When you share a YouTube video using the share button it adds “si=some_unique_code” to the URL. If you don’t remove that it shows your personal account to anyone who receives it so that they can chat directly with you. For a lot of people this is their real name.
I’ve seen it all over Lemmy so I figured I’d mention it here! You only need the stuff before the question mark in the URL to let others see the video.
This can also be turned off in your YouTube settings under the privacy section. The setting is “channel visibility for shared links”. It will still add the si code for tracking though.
https://f-droid.org/packages/com.svenjacobs.app.leon
I use this, and it works really well for the big apps and services.
That app seems not as transparent as it could be since it doesnt give any detail on the removed stuff; I recommend URLCheck instead, which is fully transparent about all trackers and even lets you pick which ones to remove at will.
On my forum, youtube links get stripped of any extra url parameters. Every site should have to do that.
That’s a great extra layer of protection, but people shouldn’t rely on it and get/stay in the habit of always removing the tracking code themselves.
Yeah, it’s easily possible to set it up to save the original link somewhere hidden. Same reason why you shouldn’t reuse passwords because it’s trivial to set up a site to look like it’s doing it right from the outside but actually saves all passwords in plaintext for owners, admins, or disgruntled staff to look at later and see if it logs in to your email.
YSK PieFed automatically strips that out.
Like if you post a YouTube link, the platform detects it and automatically edits the link?
Yeah
Edit: I posted this from PieFed, and it preserved the “?si=” part of the URL, which I have since edited out by hand.
It doesn’t do it in comments, just when you make a post.
IMO You should add that detail to your top-level comment, as it’s going to be seen by more people than this clarification that definitely runs counter to how I interpreted your comment.
They might be talking about the default web interface.
That’s what I use!
Pretty cool!
Thats great!
I just share the URL from the browser.
Even on mobile: I don’t use the YouTube app. On Android, this is a no-brainer, since you can run Firefox and uBlock Origin and bypass all the ads. On iOS it is a bit more dicey, but still advantageous to forego the app. Currently DuckDuckGo can bypass the ads for free. If you don’t mind paying, Wipr2 can also do it, in Safari. Then you just put a web shortcut to YouTube and bam, ad-free YouTube. Shitty icon though (it’s the regular icon in a white squircle). Either way, share from the browser, not YouTube.
Also, of course you can remove all the extra shit from the URL if you know how. That wisdom is lost on younger generations, but innate to older ones (who grew up around tech, like Millennials; or younger Gen X who adopted it at a young age — not like these iPad babies you have now).
I don’t see how it’s a generational thing. I remember when every link included the page type at the end, meaning there was nothing that could be truncated. If you don’t know what si stands for or don’t know that anything after a ? Is tracking bullshit, then you simply don’t know. It’s a “knowledgeable person” thing that can be learned at any time. I’ve pointed it out and many people I know still don’t care
As a web developer, everything after the ? is actually parameters for the request. Anything could be in there, even important stuff (though hopefully nothing identifying, since that is extremely unsecure). You will likely break functionality if you delete everything without knowing what it is.
if it’s obfuscated, then it’s assumed to be malicious
Usually parameters are easy to understand. Like the time parameter in yt URLs, which is t=180 (meaning 180 seconds from the beginning of the video). Usually, parameters that are a string of seemingly random letters are UIDs or tracking parameters. Whenever I see a URL with one or multiple of those, I start deleting them and seeing if the URL still works. In 90% of the cases, it still does. Amazon is one of the worst offenders, with usually 4 or 5 random looking parameters that can be deleted without affecting the functionality of the URL.
People can’t even unanimously agree on when each generation starts and ends (see terms like “zillenial” or “xillenial”) so I’d even go so far as to say it’s a completely redundant concept in the colloquial sense. Obviously most people care more about continuing to use the “kids these days” rhetoric so it hardly matters regardless, but it doesn’t make it any less ridiculous.
Blurry deliberations are typical. As time goes on, “millennial” will become more accurate as the differences between xennial and zillennial become smaller and smaller in comparison to differences between _ennial and alpha or beta or delta. I just take issue with acting like direct url interface was the experience of a generation, and not a short-lived blip for the gen pop that has already been forgotten, especially as full url purpose has shifted to something arguably evil.
Blurry deliberations are typical.
Yes, though my point that I wanted to add is that people seem to treat generational terms as if they’re a fact of reality instead of a very shaky conceptualization of cultural differences between birth groups that are already influenced by a lot more factors than just when people are born. It’s much more of a spectrum than a strict range of demographics inherent to humanity.
I don’t see how it’s a generational thing.
People who grew up when smartphones were already a thing might never have needed to learn how the Internet and URLs actually work. To a lot of everyday users nowadays, the Internet is just a series of smartphone or tablet apps you switch between. I used to think that the spread of the Internet into more segments of society would create a society of computer nerds, ha ha ha ha ha nope.
