Hundreds of web firms record 'every keystroke'
bbc.com
bbc.com
It's barely even about ads in the traditional sense anymore, it's about being able to read a fucking article without having half the internet downloaded in the background while every nano of my being available is processed and analysed by 30 different tracking companies simultaneously.
Can you be certain that this is true? Perhaps you didn't click through (I don't either), but what if your unconscious mind saw an ad that you did not register consciously.
The ad industry is just so damn broken that it's ripe for a huge disruption. The whole hypothesis of Google- that people will want to see ads centered on what they are searching for- seems to be erroneous. But it's been taken as gospel for what- a dozen years?- that everybody has piled on to the idea that we can know what people want to buy based on the type of information they seek. I think that except in explicit cases- searching for 'umbrellas that can withstand high winds' for instance- it's not true.
As I've said before here, when I'm ready to buy I'm searching Amazon, not Google.
It's probably more important than an antivirus for stopping malware.
Firefox + uBlock Origin is the right level of protection and you can get it on desktop and mobile (Android at least).
I've come across a few sites that were still using affiliate links and uO didn't block them. I'm not sure if uO has a policy of not blocking them but, to me, those are the only type of "acceptable ad" and CPU cycles shouldn't be wasted trying to detect and eliminate them.
Ad pushers have repeatedly shown that they cannot be trusted with our bandwidth and browser resources, they will always try to find the most insidious ways of inserting themselves into our lives, and try to track our every move, no matter how unwelcome they are.
Add to this the long history of malware using ad networks as an attack vector, and you have a very good case for simply blocking everything, in the name of privacy and security.
I hate ads, both for the above mentioned reasons, and because I find them extremely obnoxious (yes, even simple text ads), so I block everything with extreme prejudice. I am also on the "no mailed ads, ever" and the "you will be fined if you ever call this number with advertising" registries. My eyeballs, my attention, my PC, my OS, my browser, my home. Anything I don't trust and don't explicitly allow can just buzz off and leave me alone.
No, Firefox really does have tracking protection built-in:
https://blog.mozilla.org/blog/2017/11/20/firefox-private-bro...
I've alternated between Chromium and Firefox. Some sites seem to work better in one browser or the other.
I've re-read their whitepaper and while there is some data one may consider sensitive, it's not something like "user tracking and reporting" beyond the performance metrics and search suggestions (which all other major browsers do as well). There are optional features which may result in private data being sent to Google, e.g. keeping history with Google without local encryption - but you have to opt-in, which feels OK to me.
https://www.google.com/chrome/browser/privacy/whitepaper.htm...
While ad blockers do stop a lot of third party ads and iframes, and probably some tracking, I don't think that ad blockers are stopping most tracking by web sites. Not the kind this article is talking about, anyway. It's quite simple for sites to track user activity in ways that ad blockers can't easily stop. And I suspect it's becoming more likely quickly, purely on the anecdotal number of sites I visit that now detect ad blockers.
Some of this article seems like FUD though. It's pretty hard to think of what keystrokes you would type into a web site that you don't want to send the web site. The main thing they're getting by tracking keystrokes that they didn't get before is typos and form activity that you start and then decide to clear and bail out. I'd speculate that this is being used and is most important for sales conversion pages, where they monitor your activity to try to figure out if you started out interested in buying something but then decided not to buy.
Web sites cannot track your keystrokes when you're using a different site / tab in your browser, they can't track keystrokes when you use another program besides the browser, they can only track when you're interacting with the site. So what sensitive data can they get that you weren't already giving them?
Adblock lists are community maintained, so whether this stuff is blocked depends a lot on people who actually enjoy having their network debug panel open.
Facebook's tracking pixel their e-commerce affiliates use is insane. It sends most mouse movements and they use it to determine what words users hover their mouse over! Their AI/marketing engine is pretty advanced, to the point where their predictive analysis is accurate enough people swear Facebook/Instragram are sending microphone data.
Sure they cannot track you across tabs and browsers ... directly. But they do. If 30% of the pages you visit have some kind of Adobe Omniture or Facebook pixel, they do in fact gleam a ton of data about you. This AI is so powerful it can predict products you want, potentially before you even verbally announce them. That's incredibly powerful predictive analysis ... used to cure cance---oh no wait. It's not. It's just used to sell you shit. What a waste of tech honestly.
