Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

[Update 2: I just tested with a newly-created Gmail account and the feature did not seem to have been rolled out to the new account yet.]

[Update: I'm not sure when this feature will actually be rolled out. I think my test below automatically displayed the image because my own email address appears to be implicitly a whitelisted sender (even though "images from this sender are always displayed" doesn't appear for it). Whether Google will alter the behavior when they actually deploy this feature, I don't know.]

[Original message:]

I just tested and, yes, Gmail only loaded the referenced image when I clicked on the message to open it within Gmail. I can't be sure, because perhaps if I had waited an hour without opening the message, Gmail would have automatically loaded the image anyway. But in reply to mherdeg below, the evidence suggests that, yes, Gmail plans to opt everybody in to sending "read receipts" by default for HTML messages that reference images.

I'm surprised by Google's statement that the previous behavior of prompting was "to protect you from unknown senders who might try to use images to compromise the security of your computer or mobile device."

I realize this was a benefit, but I always thought the main purpose was for privacy --- not to betray to the email sender when I opened the email. My guess is that Google did not view this as a privacy setting, or they probably would not have forcibly changed everybody's setting.

It's doubly strange that they did so without a notice inside Gmail that they did so -- just a blog post.



I just ran the same test and can confirm the results. Google will only load your image if you open the email, which means Google has just opted-in all users to mail receipts.

I don't use any Google services outside of small tests like this, but it still makes me concerned for how this will affect the privacy of people I know.


"Email open" tracking just got a lot more reliable for all mass email & marketing automation vendors.

On the flip side, those same solutions can no longer set a persistent cookie with the image, so persistent tracking based on the initial email open will stop working.


> "Email open" tracking just got a lot more reliable for all mass email & marketing automation vendors.

Has it? If Google's proxy is caching images, then "email open" tracking might have broken entirely. All the sender would see is that their email has been opened once by the proxy -- for all gmail addresses put together.


http://example.com/trackingimage.php?email={yourusername}@gm...

Or, if they snip the GET variable for whatever reason (I don't see them doing this):

http://example.com/gmail/{yourusername}/trackingimage.php

Or even:

http://example.com/{emailidfromadatabase}/trackingimage.php

This tactic is already in use by most mass email companies.


I'd imagine that they are going to de-dup the images they proxy which means email marketers need to generate unique images per mail and that means no more 1-pixel tracking images.

A solution would be 1-pixel high tracking lines - a 1 x 128 pixel wide image that encoded 0 and 1 as two RGB colors adjacent to the mail's background color in the visual spectrum so the difference isn't noticeable would encode a sha-1 hash placed in the url.

  http://example.com/tracking-line/{hash}.png


Mass-email senders probably would put a unique identifier in the image url (different for all users), so Google will open each image, because it can't know before loading them that it's the same image.


Or they could retrieve every image sent to a gmail address immediately, regardless of whether you viewed it or not.

That would essentially render open statistics meaningless and would let Google cripple another industry after the promotions tab and 'not provided.'

I really hope they don't because it's such valuable information when creating email copy...


I agree they could do it, but people upthread are suggesting that Google doesn't do that, and only loads the image when you open the message.


they could track if an email was opened twice

first one = Google

second one = user


I would imagine that google caches the images so there would be one request instead of two.


you are right, I didn't think on that


> "Email open" tracking just got a lot more reliable for all mass email & marketing automation vendors.

No, it didn't. If you had chosen the option to ask before displaying external content -- which existed and applied to non-image content and, without which selection, email-open tracking by external non-image content was already reliable -- then the new setting to ask before displaying external images is selected for you by default.

If you hadn't selected that option before, you weren't protected from "email open" tracking.


Interesting. The fact that they don't even address this aspect of the change in the blog post makes you wonder if this is a deliberate or incompetent move. This should be obvious for anyone who works with email and easy enough to describe in layman terms the blog post. Who is the target group for the blog?


I assume the target of the blog is Gmail power users moreso than email markers. I highly doubt that the Gmail team didn't think this through before launching. As far the reason for not explaining how this works, who knows?


> Google will only load your image if you open the email, which means Google has just opted-in all users to mail receipts.

If you didn't have the "ask before displaying external content" option set before this change, you were "opted-in" to read receipts already -- its just that, due to protections designed to stop other malicious use of images, you were incidentally protected against images as the vector for silent read receipts.

With this change, you are better protected against the malicious uses of images the default-not-to-display option was designed to protect against, but exposed to external images as a vector for read receipts if you hadn't chosen to display external content only after confirmation. If you did choose that previously, then you also got the new "ask before displaying external images" chosen by default -- so if you were protected from senders injecting read receipts before, you still are now. If you weren't before, you aren't now, but then that's not really a change.


It's also weird that they didn't explain the how behind this line:

> Instead of serving images directly from their original external host servers, Gmail will now serve all images through Google’s own secure proxy servers.

In most cases, the unique identifiers are embedded in the URLs themselves, so simply serving through a proxy is ineffective. Should I blindly trust that you, Google, did the right thing?

Edit: looks like Google isn't stripping out the query parameters AND it isn't proxying for iOS devices! This is by far the least effective set of decisions... http://blog.movableink.com/gmails-recent-image-handling-chan...

I wonder if this change is a result of backlash over the promotions tab. These type of referenced images are most commonly used in marketing campaigns and were from businesses likely to pay good money to AdWords. As a concession for fewer overall impressions, perhaps, these groups got Google to let them track easier? The whole thing smells fishy.


