Note: This post now archived and as such no longer works

An external image showing your user-agent and the total "hit count"

  • TriLinder@lemmy.mlOP
    link
    fedilink
    English
    arrow-up
    2
    ·
    2 years ago

    This is possible because Lemmy doesn’t proxy external images but instead loads them directly. While not all that bad, this could be used for Spy pixels by nefarious posters and commenters.

    Note, that the only thing that I willingly log is the “hit count” visible in the image, and I have no intention to misuse the data.

    • Shadow@lemmy.ca
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 years ago

      The best part is it also works on DMs, so it’s trivial to get any persons IP address. Want an admins IP address? Just DM them a message with an embedded spy pixel.

      I emailed the lemmy developers about this a few weeks ago since IMHO it’s a pretty big security issue, no reply.

      • TheEntity@kbin.social
        link
        fedilink
        arrow-up
        0
        ·
        2 years ago

        I think you’re overestimating the value of someone’s IP address. Not much one can do with it unless someone really tries to expose themselves.

  • Steeve@lemmy.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 years ago

    You are viewing this from a (rand() % 2 == 0) ? "android" : "apple" phone.

  • TheGreatFox@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    2 years ago

    It got my OS right, but browser wrong. Tested both Librewolf and Vivaldi, which it sees as Firefox and Chrome.

    • L_Acacia@lemmy.one
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 years ago

      This is because librewolf reports itself as firefox for privacy, and vivaldi does the same thing with chrome. Their is no vivaldi string in their user agent.

  • Porrny@lemmynsfw.com
    link
    fedilink
    English
    arrow-up
    0
    arrow-down
    1
    ·
    2 years ago

    You are viewing this from Apple Mail on MacOSX…. Ummm, okay. If you say so…