I know a lot of people here use uBlock Origin since there are concerns with Ghostery/AdBlock/etc either allowing in certain ads for a price or selling some of your data to be viable. The only real solution for tech people is to run a Javascript blocker like NoScript, and explicitly white listing what you want to run .. which is honestly a ton-o-work.
Yep, heat maps for mouse movements are a very common technique. You get click location data out of Google Analytics and everyone uses Google Analytics.
But we should be clear and careful -- since I'm using the web site, my click data is not something I can ever keep private from the web site. We can (and probably should) keep it from third parties, but first party mouse and keyboard data isn't a privacy concern.
Good point about cross-tab tracking, this is fairly common too, and an ad blocker does usually block this. But, the article was primarily about key logging, and the iframed ads can't do any key logging.
Don't get me wrong; I use an ad blocker myself, and I think it's a good idea. I just wanted to make the point that blocking only 3rd party content does not solve the problem this article pointed at, and it especially doesn't solve direct key logging or mouse tracking by the website you're using.
If that data can be used to infer anything about me, it certainly is a privacy concern for me.
I think of it like going to a library and instead of freely browsing through the books without being watched, instead being spied on and every book I look at and even where my gaze travels through each book's pages being monitored.
This is a paranoid's nightmare level of surveillance, and that's what we're gradually being weaned in to accepting. It certainly is a major privacy concern for me.
Ideally, the internet would have been built in such a way as to allow fully private and anonymous use, as it's really nobody's business but your own what you look at, what you're interested in, or what you read.
We've helped build the internet in to a spy's paradise, and it's really sad.
I totally agree and empathize with the increasingly privacy hostile place the internet is. But, that analogy seems a little hyperbolic to me. The library currently does track which books you check out, and maybe fine you when you’re late to return them. They do track which books are popular, in order to figure out what to stock. Some libraries track how their building is being used, and my local library does have cameras. These are all the same kinds of things web sites are doing. It may be more aggressive on a site, and more focused on selling you something, but it’s not fundamentally different. First party sites (not ads) aren’t tracking your gaze or invading your privacy, they’re responding to what you ask for, and using some of the breadcrumbs you leave to improve conversions if they can.
Talking to a person face to face has exactly the same issues. If I buy a car, for example, the sales guy will definitely watch my gaze and listen to what I say with an ear toward exploiting anything I share with him to increase his odds of selling me a car. We wouldn’t call what the sales guy does a privacy issue, and what “first party” web site tracking directly (without third party services) is doing is no more creepy and no less private than what car sales guys do.
If the direct tracking is sold or shared or handled by a third party, then absolutely, huge privacy concerns. But for the direct communication, if you don’t want someone to infer anything about you at all, your only choice is and always has been to not use the service.
This is why I explicitly talked about browsing of books at the library, not checking them out.
But now that you mention it, tracking who checks out which books also has disturbing privacy implications, and I am against that. There's nothing stopping an anonymous library checkout system from being designed and implemented, if we only had the will.
Camera use in libraries is a relatively new phenomenon, and I'd have similar privacy concerns about it if, like website tracking, its explicit aim was to track who was looking at which books, but as far as I know it's not being used for that purpose. But it's not very far from being capable of doing that, especially with high resolution cameras and facial recognition systems. So that's definitely something to keep an eye on.
"Talking to a person face to face has exactly the same issues. If I buy a car, for example, the sales guy will definitely watch my gaze and listen to what I say with an ear toward exploiting anything I share with him to increase his odds of selling me a car. We wouldn’t call what the sales guy does a privacy issue"
I would in fact call that a privacy issue. We're just so used to it we don't normally notice it. There's also an enormous difference between one person noticing your interest in one thing and the systemic, omnipresent surveillance apparatus we've made the internet in to, which is tracking all your interests, and voiced opinions and ideas.
Look at the repression, imprisonment, murder of political or ideological opponents throughout history, and you'll see their surveillance, tallying, and location has always been a part of that. Today's surveillance apparatus is thousands or millions of times more effective than it's ever been in the past, and every bit of data collected about you feeds in to those profiles which could be used against you. We should oppose it, instead of meekly submitting to it, much less enabling it.
You're right that there is a difference between face to face conversations and digital tracking. That's why I'm weaseling out with my "first party" qualifications. As long as the tracking is between you and the site you're on, it's sort-of similar to personal conversations. Not the same, but not super different. As soon as third parties and groups of people and governments are involved, it's wildly different.
