de-anonymization hazard: Net Neutrality "promoted" post on the front page contains your IP in the hyperlink
[2 Points] fartwhif:
[1 Points] StonedNakedAndAfraid:
I'm going to copy and paste my comment from the crosspost over to this thread. You can find the original here: https://www.reddit.com/r/WatchRedditDie/comments/7jd65y/privacy_implications_net_neutrality_promoted_post/dr61i53/
Edit: It appears there is a small concern. If a user coincidentally copies and pastes the link to an add (containing the encoded JSON), and posts it somewhere, they will publicize their own IP address. This is not a concern for those operating through a VPN/Tor, because no Javascript exploit is being executed to leak your real IP.
While this seems concerning, likely this is being used by Reddit to track outside users (A.K.A. "lurkers").
Reddit does not need an IP grabbing link in order to grab your information. You can view all IP addresses used to access your Reddit account here: https://ssl.reddit.com/account-activity
Keep in mind, while you may only be able to view a set number of IP addresses, I'm willing to bet that Reddit does not keep it's promise, and all of your logs are sitting on a server somewhere.
My point is, they do not need you to clink a link to leak your identity. They are most likely using this as a means to collect information on lurking members who click links related to net neutrality. They may be doing market research depending on IP address/ISP/etc.
As described here: https://www.reddit.com/r/WatchRedditDie/comments/7jd65y/privacy_implications_net_neutrality_promoted_post/
Likely only "promoted" posts do this. To stay safe don't copy the URL, if you need to copy/paste a link URL to a "promoted" post then first click it and wait for the redirect, then copy the clean URL from the address bar.
A naughty URL is huge, hundreds of characters long and has parameters, and a clean one looks like normal readable text separated by slashes, besides the id in some links, such as /7jd65y/ in the post URL in this comment.
If anyone notices this kind of trash happening on other Reddit elements be a bro and report them here or the original post.