7 ms·
[Update 2: I just tested with a newly-created Gmail account and the feature did not seem to have been rolled out to the new account yet.] [Update: I'm not sure
by keithwinstein 13y ago
[Update 2: I just tested with a newly-created Gmail account and the feature did not seem to have been rolled out to the new account yet.]
[Update: I'm not sure when this feature will actually be rolled out. I think my test below automatically displayed the image because my own email address appears to be implicitly a whitelisted sender (even though "images from this sender are always displayed" doesn't appear for it). Whether Google will alter the behavior when they actually deploy this feature, I don't know.]
[Original message:]
I just tested and, yes, Gmail only loaded the referenced image when I clicked on the message to open it within Gmail. I can't be sure, because perhaps if I had waited an hour without opening the message, Gmail would have automatically loaded the image anyway. But in reply to mherdeg below, the evidence suggests that, yes, Gmail plans to opt everybody in to sending "read receipts" by default for HTML messages that reference images.
I'm surprised by Google's statement that the previous behavior of prompting was "to protect you from unknown senders who might try to use images to compromise the security of your computer or mobile device."
I realize this was a benefit, but I always thought the main purpose was for privacy --- not to betray to the email sender when I opened the email. My guess is that Google did not view this as a privacy setting, or they probably would not have forcibly changed everybody's setting.
It's doubly strange that they did so without a notice inside Gmail that they did so -- just a blog post.
- danielnr 13y agoI just ran the same test and can confirm the results. Google will only load your image if you open the email, which means Google has just opted-in all users to mail receipts. I don't use any Google services outside of small tests like this, but it still makes me concerned for how this will affect the privacy of people I know.
- finnh 13y ago"Email open" tracking just got a lot more reliable for all mass email & marketing automation vendors. On the flip side, those same solutions can no longer set a persistent cookie with the image, so persistent tracking based on the initial email open will stop working.
- nkoren 13y ago> "Email open" tracking just got a lot more reliable for all mass email & marketing automation vendors. Has it? If Google's proxy is caching images, then "email open" tracking might have broken entirely. All the sender would see is that their email has been opened once by the proxy -- for all gmail addresses put together.
- danielnr 13y agohttp://example.com/trackingimage.php?email={yourusername}@gmail.com http://example.com/trackingimage.php?email={yourusername}@gm... Or, if they snip the GET variable for whatever reason (I don't see them doing this): http://example.com/gmail/{yourusername}/trackingimage.php http://example.com/gmail/{yourusername}/trackingimage.php Or even: http://example.com/{emailidfromadatabase}/trackingimage.php http://example.com/{emailidfromadatabase}/trackingimage.php This tactic is already in use by most mass email companies.
- dugmartin 13y agoI'd imagine that they are going to de-dup the images they proxy which means email marketers need to generate unique images per mail and that means no more 1-pixel tracking images. A solution would be 1-pixel high tracking lines - a 1 x 128 pixel wide image that encoded 0 and 1 as two RGB colors adjacent to the mail's background color in the visual spectrum so the difference isn't noticeable would encode a sha-1 hash placed in the url. http://example.com/tracking-line/{hash}.png
- Wilya 13y agoMass-email senders probably would put a unique identifier in the image url (different for all users), so Google will open each image, because it can't know before loading them that it's the same image.
- mtrimpe 13y agoOr they could retrieve every image sent to a gmail address immediately, regardless of whether you viewed it or not. That would essentially render open statistics meaningless and would let Google cripple another industry after the promotions tab and 'not provided.' I really hope they don't because it's such valuable information when creating email copy...
- Too 13y agoInteresting. The fact that they don't even address this aspect of the change in the blog post makes you wonder if this is a deliberate or incompetent move. This should be obvious for anyone who works with email and easy enough to describe in layman terms the blog post. Who is the target group for the blog?
- michaelmior 13y agoI assume the target of the blog is Gmail power users moreso than email markers. I highly doubt that the Gmail team didn't think this through before launching. As far the reason for not explaining how this works, who knows?
- dragonwriter 13y ago> Google will only load your image if you open the email, which means Google has just opted-in all users to mail receipts. If you didn't have the "ask before displaying external content" option set before this change, you were "opted-in" to read receipts already -- its just that, due to protections designed to stop other malicious use of images, you were incidentally protected against images as the vector for silent read receipts. With this change, you are better protected against the malicious uses of images the default-not-to-display option was designed to protect against, but exposed to external images as a vector for read receipts if you hadn't chosen to display external content only after confirmation. If you did choose that previously, then you also got the new "ask before displaying external images" chosen by default -- so if you were protected from senders injecting read receipts before, you still are now. If you weren't before, you aren't now, but then that's not really a change.
