Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

1. I do not expect emails from my friends and family to include tracking pixels. So yes, this is not just "weird," but also social-engineering: It exploits people who are not Superhuman users, who do not opt into being tracked, and do not expect to be tracked by emails from friends and family.

2. If there is a tracker, the second thing I expect is that it tells people whether I read the email. I do not expect it to also track location. Well, being an HN user I do. But the typical email recipient (who I repeat is NOT a Superhuman user) does not expect to be geotagged when they open an email from friends/family.

3. If I do figure out that I'm being geotagged, I am going to think it's like Google, some sort of thing that goes into the cloud and is sold to optimize my advertising or what-not. Nobody opens an email and thinks that the person who sent it to them will be told where they were when they opened the email.

In my opinion, "weird" is not the word for any of the three things I've listed. It is not nearly strong enough to describe taking advantage of people's (possibly flawed) model for how email and tracking works.



Every time you reply to an email it includes your location, and almost no one knows this either.

Everyone who uses email is basically agreeing to a contract that they haven't read, and wouldn't understand even if they had read. Usually this doesn't matter, but occasionally weird things happen as a result.

That's not to say that anything goes, but it's also important to look at this in context.


"Every time you reply to an email it includes your location, and almost no one knows this either."

No it doesn't.

If you're talking about leaking client IPs in received headers, some providers (including gmail) have excluded this information for some time.

If you're talking about the timezone in the Date header. Fair enough. Someone can figure out what timezone you're in. Unless you change it to just be UTC or whatever.

Or are you talking about something else?


> If you're talking about leaking client IPs in received headers, some providers (including gmail) have excluded this information for some time.

Sure, in the same way that some mail clients (like Thunderbird) don’t load tracking pixels by default. But if we’re going to talk about ethics and user expectations, I think that’s a reasonably fair comparison.


I don't think it's like that at all. I just sent my self an email from a gmail account, yahoo account and outlook live account. Not one of them included my IP address in the headers. I think your information is a bit out of date.


I mean in that case these services are just sending the email on your behalf, so it's their IP address that is included. But if you're sending the email yourself then it will be your IP address.


That might have been a valid argument in 1999, but in 2019 it's difficult to send an email yourself from a consumer IP address and actually have anybody on a major provider receive it. Major email infrastructure doesn't support those users any more; they're mostly irrelevant to the discussion.


I don't think he meant sending the mail yourself to the destination domain directly (which would indeed be blocked due to plenty of reasons), I think he meant connecting to your email provider's SMTP (over the 587 "submission" port so it's not blocked by ISPs), authenticating and then sending the email. The provider will relay the email to its final destination, but your original IP would still appear in headers.


Gmail et al. still add the headers if you send the message through an actual email client though, just not if you send it through the web client. And I'm guessing that the vast majority of email users still use email clients at least some of the time, given that they work much better on your phone and they're the easiest way for consumers to have a backup of their email.


I run my own mail server, and my mail is never rejected. It is still an option, and it works as well as it ever did.


What about when using email clients? They are far from rare.


>it includes your location

To be specific, it shows your public IP, right? Using a VPN means this will not show your location, correct?


It shows your IP address to the machine you submit your message, and that SMTP server doesn't add the IP address in a Received: header, as mine does not, nobody else will know what IP address you used.


Same with Superhuman. They get location from the IP address, so using a VPN would "mask" your real location.

Disclosure: SH user.


I think the problem is person on receiving end doesn't know that. also, at marketing level it happens with all mailchimp and other campaigns, but this is so explicit at the individual level.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: