*removed externally hosted image*

  • TriLinder@lemmy.ml
    hexagon
    ·
    1 year ago

    This is possible because Lemmy doesn't proxy external images but instead loads them directly. While not all that bad, this could be used for Spy pixels by nefarious posters and commenters.

    Note, that the only thing that I willingly log is the "hit count" visible in the image, and I have no intention to misuse the data.

    • targetx@programming.dev
      ·
      1 year ago

      Nice example!

      I think proxying everything through lemmy would have a pretty big bandwidth/scalability impact. I expect the lemmy clients dont send any unique user info on these image requests so not sure how useful it would be as a spy pixel? Maybe I'm missing something :-)