They'll probably retrieve and cache every image as soon as the email is received which would effectively render open statistics meaningless for GMail addresses.


They don't, and it doesn't. See the post by @danielnr.


They don't yet. I wouldn't be surprised if they do the same as with 'not provided' where they slowly make the data less reliable until they finally just turn it off altogether.


I appreciated the lack of pictures of large penises that accompanied spam. And of course the fact that you didn't get a tracking pixel fetched. So I wonder if they are going to fetch the image from their servers, cache it, and then show it. Cutting off a supply of information for email marketers, whom they will offer to supply 'opening' information for people who use the new Gmail Promotions feature. (ok that is a lot cynical)


There is still a way to track opens for images but it is now impossible to detect device and location.


That has got to be a neat trick. If a Google server does the fetch, how would you detect opens other than theirs?


Uniquely name at least one image per outgoing email where the image name is tied to a recipient ie a316f002a5d080a613dce89a4ad8f9a9.gif uniquely identifies myemail@gmail.com. If google doesn't fetch the image until you open the email you can also determine open time. If they request and cache all images at the time the email is received regardless of its having been opened then this doesn't work.


Thanks, the next question is if gmail sees a bunch of emails from the same sender with these hash-named images, I wonder whether they will squash them.

How this plays out will be interesting to watch.


They are already scanning the content of the emails so there's nothing stopping them from determining if the images between emails are the same regardless of name, and even then just sending down whatever they have cached, 1px transparent gifs are still common for this. Could break some a/b testing software though. You could see marketers move to including a unique image per recipient like a gravatar. If it were me I'd just include something like the github avatars in the footer of every message. Google can learn that those are tracking images and block them but will they?


"Thanks, the next question is if gmail sees a bunch of emails from the same sender with these hash-named images, I wonder whether they will squash them."

Are you saying squash the sender or squash the tracking images?

I hope gmail doesn't start squashing my emails because it contains a tracking pixel.


Easy: a unique image URL for each recipient. Seems like a huge win for marketers and spammers.


> Update: I'm not sure when this feature will actually be rolled out.

FTA: This new improvement will be rolling out on desktop starting today and to your Gmail mobile apps in early 2014.


I don’t think you quite understand the changes here, no "read receipts" are sent, any analytics sent only point to the Google proxy processing the images, no individual recipients nor their actions are revealed.

See how marketers are scrambling to adjust to this change:

a.) Gmail is now requesting all images from proxy servers (googleusercontent.com), which incorrectly situates users in its headquarters in Mountain View, California when images are downloaded. This impacts the ability to geo-target image content for those Gmail users who are affected by the changes. (Note: Local Maps using zip codes appended as query parameters are unaffected.)

b.) Gmail is stripping the user-agent headers from the client request, which eliminates the ability to determine the Gmail user’s device and target image content appropriately.

c.) Gmail is removing the cache-control headers from the responses, which forces the user’s images to be stored in their browser’s cache for up to a day. This only impacts live image content if a Gmail user re-opens the email after the first open.

...

http://blog.movableink.com/gmails-recent-image-handling-chan...

Basically their only avenue for now is mobile email which will soon follow in adopting this method.


OP was using "read receipts" colloquially, to include "tracking images with a unique code embedded in them".

And, as such, OP's claims are exactly correct.

The only way this would not be true is if GMail pulled every image in every email, even if it's not read by the recipient. Given GMail's usage of the term "proxy server" in their blog post, as well as the tests by the OP and others on this thread, this appears not to be the case.


Gmail seems to be proxying the images through: https://ci5.googleusercontent.com/proxy/ and my understating the polling happens when Google receives the email not when it's opened.


I don't understand how a proxy will protect me from an image loaded as

http://marketer.com/4b3403665fea6.jpg

where that hash is used to link to my email address


> I don't understand how a proxy will protect me from an image loaded as

It will protect you from it being as a read receipt if (and I'm not sure if this is the case, though it should be trivial to test by sending email with images served from a site you control to an email you control without opening it) Google requests the image once it has received the email.


If you read other comments, a number of people have done the trivial test and confirmed that images aren't requested until you open the email.


Wow this is really dreadful.


Now it will seem to the sender that 100% of e-mails sent to Gmail recipients have been opened, rendering actual measurement impossible. A unique ID is useless if all unique IDs are requested all the time.

I'm sure they built-in rate-limiting to prevent DDOSing the sender's image server...


Apparently not. First, only messages read in gmail.com and Gmail mobile clients (not any other email clients). And apparently the image is not requested from the sender until the message is opened. Finally, apparently any querystring parameters will continue to function as usual.


Or possibly they could use heuristics to detect a newsletter and deliver the first fetched image to every recipient of the same newsletter.


Even if Gmail loads tells the marketer that you have opened the message (as people are pointing out, it's a bit unclear), there are still some advantages.

It protects you from the guys at marketer tracking your user-agent, your ip address (which gives a rough geo-ip), the number of times you opened the email, etc. It's unclear to me whether the images could set cookies before (they probably did), but even without that, they could just use etag-tricks, or stuff like that, to track you cross-sites.

Marketers might now know when you open the message, but proxying the image prevents them from getting more precise information.

(No idea exactly how much of this and more Google does, obviously, but they put themselves in position to do it)


It will if the images are cached.


No it wouldn't. You can't tell anything about what's on the other end of random_unique_number_65984654.jpg




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: