When you share a YouTube video using the share button it adds “si=some_unique_code” to the URL. If you don’t remove that it shows your personal account to anyone who receives it so that they can chat directly with you. For a lot of people this is their real name.
I’ve seen it all over Lemmy so I figured I’d mention it here! You only need the stuff before the question mark in the URL to let others see the video.
This can also be turned off in your YouTube settings under the privacy section. The setting is “channel visibility for shared links”. It will still add the si code for tracking though.
I use this on Android to sanitise links I sent out as well as clean incoming links before viewing them.
https://play.google.com/store/apps/details?id=com.svenjacobs.app.leon
Facebook and Instagram do the same btw. Just FYI.
I just share the URL from the browser.
Even on mobile: I don’t use the YouTube app. On Android, this is a no-brainer, since you can run Firefox and uBlock Origin and bypass all the ads. On iOS it is a bit more dicey, but still advantageous to forego the app. Currently DuckDuckGo can bypass the ads for free. If you don’t mind paying, Wipr2 can also do it, in Safari. Then you just put a web shortcut to YouTube and bam, ad-free YouTube. Shitty icon though (it’s the regular icon in a white squircle). Either way, share from the browser, not YouTube.
Also, of course you can remove all the extra shit from the URL if you know how. That wisdom is lost on younger generations, but innate to older ones (who grew up around tech, like Millennials; or younger Gen X who adopted it at a young age — not like these iPad babies you have now).
I don’t see how it’s a generational thing. I remember when every link included the page type at the end, meaning there was nothing that could be truncated. If you don’t know what si stands for or don’t know that anything after a ? Is tracking bullshit, then you simply don’t know. It’s a “knowledgeable person” thing that can be learned at any time. I’ve pointed it out and many people I know still don’t care
People can’t even unanimously agree on when each generation starts and ends (see terms like “zillenial” or “xillenial”) so I’d even go so far as to say it’s a completely redundant concept in the colloquial sense. Obviously most people care more about continuing to use the “kids these days” rhetoric so it hardly matters regardless, but it doesn’t make it any less ridiculous.
Blurry deliberations are typical. As time goes on, “millennial” will become more accurate as the differences between xennial and zillennial become smaller and smaller in comparison to differences between _ennial and alpha or beta or delta. I just take issue with acting like direct url interface was the experience of a generation, and not a short-lived blip for the gen pop that has already been forgotten, especially as full url purpose has shifted to something arguably evil.
Blurry deliberations are typical.
Yes, though my point that I wanted to add is that people seem to treat generational terms as if they’re a fact of reality instead of a very shaky conceptualization of cultural differences between birth groups that are already influenced by a lot more factors than just when people are born. It’s much more of a spectrum than a strict range of demographics inherent to humanity.
As a web developer, everything after the ? is actually parameters for the request. Anything could be in there, even important stuff (though hopefully nothing identifying, since that is extremely unsecure). You will likely break functionality if you delete everything without knowing what it is.
if it’s obfuscated, then it’s assumed to be malicious
Usually parameters are easy to understand. Like the time parameter in yt URLs, which is t=180 (meaning 180 seconds from the beginning of the video). Usually, parameters that are a string of seemingly random letters are UIDs or tracking parameters. Whenever I see a URL with one or multiple of those, I start deleting them and seeing if the URL still works. In 90% of the cases, it still does. Amazon is one of the worst offenders, with usually 4 or 5 random looking parameters that can be deleted without affecting the functionality of the URL.
I don’t see how it’s a generational thing.
People who grew up when smartphones were already a thing might never have needed to learn how the Internet and URLs actually work. To a lot of everyday users nowadays, the Internet is just a series of smartphone or tablet apps you switch between. I used to think that the spread of the Internet into more segments of society would create a society of computer nerds, ha ha ha ha ha nope.
It would be great if link cleaning and auto-mirroring was part of the lemmy UI itself.
The problem is that there is an almost infinite way to design these kinds of URLs, so maintaining a database of what should be stripped out isn’t trivial.
Yeah, would be best within particular client implementations. Not core Lemmy tho. Too many ways to do this and high maintenance.
I think that would probably be a client implemented feature, not a Lemmy one. I also don’t design social medias, so I don’t really know.
Along similar lines be careful of the images you post if you location tag your photos. A lot of the larger websites will strip the location data by default but some do not. I’ve saved a handful of photos from reviews off the internet and now have people’s home addresses where the photo is of the product in their living room or whatever.
If you go to the ‘map’ section of your photos app it arranges them by location.
You can turn location tagging off globally when photos are taken or usually when you go to share a photo there is an option buried in a menu to strip location data(on mobile).
You can turn location tagging off globally
That’s one of the first things I did when configuring my kids phones.
I have an iOS shortcut that remove exit meta data.
You should also known that TikTok does this by default and the generated code is impossible to remove afaik, it’s part of the video identifier.
So when sharing a tiktok video always download it and share the file.
I recommend downloading it anyway, since that doesn’t require people to use tiktoks site, but if you paste the vm link yourself into a browser, it’ll redirect to the canonical link, without the tracker.
til people don’t reflexively strip out everything after the ? unless you know exactly what it’s doing
tbf, it’s intentionally designed to be malicious and deceiving
Hey look at this video: https://youtube.com/watch
yup. all you need is the v=vkjlhaswlikuj3hg4 thing. that is the only thing you need, as it identifies the video. Strip everything else.
Not sure if my anxiety is justified here, but I am not tech savvy whatsoever. And I worry about all the things I’m doing that’s probably completely giving myself away that I’m just unaware of. I didn’t know about this at all.
pretty much everything that has a “share” button does this. it’s not to help you share the link more easily than copying from the address bar - it’s to harvest your data
Even voyager gives a link to vger.to when you hit share instead of a direct link to the thing you want to share. No idea what they are doing with it (other than trying to redirect it to the app). Maybe it’s set up to just use the localhost and that’s all it does, but I usually strip that part out because I have no idea either way.
vger.to solely exists so i can text dumb memes to my non tech inclined friends, and they open in voyager on their device instead of the web.
It’s a dumb service and has zero analytics other than cpu disk bandwidth use lol
Would you be able to add an
open in browserbutton, or a way to just copy the normal link as well? I can’t see any way to do it in voyager. It’s probably my only issue with it.Yeah, this is why that vger.to link is so annoying for me (other than triggering the reaction to the dark pattern, even if it isn’t exploiting it like what seems to be the industry standard these days), because most of the time when I use the share thing, I’m really just trying to get the url to open it in my browser, so that “open in voyager” link is the exact opposite of what I want, though I can see how it might be nice for actually sharing the link with others.
It is . But now you know . Don’t freak - and you might even learn how to install a privacy based browser, vpn, or operating system. Keep the tinfoil har dude and best of luck
I never knew users could get the profile from it, I always thought that was a youtube internal thing. thats not cool
It’s a very recent change
i would be surprised if it is true that “If you don’t remove that it shows your personal account to anyone who receives it so that they can chat directly with you”, and a search just now didn’t find anything to substantiate that.It’s a very recent change
is it though? if so, how do you actually find out the profile name from thesiparameter?obviously tracking parameters from URLs should be removed in any case, but afaict only google can use this to find which user generated the link.after some more reading i found conflicting reports but i think this might actually be happening; apparently it is only visible in the app?
I’ve seen it when opening shared links in the browser but it’s possible that you need to be logged in for it to show
Always remove those search parameters before pasting links, even to my friends. F—k these big tech platforms, I’m not giving you any sharing data!
Same here, the awful thing is if they click on it, they cannot see the comments under the video and can only “reply” to you. Not sure what that should do, since the link has already been shared.
Get YouTube Sharing URL sans Sharing / Tracking Code (for iOS users)
If it helps, for Androids share YT link to something like Untracker to remove unwanted nonsense from the url which you can then pass on safely (also works for things such as Amazon links).
For images, share to something such as Imagepipe first to remove location data. Other apps such as Aves Libre gallery or image Toolbox also strip this data but Imagepipe is simple - share image to it & it passes the image directly to your messaging app after stripping the data
It can’t share my personal account if I’m never signed in.
Additional PSA: TikTok does the same. Also Instagram, but in my experience it doesn’t reveal the sharing user (yet).
Insta does. if you open it on web and you didn’t log in, the popup that beg you to log in will also include the user who shared it.
What the fuck
Instagram absolutely does reveal the sharing user
On android, urlcheck is a great app to modify URLs before sharing or opening. For this problem, you can use the json editor, and add the following two entries with small a regex I wrote:
"shorten Youtube": { "regex": "^https?:\/\/(?:[a-z0-9-]+\\.)*?youtube\\.com\/(.*)&.*", "replacement": [ "https:\/\/youtube.com\/$1" ], "enabled": true }, "shorten Youtu.be": { "regex": "^https?:\/\/(?:[a-z0-9-]+\\.)*?youtu\\.be\/([^?]*)?.*", "replacement": [ "https:\/\/youtube.com\/watch?v=$1" ], "enabled": true },A button to shorten the link appears in urkcheck when the pattern matches. You can all auto shorten them by replacing “enabled”: true
With
“automatic”: trueWow. This is awesome. Thank you! I will have to see if the dev has a donate button.
FWIW I had to noodle with the spacing of your json after copying from Lemmy (Voyager android app) but I got it to work. Thanks for sharing!