The camera issue is interesting. This will be a growing concern from now on. According to US law, there is no expectation of privacy from being photographed while you're in a public place. You are not currently entitled to privacy in a library, or while walking downtown, or while driving in a car on public roads. But that law wasn't drafted with the idea of digital mass surveillance in mind, nobody had the capability to capture and correlate all your movement when it was written.
Also, I've always wondered what the use is of tracking which words the mouse is hovering over. I mean who does that: hovering the mouse over words?
Lots of people, you’d be surprised. ;) Sometimes I catch myself unconsciously highlighting what I’m reading.
But the mouse tracking is for detecting waffling potential button clicks and form fills too.
It’s a bad proxy for attention, but it is a proxy that kinda works.
Lots of people will cut and paste passwords and sensitive information while working and swapping back and forth between applications. That would include every sort of personal information possible that can be put into a clipboard.
Having 3rd party tracking services is a bit of a problem with some complex issues, but it's very common. Ad blockers can help, but I suspect the ability for ad blockers to increase privacy is going down. It's easy for sites to configure third party services as though they belong to the site's domain, and all ad blocking goes out the window. This is an arms race that will not end by blocking third party requests.
For first party tracking though, direct tracking by the web site, there is no hard line for what input tracking even means, using the web site at all is a form of input tracking. Logging of inputs to a site by the site should be and always has been expected. Accidentally sending sensitive data directly to a site has always been a problem, and ad blockers don't solve that problem at all.
The problem is that most of us are reading what should be static content which is instead a dynamic program written in a general-purpose language.
Personally, I do not understand why this has become acceptable, if all I am doing is viewing text and static images.
Ideally, I would like it so that the browser suspends everything if a tab is not visible in the foreground, unless I pin it.
Dynamic mode is the somewhat hidden feature that makes uBlock Origin as powerful as NoScript, and more flexible when it comes to differentiating between whether to allow content from a domain globally, or only on specific sites.
https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-qu...
Highly recommended.
I would like to combine uBlock and uMatrix, but I'm not sure I can replicate the functionality I want. Your mention of dynamic filtering is interesting and I wonder if others are using it and can make a recommendation?
I need all JavaScript off by default (including first-party) and the ability to block both ad-serving domains and filters such as /ads/ that work across all domains. Is this possible to do entirely within uBlock Origin?
However, if you're using chrome, you should have the ability to disable it from the browser altogether.
Read more about it here: https://github.com/gorhill/uBlock/wiki/Dynamic-filtering:-qu...
and yes you can disable ALL javascript with uBlock :)
It is getting back to usable but it still lacks ABE and some other tools.
See https://www.reddit.com/r/firefox/comments/706xrr/umatrix_vs_...
This will block all externally loaded fonts, only system fonts will be used.
If you're on Chrome, don't forget to also install uBO-Extra[2] along with uBlock Origin[2], otherwise you don't get WebSocket coverage.
[1] https://github.com/gorhill/uMatrix [2] https://github.com/gorhill/uBO-Extra
[1] https://chromium.googlesource.com/chromium/src/+/0f198df6bc8... [2] https://bugs.chromium.org/p/chromium/issues/detail?id=129353...
Not to bash the BBC – all web publishers are using this stuff and loads more. The BBC are unusually good actually, as their sites don't run adverts and all the adtech crap that comes with them.
As someone who designs and builds websites, the data provided by platforms like Hotjar etc. are very useful. And the advertising stuff is required if you want to keep the lights on (unless you have another source of funding like the BBC).
As a user I block it all with extreme prejudice.
Recently I was surprised to discover that the Australian equivalent that also has no advertising has half a dozen trackers on there main page. Plus twitter integration and CDN material.
- Heatmap views of where people hover and start to type
- capture of individual sessions to research support cases
- Better understanding of user flows through a site or web app
And all of these tools, at least the reputable ones cited in the article, allow you to mask fields or parts of the screens so that PII isn't captured, and reputable companies do that.
The other part of this is that I don't think the article captures well is that these tools aren't used for targeting of ads or personalization or "spying" in the sense of malice, but to try to better understand users, what they're trying to find on a site, and clarify pain when using applications. I also think the people that use these tools, generally speaking, are perfectly fine with blocking them, since it's meant as a diagnostic and analytic tool.
