Note: This post now archived and as such no longer works
This is possible because Lemmy doesn’t proxy external images but instead loads them directly. While not all that bad, this could be used for Spy pixels by nefarious posters and commenters.
Note, that the only thing that I willingly log is the “hit count” visible in the image, and I have no intention to misuse the data.
Interesting demo! Does this use the user agent string for identifying clients?
It does
Unknown mobile client. Yeah, I’m pretty mysterious like that.
“You are viewing this from Firefox on Windows.”
I should worry that this info is exposed?
Would be interesting to use such an embedded image to acquire some statistics on lemmy users. We could answer questions like: What percentage of lemmy users use Linux?
Can countermeasures be implemented in the clients to mitigate privacy risks, while not having to proxy images?
You are viewing this from an unkown (mobile?) client 🤔