Note: This post now archived and as such no longer works

54 points

This is possible because Lemmy doesn’t proxy external images but instead loads them directly. While not all that bad, this could be used for Spy pixels by nefarious posters and commenters.

Note, that the only thing that I willingly log is the “hit count” visible in the image, and I have no intention to misuse the data.

permalink
report
reply
38 points
*

I guess it knows that it’s unknown

permalink
report
reply
6 points

I guess mobile clients screw with their fingerprinting method. Also doesn’t work on Slide.

permalink
report
parent
reply
2 points

Wait what, slideforreddit works for lemmy now?

permalink
report
parent
reply
2 points

looks like sync in the screenshot, i think thats what they meant

permalink
report
parent
reply
1 point
*

It sees my phone fine (Chrome on Android)

permalink
report
parent
reply
3 points

It’s the same for me

permalink
report
parent
reply
3 points

I guess Donald Rumsfeld was right.

permalink
report
parent
reply
32 points

This is true for most link aggregators that attempt to render external content. Proxying images and videos would dramatically increase costs.

If you care that much about anonymity, use a VPN/Tor and a browser with advanced fingerprinting resistance — tor browser, mullvad browser, or firefox with resist fingerprinting = true.

permalink
report
reply
5 points
*
Deleted by creator
permalink
report
parent
reply
2 points

That makes sense. But I guess there’s these questions: at what resolution? For how long? Maybe the status quo is such because it’s simpler code. The project is still relatively young. I wonder where/how we can discuss these things?

permalink
report
parent
reply
2 points
*
Deleted by creator
permalink
report
parent
reply
1 point

It still adds up fast especially if you run an instance that stores to s3 with a cdn. My mastodon server racked up 1k in cdn usage one month before I switched to local storage no cdn.

permalink
report
parent
reply
2 points

At the very least setting referer policy headers and such would be a good addition.

permalink
report
parent
reply
-2 points

That’s great except those browsers often don’t work.

permalink
report
parent
reply

Hexbear.net stays winning, external embeds are domain whitelist-only until pictrs adds proxying support, and blurred by default.

Good PSA tho, I’d honestly encourage other instances to do the same but it requires dev effort that I know not everyone has, and upstream isn’t quite as paranoid about this stuff.

For reference:

permalink
report
reply
3 points

Cool, didn’t know some Lemmy instances did this

permalink
report
parent
reply
2 points

Is there a pull request for it though?

permalink
report
parent
reply

as far as I know upstream lemmy doesn’t want it and is waiting on pictrs proxying support. If I’m wrong though our code is public, I’m sure a dev would be happy to put together a PR,

permalink
report
parent
reply
9 points

*removed externally hosted image*

permalink
report
reply
2 points

Looks like your home instance hexbear.net is filtering external images.

permalink
report
parent
reply

Technology

!technology@lemmy.ml

Create post

This is the official technology community of Lemmy.ml for all news related to creation and use of technology, and to facilitate civil, meaningful discussion around it.


Ask in DM before posting product reviews or ads. All such posts otherwise are subject to removal.


Rules:

1: All Lemmy rules apply

2: Do not post low effort posts

3: NEVER post naziped*gore stuff

4: Always post article URLs or their archived version URLs as sources, NOT screenshots. Help the blind users.

5: personal rants of Big Tech CEOs like Elon Musk are unwelcome (does not include posts about their companies affecting wide range of people)

6: no advertisement posts unless verified as legitimate and non-exploitative/non-consumerist

7: crypto related posts, unless essential, are disallowed

Community stats

  • 3.7K

    Monthly active users

  • 2.6K

    Posts

  • 41K

    Comments

Community moderators