![]() |
WORTH A LOOK: Guide to Fax to Email and Email to Fax Services
Did you know you can now send and receive faxes via email? That's right, you don't even need a fax machine! Click here to compare online fax services. |
|
|||||||
| FastMail.FM General Discussions Everything that does not belong in the help or feature requests Forums goes here. This includes discussion about FastMail.FM policies, development (such as stylesheet development),FastMail.FM support sites like the Wiki, and so forth. |
![]() |
|
|
Thread Tools |
|
|
#1 |
|
Member
Join Date: Jan 2004
Location: Chicago
Posts: 92
|
Tracked email and privacy
I know Fastmail already has the feature where tracking webbugs are blocked, but ReadNotify.com appears to use several different methods to violate privacy, and one or more of the methods they're using is getting past Fastmail. I know because I signed up for a trial ReadNotify account and sent myself an email to test it out, and as soon as I opened the message in the Fastmail web interface (but not in my desktop IMAP client) I got a read notification.
Here's one link about it-also read the comments because one of them goes into good detail about every html and css tag that can be abused to violate privacy in this way, and here's a link that shows the html source of a ReadNotify message so you can see some of the tricks they pull (IFRAME, and using the gopher protocol). In ReadNotify's own words, some of the methods they use. This really creeps me out. I hope Fastmail can block these pigs. |
|
|
|
|
|
#2 |
|
The "e" in e-mail
Join Date: Oct 2003
Location: San Diego, CA
Posts: 2,550
|
Why not just bounce all messages sent through the readnotify.com servers? Can you post the headers so the rest of us can see what those servers are?
|
|
|
|
|
|
#3 |
|
Member
Join Date: Jan 2004
Location: Chicago
Posts: 92
|
I'm not sure how I would do that, it sounds like a capital idea to me. The test email I sent myself looked like it came from me, so how do I tell and block them?
|
|
|
|
|
|
#4 |
|
The "e" in e-mail
Join Date: Oct 2003
Location: San Diego, CA
Posts: 2,550
|
The message headers should give it away. Let's have a look at them (with your address removed).
|
|
|
|
|
|
#5 | |
|
Member
Join Date: Jan 2004
Location: Chicago
Posts: 92
|
Quote:
|
|
|
|
|
|
|
#6 |
|
Ultimate Contributor
Join Date: Sep 2001
Location: Australia
Posts: 11,452
|
Can you try this on the beta server, and tell us if webbugs are still not squashed fully?
|
|
|
|
|
|
#7 |
|
The "e" in e-mail
Join Date: Apr 2003
Location: USA
Posts: 2,978
|
Keep up the fight (and let us know - yes I'm lazy)
I know it's asking too much, but later you might even want to look into others. List I have from the forum:- http://didtheyreadit.com - http://havetheyreadityet.com - http://msgtag.com - http://postofficer.com/p (& http://postofficer.com/aet) - http://readnotify.com - http://returnreceipt.com - http://sentthere.com - http://trackthis.cc Some are intentionally more conservative. Anyways Googling or web directory search will probably turn up gazillion others... |
|
|
|
|
|
#8 |
|
The "e" in e-mail
Join Date: Oct 2003
Location: San Diego, CA
Posts: 2,550
|
I managed to Google up a sample message from Readnotify in some mailing list archive last night, and I notice that both that message and the one you posted were relayed through the server my.guardpuppy.com. A Whois lookup shows that guardpuppy.com and readnotify.com are registered to the same person.
So, at least for the moment, it looks like rejecting mail relayed through a guardpuppy.com server should keep these scumbags out of your inbox. |
|
|
|
|
|
#9 | |
|
Cornerstone of the Community
Join Date: Apr 2004
Location: Nottingham, UK
Posts: 691
|
Quote:
Neil |
|
|
|
|
|
|
#10 |
|
Member
Join Date: Jan 2004
Location: Chicago
Posts: 92
|
I just tested on the beta server as well, and neilj is right: they never realize that I've opened the message.
There's still a problem, though it pales in comparison it's still creepy: they're hijacking URLs! Instead of http://www.opera.com/m2 my link in my email is now http://www.ztgnknginf66gk.readnotify....opera.com/m2/. As soon as I clicked the link, they registered me as having viewed the message. Can anything be done about the link hijackings or am I asking for too much effort in return for too little reward? |
|
|
|
|
|
#11 |
|
Member
Join Date: Jan 2004
Location: Chicago
Posts: 92
|
LrdVader-nice job spotting the guardpuppy thing.
|
|
|
|
|
|
#12 | |
|
The "e" in e-mail
Join Date: Oct 2003
Location: San Diego, CA
Posts: 2,550
|
Quote:
What would be nice, if it's not too much work and too prone to false positives, would be a SpamAssassin test for Readnotify tricks in the body of the message. Even with a low score like 0.1, that would still add a nice header tag that a script could be set to filter on. |
|
|
|
|
|
|
#13 | |
|
Cornerstone of the Community
Join Date: Apr 2004
Location: Nottingham, UK
Posts: 691
|
Quote:
Neil |
|
|
|
|
|
|
#14 |
|
Member
Join Date: Jan 2004
Location: Chicago
Posts: 92
|
I'll just hover over every link prior to clicking it, which I do anyway. It's not likely anyone corresponding with me would use one of these services anyway, and they would hear quite an earful if I discovered they did.
|
|
|
|
![]() |
| Thread Tools | |
|
|