Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Phone
Jul 30, 2005

親子丼をほしい。

Joementum posted:

Google is going to start allowing Gmail to display forms with postbacks inside the email

https://github.com/ampproject/amphtml/issues/13457

there's no way that this will be abused

Adbot
ADBOT LOVES YOU

Chris Knight
Jun 5, 2002

me @ ur posts


Fun Shoe
https://twitter.com/zackwhittaker/status/963219939845959681

Potato Salad
Oct 23, 2014

nobody cares


Hey, so I was thinking: what if we put dynamic content in legal agreements?

Shaggar
Apr 26, 2006
theres a simple solution to forms in emails and that's to block emails with forms in them

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Shaggar posted:

theres a simple solution to forms in emails and that's to block emails with forms in them

that’s where you’ll be foiled by the inevitable rise of easy-to-use E2E e-mail encryption

Potato Salad posted:

Hey, so I was thinking: what if we put dynamic content in legal agreements?

I think it’s called “new precedents”

Potato Salad
Oct 23, 2014

nobody cares


Take legal documents, hash them, and put them in the block chain.

But, actually.

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
just make Twitter the only legal form of communication imo

bob dobbs is dead
Oct 8, 2017

I love peeps
Nap Ghost

this is gonna be the next antivaxxing
guarantee you, this is it

Main Paineframe
Oct 27, 2010

Joementum posted:

Google is going to start allowing Gmail to display forms with postbacks inside the email

https://github.com/ampproject/amphtml/issues/13457

the phishing potential is gonna be hilarious

Joementum
May 23, 2004

jesus christ

Main Paineframe posted:

the phishing potential is gonna be hilarious

"Important Documents Enclosed! Enter your username and password to show the full email!"

Angela Merkle Tree
Jan 4, 2012

the definition of open: "mkdir android ; cd android ; repo init -u git://android.git.kernel.org/platform/manifest.git ; repo sync ; make"
College Slice
i work for an edm provider and i can't wait to :regd08:

quote:

All network requests must be proxy-able to ensure that user anonymity is preserved
good thing it's impossible to generate recipient-specific links

now we can reliably track opens/views in gmail without relying on the user allowing image loading

Potato Salad
Oct 23, 2014

nobody cares


Joementum posted:

"Important Documents Enclosed! Enter your username and password to show the full email!"

Don't kinkshame Watchdox

Joementum
May 23, 2004

jesus christ

Angela Merkle Tree posted:

good thing it's impossible to generate recipient-specific links

yeah, the first thing i thought when i read that was "uhhh, they know mail merge exists...... right?"

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Angela Merkle Tree posted:

i work for an edm provider and i can't wait to :regd08:

like someone skrillex tier or or someone more obscure

NyetscapeNavigator
Sep 22, 2003


infosec alex jones

Hed
Mar 31, 2004

Fun Shoe

Cocoa Crispies posted:

like someone skrillex tier or or someone more obscure

Phoenixan
Jan 16, 2010

Just Keep Cool-idge

NyetscapeNavigator posted:

infosec alex jones
youtube linux people pretty much fall into these lines yeah

rjmccall
Sep 7, 2007

no worries friend
Fun Shoe

Cocoa Crispies posted:

like someone skrillex tier or or someone more obscure

into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood
into the blood

Asshole Masonanie
Oct 27, 2009

by vyelkin

Cocoa Crispies posted:

like someone skrillex tier or or someone more obscure

lmao

Angela Merkle Tree
Jan 4, 2012

the definition of open: "mkdir android ; cd android ; repo init -u git://android.git.kernel.org/platform/manifest.git ; repo sync ; make"
College Slice
we almost called our app "buzzword EDM" until i mentioned this would happen lol

e: actual acronym is "electronic direct marketing" which is a nice way to say "legally-compliant spam"

Achmed Jones
Oct 16, 2004



rjmccall posted:

into the blood

this made my day

like a beggar’s dog tasting the wind

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

I though gmail always fetched the images whether or not the user showed them or opened the email, and then rewrote the links to reference their proxy cache. wouldn’t they do something similar here?

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


Potato Salad posted:

Take legal documents, hash them, and put them in the block chain.

But, actually.

