Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on lemmy.ml

15 replies

This is possible because Lemmy doesn't proxy external images but instead loads them directly. While not all that bad, this could be used for Spy pixels by nefarious posters and commenters.

Note, that the only thing that I willingly log is the "hit count" visible in the image, and I have no intention to misuse the data.

50
jayandpreply
sh.itjust.works

I guess mobile clients screw with their fingerprinting method. Also doesn't work on Slide.

6
lemmy.world

This is true for most link aggregators that attempt to render external content. Proxying images and videos would dramatically increase costs.

If you care that much about anonymity, use a VPN/Tor and a browser with advanced fingerprinting resistance — tor browser, mullvad browser, or firefox with resist fingerprinting = true.

31
lemmy.sdf.org

That makes sense. But I guess there’s these questions: at what resolution? For how long? Maybe the status quo is such because it’s simpler code. The project is still relatively young. I wonder where/how we can discuss these things?

2

It still adds up fast especially if you run an instance that stores to s3 with a cdn. My mastodon server racked up 1k in cdn usage one month before I switched to local storage no cdn.

1

This reminds me of those old forum signatures which looked like a signpost, and showed your IP address, browser, OS etc. They were pretty popular back then (when no one cared about their privacy), to the point that some folks even made parody versions of those signatures (like changing the IP to "127.0.0.1" or writing a funny message).

6

You reached the end

This post knows where you're viewing it from (Lemmy doesn't proxy external images) [ARCHIVED] | Spyke