- websites implementing these tools need to specifically opt-in text fields they want to capture the inputs for
- for HTML-side capture, the javascript will obfuscate PII before sending it to the servers
- some of these tools will not capture password fields under any circumstances
Does that address some of your concerns?
It's capturing the things you are typing into the website's input boxes!
Sorry, call me paranoiac, but i will never trust the javascript of a website. With no webdev experience, i was able to inject js (almost by mistake) three years ago. Moreover, is the js communicating with the backend using https too? How can i check that? Are those js library on the website server, or are they hosted by a third party? I can trust them, but how do i know that no attacker was able to modify those scripts? Yes, those risks are small, but i'd rather have ublock making those risks closer tho 0 than not, am i wrong?
I'm genuinely curious what steps are executed once this data is collected.
Also, in theory, you only need to do this after design/layout changes and only for a while, so what justifies collecting it all the time? I might be wrong though.
Google does this on all of their products. And people that have left Google have made their own versions of this software for others to use. For example: https://www.fullstory.com/
- I'm going to capture 5% of users sessions as they progress through a purchase funnel
- I capture data for a few days after a design change, and look at behavioral changes, such as spending more time in a particular step of the funnel
- Where there's something weird going on, I'll watch an aggregate view of people's mouse behaviors - I can then see that a lot of people are hovering between two different buttons, or highlighting a particular sentence
- Based on that feedback, I'll do an A/B test of changing the button textx or the dialogue message
- Capture more data, did that change?
It's not "Let's go look at john smith's website behavior" except in the support example, where you get a user's consent to do that, and you usually only do it for internal corporate applications where there's a dedicated helpdesk.
Edit: It also needs to be stored anonymously, though even people I know who build wifi/bluetooth tracking software&hardware say that is almost impossible.
But, I thought it wasn't coming in to force until next May.
They're very useful for testing. I don't think there's any debate about that. The issue is with using them in production capturing everyone's data with no regard for a user's privacy.
The result of these tools is a far better user experience on our site and many other sites.
"recording every keystroke" makes it sound like there's malicious intent, but it's misleading. It should be added that all these tools have a lot of options to avoid tracking sensitive data (like password fields) and we always rely on that (in fact anything else would be a compliance violation for us).
Thinking from a security perspective, I'm not sure "intent" is an important consideration. The question is: should third parties have the technical capability to do this?
IMO there are enough bad actors out there to answer this with a resounding _no_, at least by default.
If you want to record user browsing sessions, you should ask permission.
The third party follows users over all the websites they're deployed on. Best example is google analytics and all beacons scripts (G+, FB like, share on twitter etc.) which track you almost everywhere.
... so it is deceptive to watch them.
Not quite the same thing.
Hmmm... nice pitch. Has your series A filled up yet?
/hehehe like I have money :)
https://www.washingtonpost.com/news/the-switch/wp/2013/10/19...
No. We are doing analytics for the sole purpose of selling our products and services better. Let's not kid ourselves into thinking we are spying on our users for the greater good. Nobody implements user tracking simply to make their user's lives better. If it does happens, it's merely a side effect of our sales strategies.
I look at a lot of companies professionally and the range goes from: "GDPR? What is that?" to "Sure, we're ready, here is what we did and we are already compliant.".
Most companies are somewhere in the middle between those two, they are aware that something is changing but they are still trying to figure out the impact on their business. Lawyers are - unless their specialty is privacy law and they have boned up on this - pretty useless and generally tend to know even less.
I mean why do advertisers think its impressive to do this? I swear they increase their intrusion and in return more and more people tune into ad blocking. And don't even ask what I do about sites that insist I turn it off -- I blacklist them.
However, any React developer worth their salt (probably still a minority, as mentioned above) should be using ReactDOMServer which will render the page fine without browser JS being enabled.
In most cases though, you should be able to present a pretty useful static page by default without too much effort.
(Of course, as a Web user I consider both JS-only pages and SEO to be awful somewhat-parasitic practices, but that doesn't unfortunately doesn't factor into many business decisions :( )
Sometimes we see examples here on HN of blogs, that are mostly text content and pictures, built on a client side JS framework like React, but that's the exception.
- Late 1990's: static html documents + forms - early 2000's: shitty DHTML scripts that added nothing - early 2010's: javascript + gracefully downgrading sites - 2015/16: required useful javascript everywhere - early 2017: trackers everywhere, html5 popups, trackers, spywhere, trackers, bitcoin miners, trackers, etc, etc.
