Block 1x1 images

What about external images?

Could they screw things, in the same way?


What about external images?

Could they screw things, in the same way?

--- End quote ---
Yeah, that's what I'm talking about, really :P

A malicious image that is loaded in the users' browser.


I wouldn't call this a security issue but a feature. If a site makes use of analytics it may be a good idea to not have this since some analytics systems use 1x1 images to recognize stuff.


--- End quote ---

It's not a bad thought. I get where you're coming from. Problem is that there are several legit uses for 1x1 images, so you're running the risk of breaking things if you just ban them completely.

However, there are no legit uses that I can think of for 1x1 images in posts, sigs, avatars or PM's. If only those were restricted then that should nobble the wallies without breaking anything legit.

Is it really worth it to parse a post to get this information about an image in a post? It means you'd have to send off a request just to get the image first to figure out the size/dimensions etc. I'd much rather just limit the ability for people to posts images in the same way I'd like to limit who can post links for spamming.

Fair nuff.


