This post knows where you're viewing it from (Lemmy doesn't proxy external images)
This post knows where you're viewing it from (Lemmy doesn't proxy external images)
Note: This post now archived and as such no longer works
This post knows where you're viewing it from (Lemmy doesn't proxy external images)
Note: This post now archived and as such no longer works
This is possible because Lemmy doesn't proxy external images but instead loads them directly. While not all that bad, this could be used for Spy pixels by nefarious posters and commenters.
Note, that the only thing that I willingly log is the "hit count" visible in the image, and I have no intention to misuse the data.
The best part is it also works on DMs, so it's trivial to get any persons IP address. Want an admins IP address? Just DM them a message with an embedded spy pixel.
I emailed the lemmy developers about this a few weeks ago since IMHO it's a pretty big security issue, no reply.
Not really.
Same, I'm using an app.
Jerdoa
"an unknown (mobile?) client"
Well, nice try anyway.
sPoOky
Same, woo for my security I guess!
You are viewing this from Apple Mail on MacOSX…. Ummm, okay. If you say so…
iCloud relay perhaps?
uBlock Origin? NoScript? Internet Explorer?
Liftoff, and the device has Blokada5 running but it didn't block that.
It got my OS right, but browser wrong. Tested both Librewolf and Vivaldi, which it sees as Firefox and Chrome.
This is because librewolf reports itself as firefox for privacy, and vivaldi does the same thing with chrome. Their is no vivaldi string in their user agent.
That makes sense. Vivaldi uses a chrome user agent most of the time, unless you use a Microsoft service, in which case it uses a Microsoft Edge user agent.
You are viewing this from a (rand() % 2 == 0) ? "android" : "apple"
phone.
The post know where I am because it knows where I am not.
“You are viewing this from bile Safari”
Right client, wrong operating system. It knows I'm using Leomard, but it thinks I'm on iOS. I suspect it doesn't handle architecture detection well on Apple Silicon machines.
Very interesting, I think I'll probably be using Tor for my Lemmy usage from now on, or at least a VPN since this does have the potential to be used maliciously in personal DDoS attacks.
"You are viewing this from ome Mobile web View on Andr".... Uhhhh... Ok?
Probably the image is cached.
Whatever Software you're using to view this caches the image
What is the functioning process of this?
A simple GET request.
Your assumption that doxxing is somehow the only valid privacy/security concern is misguided.
This is Lemmy, you are willing to let people know you use windows??