does for other providers, but it does not preserve privacy in your case as it still loads the images.
- amilich 3y agoNo, I'm not joking. We do have this option, and it's consistent with the defaults across private mail providers. Still waiting for your list of the ones that don't load images by default. It does not load the images. That's just patently false disinfo.
- mike-cardwell 3y ago> No, I'm not joking. We do have this option, and it's consistent with the defaults across private mail providers. Still waiting for your list of the ones that don't load images by default. If you read back, you'll see I wrote email clients and providers. But I'll note that you have not provided a list of clients or providers with privacy defaults that are worse than yours. > It does not load the images. That's just patently false disinfo. It absolutely does. You have no idea how your own product works. I literally showed you a tool where you (or anyone else) can verify this yourself in a few minutes: https://www.emailprivacytester.com https://www.emailprivacytester.com - By the way, I am the author of this tool, and your email product is the least privacy preserving email product on the market right now.
- amilich 3y agoI just compared Skiff and Tutanota on your tool. The results were the same. Thank you for confirming this.
- mike-cardwell 3y agoI just tested Tutanota and it does not have the same bug that skiff has. I think you must be having trouble understanding what the bug is. In skiff, even if you choose to not load remote images, when you view an email that has remote images, although it doesn't show the images, it does fetch them. I look at my web server logs, and I can see it happen. Emailprivacytester.com also shows it happen. I have tested this several times now. I do not know what your difficulty is. Perhaps you should pass this on to somebody more technical than yourself at your organisation who can actually understand and diagnose the problem.
- mike-cardwell 3y agoEven more worrying, I just went into the settings and toggled on "Block remote content" and then sent my self another test through https://www.emailprivacytester.com https://www.emailprivacytester.com, and it still triggered a remote content load when I viewed the email. It's saying that the images were blocked, but that didn't stop them being fetched. Entirely defeating the point of the setting.
- mike-cardwell 3y ago> There is no foolproof way to load any remote content without possibly exposing email open information. Also, this is false. You could download all remote content at time of delivery. That way it would be impossible for a sender to differentiate between an email simply being delivered and one being read.