I use this on Android to sanitise links I sent out as well as clean incoming links before viewing them.
https://play.google.com/store/apps/details?id=com.svenjacobs.app.leon
Facebook and Instagram do the same btw. Just FYI.
It would be great if link cleaning and auto-mirroring was part of the lemmy UI itself.
I think that would probably be a client implemented feature, not a Lemmy one. I also don’t design social medias, so I don’t really know.
Yeah, would be best within particular client implementations. Not core Lemmy tho. Too many ways to do this and high maintenance.
The problem is that there is an almost infinite way to design these kinds of URLs, so maintaining a database of what should be stripped out isn’t trivial.
Done. Thank you.
Since 4 March 2026 I am seeing “is=” in some YouTube links instead of “si=”, also with the 16 character ID.
If it helps, for Androids share YT link to something like Untracker to remove unwanted nonsense from the url which you can then pass on safely (also works for things such as Amazon links).
For images, share to something such as Imagepipe first to remove location data. Other apps such as Aves Libre gallery or image Toolbox also strip this data but Imagepipe is simple - share image to it & it passes the image directly to your messaging app after stripping the data
Along similar lines be careful of the images you post if you location tag your photos. A lot of the larger websites will strip the location data by default but some do not. I’ve saved a handful of photos from reviews off the internet and now have people’s home addresses where the photo is of the product in their living room or whatever.
If you go to the ‘map’ section of your photos app it arranges them by location.
You can turn location tagging off globally when photos are taken or usually when you go to share a photo there is an option buried in a menu to strip location data(on mobile).
I have an iOS shortcut that remove exit meta data.
You can turn location tagging off globally
That’s one of the first things I did when configuring my kids phones.
The frequency with which I’ve seen the
siattribute included in youtube links has made me painfully aware of just how many people are not using the internet the same way I do; they’re experiencing the internet through a handful of mobile apps, not through a web browser on the desktop.This is why I use YouTube revanced. The features for it are great.
yup. I don’t use the google apps for ANYTHING. Even on my tab/phone, I use a browser (orion, with ublock origin installed) to watch youtube. It’s really annoying, but it’s better than using their spyware app.
even some IT pros are leaving it in, knowing well what it does. some people just couldn’t care less.
I’m not an IT pro but I am ashamed I didn’t know this. I’ve spent a lot of time cutting up youtube links for shiz.
Traffic is roughly 70-80% mobile on most websites I know.
Even then… what proportion of people do you think know the parts of a URL? Or know what a URL even is…
You may be in a bubble, friend
I know all this stuff and even I don’t look at the technical stuff in the URL. I just make sure it doesn’t have dQw4w9WgXcQ in there.
I refuse to search for that user, but dammit am I curious.
A problem I’ve had is people using those Google share links. I keep yelling them that I’m not clicking that link no matter how funny or interesting it may be.
Not sure if my anxiety is justified here, but I am not tech savvy whatsoever. And I worry about all the things I’m doing that’s probably completely giving myself away that I’m just unaware of. I didn’t know about this at all.
It is . But now you know . Don’t freak - and you might even learn how to install a privacy based browser, vpn, or operating system. Keep the tinfoil har dude and best of luck
pretty much everything that has a “share” button does this. it’s not to help you share the link more easily than copying from the address bar - it’s to harvest your data
Even voyager gives a link to vger.to when you hit share instead of a direct link to the thing you want to share. No idea what they are doing with it (other than trying to redirect it to the app). Maybe it’s set up to just use the localhost and that’s all it does, but I usually strip that part out because I have no idea either way.
vger.to solely exists so i can text dumb memes to my non tech inclined friends, and they open in voyager on their device instead of the web.
It’s a dumb service and has zero analytics other than cpu disk bandwidth use lol
Would you be able to add an
open in browserbutton, or a way to just copy the normal link as well? I can’t see any way to do it in voyager. It’s probably my only issue with it.Yeah, this is why that vger.to link is so annoying for me (other than triggering the reaction to the dark pattern, even if it isn’t exploiting it like what seems to be the industry standard these days), because most of the time when I use the share thing, I’m really just trying to get the url to open it in my browser, so that “open in voyager” link is the exact opposite of what I want, though I can see how it might be nice for actually sharing the link with others.
til people don’t reflexively strip out everything after the ? unless you know exactly what it’s doing
yup. all you need is the v=vkjlhaswlikuj3hg4 thing. that is the only thing you need, as it identifies the video. Strip everything else.
tbf, it’s intentionally designed to be malicious and deceiving
It can’t share my personal account if I’m never signed in.

















