If you want to get away with something evil, hide it inside of something boring. That’s what they’re doing.

Appreciate the links. Thanks!

Thank you, this is exactly the kind of info I was looking for. I figured someone was on top of this and the reddit dipstick was just being overly dramatic as usual.

Right, but I think the difference here is lemmy allows users to embed these in their markdown text.

When it comes to posting on lemmy I’d also consider bringing up that old bromide: don’t post anything you wouldn’t want your mother to see.

At least for now, anyway.

random angry guy just hates lemmy for whatever reason

There is definitely some of that at play here. I am hoping some smarter cybersec folks without the anti-lemmy-rage-bias can weigh in on t.

I am not a cybersecurity expert. And these are good questions. The problem is certainly not unique to Lemmy.

However, my (limited) understanding of it the opposing opinion is. 1. This is bad for privacy (marketers and other bad actors use these to track down your IP and other metadata) and 2. It should have been thought of before now and already had some protections put into place.

Thanks. Not a fan of guilt by association of this type. The idea of FUD has been around for decades. It’s not inherently crypto or inherently anything. It’s just a useful acronym for a tactic some people use.

The Spy Pixel problem
Unsurprisingly, some folks on raddle and reddit seem to have a big problem with lemmy. A lot of it is pure FUD. However, this appears to be a valid security concern: https://raddle.me/f/fediverse/166674/lemmy-is-so-much-like-email-it-even-brought-back-spy-tracker Any thoughts on how fixable this is? Of course the general consensus on reddit is "lemmy devs are clueless and dangerous". I'm pretty sure a lot of it is one guy with multiple alt accounts, tho. He has a Joe McCarthy attitude about lemmy because of one of the primary devs.

VeraCrypt was created as a fork of TrueCrypt because TrueCrypt underwent a code audit and they felt it wasn’t secure enough. Older version of VeraCrypt were also found to have vulnerabilities. It’s a never ending race between castle walls and cannonballs when it comes to this stuff. Maybe the journalist had TrueCrypt or an older unpatched version of VeraCrypt.

I’ve blocked their ads for years. I support content creators by buying merchandise and with Patreon.

After hearing about this, I’ve decided to give YouTube Premium a try. It seems like an easier and more consistent way for me to support creators. I watch YT almost daily, and get a lot of value from it. I hate ads and refuse to watch them, but Premium users don’t see them.

I wouldn’t blame anyone for walking away from YouTube over this. But for me at least, this was kind of a no-brainer.

I know Google tracks users and targets us with ads. I’m deep in their ecosystem anyway, and rely on their services for work, hobbies, and managing my data. I am stuck with them, unfortunately.

I do block what I can (Meta, Microsoft, Amazon) with Pi Hole and browser extensions. But there’s no total escape from an internet footprint, short of dropping off the grid. I’m dependent on Alphabet to live my lifestyle, for better or worse.