Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Google Meddling with URLs in Emails, Causing Security Concerns (hackaday.com)
32 points by vaccinator on Oct 21, 2020 | hide | past | favorite | 5 comments


I saw this too.

I have a gmail account, but I actually blocked google.com in my hosts file on windows. So when I would click ANY link in gmail it would fail. It looks like the link has to pass through some google gateway or something before redirecting to the intended destination. Of course if I just copy the link url and paste in a new tab it works. But yeah google fiddles with the URL for sure.


To be the devil's advocate, Google doesn't learn this way anything they wouldn't get to know without this intermediary link.

Another thing pops to mind, though: will false positives prevent people from accessing intranet links that Google fails to resolve (from outside the internal network).


They'd also learn which user logged in via the browser loaded the link, which is different from which user may have received the link in an IMAP email box.

For example, if you're checking G Suite IMAP mail for user@biglargecompany.com, and your browser is logged in to wingsfan6969@gmail.com, Google now knows who works where.

This could be used for competitive advantage, as Google is in a lot of markets.


> To be the devil's advocate, Google doesn't learn this way anything they wouldn't get to know without this intermediary link.

They'd know if and when the link was clicked.


They do learn if you clicked the links or not...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: