Gmail for android silently overwrites links in your emails, so it can track what you open

I clicked on a link inside an email from a privacy service, and was surprised to see they used google tracking for their stuff, so I opened it in thunderbird and behold, it had no tracking.

But the worst part is… if I went back again and long pressed the link on gmail, it showed the link preview, WITHOUT the tracking. There’s some kind of rule, so try it first on a new, unopened email, without long clicking. You’ll need something to intercept it because the browser will just redirect to the main link.

Imagine the mailman looking at you, noting down which letters you open, it’s crazy.

I noticed this thanks to link eye, an app that intercept all browser links and shows a list of supported apps, so you can redirect to the preferred one. It also displays the link, it’s abandoned but still working.

I’m 99% sure I have all the privacy stuff set correctly. I suppose it may also happen on desktop/ios, but I have no way to check it

Also fedia is not showing me a field to set the post title, so I’m sorry if everything ends up in the title or if the title is empty

long press

opened link

  • Taleya@aussie.zone
    link
    fedilink
    English
    arrow-up
    1
    ·
    20 hours ago

    Does the same thing from gsheets. Cracks me up seeing it try to track an Aspera ssh tunnel that’s literally only accessible from one IP.

  • pulsewidth@lemmy.world
    link
    fedilink
    arrow-up
    62
    ·
    2 days ago

    Yes, this is shitty and grey pattern behaviour designed to fool even more seasoned email users into giving up more privacy.

    However, do not use gmail for anything if you value your privacy. Failing that, there is no need to ever use the Gmail app, can easily use any of a hundred other mail apps on Android.

  • Jason2357@lemmy.ca
    link
    fedilink
    arrow-up
    40
    ·
    2 days ago

    Absolutely everything is tracked in Gmail. Spend an extra second hovering over the send button for Sara’s email and it will be in their data model for you. That’s the whole point of Gmail for them.

    Even without redirect links, it would be entirely possible to use other app mechanisms to track which links are clicked.

  • Kissaki@feddit.org
    link
    fedilink
    English
    arrow-up
    20
    ·
    2 days ago

    Outlook replaces weblinkes in emails as well, to a “safelinks” redirect URL. Certainly a security feature, but man it’s annoying. Not just the redirect, and the potential tracking, but when a readable URL to my build server build turns into a multiline cryptic unreadable mess and then pollutes my webbrowser history - fuck.

    I already thought about a Thunderbird extension where I can replace them back to their original.

    (My workplace uses Outlook.)

      • Kissaki@feddit.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        When I access through Thunderbird via IMAP the emails have been rewritten. It’s not local to the Outlook client software.

        I think my webmail is outlook.office.com, dunno if that’s the same as outlook.office365.com. It may be a org/account setting managed by my org. Maybe you also don’t receive emails with unlabeled links, where it’s very obvious that they’re replaced. On linked text, only if you notice the URL you’re opening.

    • Kairos@lemmy.today
      link
      fedilink
      arrow-up
      2
      ·
      2 days ago

      It’s literally never done anything except add delay. It shouldn’t be showing the fucking link if its dangerous especially because there’s ways around it.

    • ayush@reddthat.com
      link
      fedilink
      arrow-up
      8
      ·
      23 hours ago

      @Blackmist@feddit.uk - I have heard people make comments on the same lines before. Generally my response is - “oh, so that makes it ok?”

      But I want to do better. Could you please help me understand what’s the underlying point you were trying to make? Thank you!-

  • KuroiKaze@lemmy.world
    link
    fedilink
    arrow-up
    4
    arrow-down
    2
    ·
    2 days ago

    Did you think an amazing system like Gmail was free? I know when I use stuff like that what the cost is but I get virtually nothing important in email anyway.

  • ramenshaman@lemmy.world
    link
    fedilink
    arrow-up
    9
    ·
    2 days ago

    Within the last week or two I started fully committing to Tuta and I don’t give out any of my gmail addresses for anything. I wish I’d done it sooner.

    Soon (maybe this week) I’m going to buy a device to use as an Immich server. People online say they’ve had good performance with a Raspberry Pi 5 so I’ll probably try that first.

    Fuck Google.

  • Anon518@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    11
    ·
    2 days ago

    It’s not just their mobile app. Gmail on desktop browsers (firefox) does something similar. You can see it in your “history” after clicking a link.

  • slazer2au@lemmy.world
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    1
    ·
    2 days ago

    Not shocking as how else does google pay for Gmail if it can’t build a better advertising profile on you?

  • HubertManne@piefed.social
    link
    fedilink
    English
    arrow-up
    4
    ·
    2 days ago

    gmail does this in general. whats really annoying is you can use the browser copy clean link and im not sure if they are not following standards or what but you still get the google encapsulated link.

    • Flagstaff@programming.dev
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 days ago

      That useless “feature” has never worked for me, I think literally once. I use my own AutoHotkey link-cleaning script that I have yet to find out how to port over to Linux.

  • foxfell@lemmy.ml
    link
    fedilink
    arrow-up
    7
    arrow-down
    1
    ·
    2 days ago

    Hi, just tested and it’s not doing this to me. Links are showing, copying, and opening correctly.