I literally went to a meeting where this was being touted yesterday.

as usual, it's nothing anyone couldn't do already if they wanted to (but nobody does) but with blockchains!!!

edit: if you bolted a REST service onto Git it would do exactly what they were talking about, I should build my own and call it gitChain

Powerful Two-Hander fucked around with this message at 12:04 on Feb 14, 2018

Wiggly Wayne DDS
Sep 11, 2010



Subjunctive posted:

I though gmail always fetched the images whether or not the user showed them or opened the email, and then rewrote the links to reference their proxy cache. wouldn’t they do something similar here?
yeah that's what i figured as well

Pile Of Garbage
May 28, 2007



just checked and yeah that's deffo what google does. the images are cached and then loaded via something like https://mail.google.com/mail/u/0/?u...38b17&zw&atsh=1

edit: that link is from one of my e-mails but it disnae matter as they require auth

4lokos basilisk
Jul 17, 2008


Powerful Two-Hander posted:

if you bolted a REST service onto Git it would do exactly what they were talking about, I should build my own and call it gitcoin

ftfy

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

Subjunctive posted:

I though gmail always fetched the images whether or not the user showed them or opened the email, and then rewrote the links to reference their proxy cache. wouldn’t they do something similar here?

I think they're only fetched once you open the email. So spam senders can still tell if you opened it and when, but not get your origin IP or cookies.

It was a halfway privacy measure so they could switch image loading on by default.

4lokos basilisk
Jul 17, 2008


mrmcd posted:

I think they're only fetched once you open the email. So spam senders can still tell if you opened it and when, but not get your origin IP or cookies.

It was a halfway privacy measure so they could switch image loading on by default.

but if google caches the images when the mail is received, not when the mail is opened...?

univbee
Jun 3, 2004




https://twitter.com/paklonginvul/status/961694761580036096

fins
May 31, 2011

Floss Finder
I think the AMP stuff will last just long enough to goatse the entire gmail userbase.

mrmcd
Feb 22, 2003

Pictured: The only good cop (a fictional one).

Penisface posted:

but if google caches the images when the mail is received, not when the mail is opened...?

Yes I'm saying they don't do that. At least, that's what this email marketing professional spammer blog post from 5 years ago says: https://blog.mailchimp.com/how-gmails-image-caching-affects-open-tracking/

quote:

Using cached images is a fine idea for Gmail, but it has the potential to mess with open tracking for ESPs. Fortunately, MailChimp can still detect the first request for the open-tracking pixel. This won’t interfere with the count of “unique opens” you get in your reports, but it could prevent us from seeing multiple opens per subscriber.

Maybe it's changed since then. I don't actually care enough to find out. :effort:


edit: It could also be motivated entirely by capacity than preserving open rates for marketers. There's possibly a lot of dormant gmail accounts and spam that's never opened out there, and you can't keep the cache around forever on the hope they might request it.

mrmcd fucked around with this message at 14:06 on Feb 14, 2018

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.



forked already I see!

Pile Of Garbage
May 28, 2007



from what i observed google only fetches when you open the message. there's zero reason for them to retrieve and cache images upon message receipt because i'm pretty sure the gmail app doesn't download messages by default so why bother when the user may immediately archive/delete the message?

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/enigma0x3/status/963832760224894981

https://twitter.com/hexwaxwing/status/918227574106607616

Shaggar
Apr 26, 2006
I guess that's a vulnerability but its bypassing one of 3 or 4 prompts the user has to ignore to get the payload to launch. at that point you'd probably be better off sending them an actual executable.

Shame Boy
Mar 2, 2010

lmao i signed up for IHG's (holiday inn's parent comany I guess?) dumb rewards program because it cuts like $20 from the price of the room and when creating an account instead of a password you pick a 4 digit numeric pin :allears:

i sure hope the credit card info i had to enter to book the hotel isn't tied to that!

e: holy crap it sent me a separate email to thank me for "updating" each individual field on the sign-up form i filled out to create the account, this site is amazing

Shame Boy fucked around with this message at 20:00 on Feb 14, 2018

Mozi
Apr 4, 2004

Forms change so fast
Time is moving past
Memory is smoke
Gonna get wider when I die
Nap Ghost
better make it the same as your ATM pin, just to be safe

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

the most important thing about defense in depth is that it lets you justify a weakness in any layer, until you discover too late that they can be made to line up

apseudonym
Feb 25, 2011

Subjunctive posted:

the most important thing about defense in depth is that it lets you justify a weakness in any layer, until you discover too late that they can be made to line up

That's a tad cynical, at least for people who really do defense it's so that one of those weaknesses doesn't totally loving you everytime.

Adbot
ADBOT LOVES YOU

post hole digger
Mar 21, 2011

Schadenboner posted:

I mean, if it were "Mine coin for us while you read this story" and it were well-behaved and respectful of the reader's computer and it reliably hosed-off after the tab was closed I wouldn't even be against it.

But from the intersection of crypto and web ads no good can come.

ya in theory i think its actually pretty smart but in reality probably lol

  • Locked thread