PogoWasRight.org

Menu
  • About
  • Privacy
Menu

Gmail Image Proxy Changes Have Privacy, Security Implications

Posted on December 14, 2013July 1, 2025 by Dissent

Michael Mimoso reports:

Google’s decision to automatically display images in Gmail messages has security experts on edge about the privacy and security implications of the move. Of particular concern is the ability of an attacker, or marketer, to learn whether messages are being opened, as well the possibility of an attacker spiking an image URL with additional attacks that could lead to denial of service conditions or worse.

Read more on ThreatPost.

No related posts.

Category: Online

Post navigation

← 9th Circuit Takes New Look at DNA Collection
Minnesota lawmakers demand information on controversial phone-tracking devices →

1 thought on “Gmail Image Proxy Changes Have Privacy, Security Implications”

  1. Jason says:
    December 14, 2013 at 2:20 pm

    This seems to be more a question of implementation. If Google pulls the image immediately and caches it, it actually increases privacy because the originator won’t know whether or not the recipient opened the email or not. However, the article indicates they are repulling the image every time the email is opened, which is not good. I also take issue with the idea that a malicious attacker could execute a DOS attack on a server by embedding an image from that server. I’m betting Google has either already thought of that or will implement something soon to prevent such an attack.

Comments are closed.

Search

Contact Me

Email: info[at]pogowasright.org
Security Issue: security[at]pogowasright.org
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]pogowasright.org

Research Report of Note

A report by EPIC.org:

State Attorneys General & Privacy: Enforcement Trends, 2020-2024

Categories

Recent Posts

  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit
  • How Palantir shifted course to play key role in ICE deportations
  • U.S. Judge Blocks Trump From Cutting Medicaid Funding For Planned Parenthood In 22 States
  • India backs off mandatory ‘cyber safety’ app after surveillance backlash
  • Judge orders Trump administration to halt warrantless immigration arrests in District of Columbia
  • EU court says websites on the hook for user privacy harms

RSS Recent Posts at DataBreaches.net

  • Marquis data breach impacts over 74 US banks, credit unions
  • Virginia Twins Arrested for Conspiring to Destroy Government Databases
  • Cyberattack on Puerto Rico IT vendor Truenorth hits 3 agencies
  • Easy Question, Complicated Answer: What Does It Take to Stop Workers From Snooping?
  • Update on Dos-OP’s report on Nova RaaS
©2025 PogoWasRight.org. All rights reserved.