6 ms·
Easy: Make the "Dear <username>" part of the email an image. Boom, deduplication fooled. (Also, they don't currently seem to do anything like you're suggesting
by codeflo 13y ago
Easy: Make the "Dear <username>" part of the email an image. Boom, deduplication fooled.
(Also, they don't currently seem to do anything like you're suggesting.)
- surrealize 13y agoWith google's machine learning brain trust, I think they could still do a pretty good job deduping. Maybe not perfect, but I'd bet on them to win an arms race. Edit: ah, codeflo and EGreg are right. I was just thinking about the task of determining that the images serve the same role in each message (which I'm sure google could do a good job of). But (as they point out) in the "Dear <user>" case they'll still have to show the right image to the right user. Although, as Nacraile and jaxn say, if they load all those images eagerly they'll remove the value of those unique tracking images, and impose a cost on the sender.
- codeflo 13y agoThere's a huge difference between something that they might do, in theory, at some point, using vaguely magic machine learning technology, and what that they are currently doing, right now, to address the privacy concerns over a change that they already rolled out to millions of users.
- EGreg 13y agoAre you saying Google will try to guess and reconstruct "Dear Marge" in the same font as "Dear John" instead of requesting both from the origin server?
- backlava 13y agoGetting the font right is the easy part. Figuring out the formerly occluded pixels in the background image is the hard part.
- ceejayoz 13y ago> But (as they point out) in the "Dear <user>" case they'll still have to show the right image to the right user. They could do a "This sender appears to be attempting to track you. We have disabled images as a precaution. Click here to load." Scary enough to the average user it'd probably kill the the technique very quickly.
- Silhouette 13y agoScary enough to the average user it'd probably kill the the technique very quickly. I'm not sure about that. It's nothing that desktop clients such as Thunderbird haven't been doing for years. I don't see any remote images in any e-mail until I click to say load them, and this works in much the same way that plug-in elements like Flash and Java are now click-to-show in various browsers. Numerous marketers and mailing list services still use the technique to track an approximation of reader numbers, though.
- rspeer 13y agoNah, nobody pays attention to warnings attached to Gmail messages after having seen so many of them. A particular example of crying wolf that comes to mind is the yellow box that says, "HEY! THIS SENDER ISN'T WHO THEY SAY THEY ARE!", which usually means that someone just forwards their .edu address to Gmail.
- scoot 13y agoOr just cache unique images on delivery...
- Nacraile 13y agoWhat if google just immediately fetches images for all received messages, regardless of deliverability? They can dedupe wherever possible, but the sender still ends up with no information about whether the message was delivered, much less read.
- jaxn 13y agoAND it could create a dis-incentive to load up an email with unique images since as soon as you send the email out all of those gmail addresses are coming right back at your server to request the images.
- jblow 13y agoAnd then you can cause Google to DDoS someone else's site by sending out spam containing lots of image URLs.
- prostoalex 13y agoUsers would have to have previously agreed to "Always load images from domain.com"
- vidarh 13y agoThe cost of a new domain per e-mail campaign would be trivial. (and "normal users" do click the show images links)
- xur17 13y agoYou can somewhat do this with the current system. I had no problems sending an email with 10 10mb images. Google happily fetched all 10 of the images off my server. Not sure if they limit it at some point, but if a server accepts urls such as: http://i.imgur.com/9Y5FDz7.jpg http://i.imgur.com/9Y5FDz7.jpg http://i.imgur.com/9Y5FDz7.jpg?1 http://i.imgur.com/9Y5FDz7.jpg?1 http://i.imgur.com/9Y5FDz7.jpg?2 http://i.imgur.com/9Y5FDz7.jpg?2 etc... Google would fetch each separately. Send this out to a bunch of people, and it seems problematic. I'm going to be optimistic, and assume they built in some sort of limiting, but who knows.
- nly 13y agoAnd Google could just mark any mail from sources who pull these shenanigans as spam
- webjprgm 13y agoYup. Though I suspect my university's alumni newsletter also has tracking images in it. I haven't checked, but if I were them I'd use a tracking image.
- anatari 13y agoAlthough I'm sure it's possible to fool their image hashing algorithm, I doubt this will. Image hashing algorithms are designed to be resistant to small changes in the image and more advanced ones can generate hashes that determine how similar one image is to another. I haven't tried this, but you can probably see a proof of this using google image search. Add some text to an image, and see if Google image search can find the original.
- webjprgm 13y agoProcedurally generated fractal backgrounds with random seed, that might work? Anyway, I think it would be perfectly fine if Google matched up emails with similar content and where there was one image that was unique for everybody just remove it, maybe with a note to the user in that case. Do NOT have a "click to load images" button. If users can't ever see them then it completely destroys spammers' ability to use them even for a rough sampling. I would love to see spam as an advertising method be completely destroyed. It won't be, because even without tracking it is still easy and useful to spam out lots of ads, but this would help.
- jpadkins 13y agothey dont have to even edit the image. they can just put a tracking id in the image metadata.