- anonsumus 13y agoI don’t think you quite understand the changes here, no "read receipts" are sent, any analytics sent only point to the Google proxy processing the images, no individual recipients nor their actions are revealed. See how marketers are scrambling to adjust to this change: a.) Gmail is now requesting all images from proxy servers (googleusercontent.com), which incorrectly situates users in its headquarters in Mountain View, California when images are downloaded. This impacts the ability to geo-target image content for those Gmail users who are affected by the changes. (Note: Local Maps using zip codes appended as query parameters are unaffected.) b.) Gmail is stripping the user-agent headers from the client request, which eliminates the ability to determine the Gmail user’s device and target image content appropriately. c.) Gmail is removing the cache-control headers from the responses, which forces the user’s images to be stored in their browser’s cache for up to a day. This only impacts live image content if a Gmail user re-opens the email after the first open. ... http://blog.movableink.com/gmails-recent-image-handling-changes-the-impact-and-resolution/ http://blog.movableink.com/gmails-recent-image-handling-chan... Basically their only avenue for now is mobile email which will soon follow in adopting this method.
- finnh 13y agoOP was using "read receipts" colloquially, to include "tracking images with a unique code embedded in them". And, as such, OP's claims are exactly correct. The only way this would not be true is if GMail pulled every image in every email, even if it's not read by the recipient. Given GMail's usage of the term "proxy server" in their blog post, as well as the tests by the OP and others on this thread, this appears not to be the case.
- anonsumus 13y agoGmail seems to be proxying the images through: https://ci5.googleusercontent.com/proxy/ https://ci5.googleusercontent.com/proxy/ and my understating the polling happens when Google receives the email not when it's opened.
- seanalltogether 13y agoI don't understand how a proxy will protect me from an image loaded as http://marketer.com/4b3403665fea6.jpg http://marketer.com/4b3403665fea6.jpg where that hash is used to link to my email address
- yajoe 13y agoIt's also weird that they didn't explain the how behind this line: > Instead of serving images directly from their original external host servers, Gmail will now serve all images through Google’s own secure proxy servers. In most cases, the unique identifiers are embedded in the URLs themselves, so simply serving through a proxy is ineffective. Should I blindly trust that you, Google, did the right thing? Edit: looks like Google isn't stripping out the query parameters AND it isn't proxying for iOS devices! This is by far the least effective set of decisions... http://blog.movableink.com/gmails-recent-image-handling-changes-the-impact-and-resolution/?utm_source=Movable+Ink+Newsletter&utm_campaign=0a07fae09d-December_2013_newsletter12_11_2013&utm_medium=email&utm_term=0_87cc366eea-0a07fae09d-324220977 http://blog.movableink.com/gmails-recent-image-handling-chan... I wonder if this change is a result of backlash over the promotions tab. These type of referenced images are most commonly used in marketing campaigns and were from businesses likely to pay good money to AdWords. As a concession for fewer overall impressions, perhaps, these groups got Google to let them track easier? The whole thing smells fishy.
- mtrimpe 13y agoThey'll probably retrieve and cache every image as soon as the email is received which would effectively render open statistics meaningless for GMail addresses.
- deleted 13y ago[deleted]
- ToastyMallows 13y ago> Update: I'm not sure when this feature will actually be rolled out. FTA: This new improvement will be rolling out on desktop starting today and to your Gmail mobile apps in early 2014.
- ChuckMcM 13y agoI appreciated the lack of pictures of large penises that accompanied spam. And of course the fact that you didn't get a tracking pixel fetched. So I wonder if they are going to fetch the image from their servers, cache it, and then show it. Cutting off a supply of information for email marketers, whom they will offer to supply 'opening' information for people who use the new Gmail Promotions feature. (ok that is a lot cynical)
- cglace 13y agoThere is still a way to track opens for images but it is now impossible to detect device and location.
- ChuckMcM 13y agoThat has got to be a neat trick. If a Google server does the fetch, how would you detect opens other than theirs?
- exhilaration 13y agoEasy: a unique image URL for each recipient. Seems like a huge win for marketers and spammers.
- ktsmith 13y agoUniquely name at least one image per outgoing email where the image name is tied to a recipient ie a316f002a5d080a613dce89a4ad8f9a9.gif uniquely identifies myemail@gmail.com. If google doesn't fetch the image until you open the email you can also determine open time. If they request and cache all images at the time the email is received regardless of its having been opened then this doesn't work.
- ChuckMcM 13y agoThanks, the next question is if gmail sees a bunch of emails from the same sender with these hash-named images, I wonder whether they will squash them. How this plays out will be interesting to watch.