2017 is the year where you NEED a javascript blocker. What's the use of having any security at all if you're going to leave the biggest attack vector in modern times completely unprotected?
Plus, the web has become completely unusable without a script blocker.
Nowadays I always push for HTML5/CSS3 with minimal JavaScript, preferably with server side rendering.
For anything really complex I usually try to see if it can be done as native app instead.
When you exaggerate like that, it diminishes your point. I use the web all day, every day and I have never installed a script blocker.
Not to mention hazardous.
The extensions just make it easier to allow whitelisting sites that you trust and that require javascript, or toggling for the current site.
This article is a little clickbaity- it implies your passwords and other private info are being stolen, instead of just webpage clicks.
Maybe people can hack those tools for ill but that's true of almost any web software platform.
After a set of test data refresh, we lost some of the new test passwords associated with some of the new data. Then it clicked: Dynatrace has keylogging. I searched for login events of those users, and sure enough, there were the keystrokes for the passwords of each of those users.
Yes, this kind of software is a godsend for debugging, but improper usage, storage or transmission of data is a real concern.
PDFs execute code, DOC(X)s execute code.
Users want features: interactivity, automation of various bits, etc. Features = users = money. Money > anything (security, privacy, etc.).
Code execution by default in HTML documents is unusual.
That wouldn't give you Google maps, docs or gmail, but the vast majorit of SAAS products could have probably been created in one way or another with the restriction that no code could execute client side.
More and more pages that could have worked just fine now render as totally blank because client side frameworks are now being pushed from every angle. As an end user there is no clear advantage to this.
So, it wouldn't have given you three of the most important and useful applications in the modern world, used every day by millions of people.
Gmail could have been made to work (on the web) by the way, just not with such a spiffy interface, and maps probably as well.
What makes you think that's not the main selling point of those applications? "Except for that one thing that normal people care about, my sticks-and-stones are just as good!" :)
Software was plenty usable before we had the CPU power to burn on 'pretty'. In fact, in many ways it was more usable.
To some extent hardware has outpaced our ability to do useful things with the cycles and transistor budgets available. So we've become super wasteful and our software is now mostly immature. If instead clock cycles had doubled every decade or two and ditto with the transistor count we probably would have had a much more mature software eco system as a result, rather than a bunch of pretty junk with plenty of that pretty junk as a service rather than as an application that you control and all the security headaches that come with that.
I've got a 5 year old 'TomTom', a simple and dedicated navigation device. It beats the pants of all the connected versions out there because it simply always works. I didn't download anything for it, you just switch it on, it takes about 30 seconds to find its bearings (longer in urban canyons) and then you tell it where to go, with pretty much all of Europe covered. User interface is a dream compared to mobile phones and most other in-car navigation systems.
Turn-by-turn voice navigation works and works well. No online service even comes close for that application.
So, whatever the web has shown is that people don't want, at least speaking for myself you can keep your services and give me that download.
And guess what, nothing beats the convenience of the web's 0-install in those cases.
The HTML <form> is all that is needed to conduct business. The web was created as documents+forms in the IBM 3270 model, which businesses and other other organizations were using since the 1970s.
Edit: TO anyone else wondering the same thing, the answer is no. However, Ghostery does block it. I didn't like ghostery before because it broke all kinds of sites, so this time around I re-added it except I ONLY selected the "Site Analytics" category and left all the others blank (which can be handled by uBlock origin)
Do you have a source for them selling data?
In all fairness to Ghostery, it seems they've cleaned up their act after being bought out by Cliqz: https://adexchanger.com/data-exchanges/ghostery-sheds-ad-tra...
Specifically, it was the Ghostrank feature that was troublesome: https://en.wikipedia.org/wiki/Ghostery#Criticism
I don't know how the current version of Ghostery behaves.
But it's not 'every keystroke', but keystrokes you make whilst interacting with a page on that particular site.
If it's b or c, I have a MAJOR problem with this.
Could a website that has a keylogger in it potentially pick up these keystrokes when I put my password into an extension?
I think this article is a bit sensationalist. These sites already have access to all of your data (stored in their databases!). There's nothing additional they are gaining from this aside from how you input that data. That is much less sensitive information and I can't think of another usage aside from improving their site's UX.
The assumption for most people is going to be that they have the data that you explicitly sent them. Implicitly gathering and sending data is equivalent to snooping on people without consent. It's all about expectations.
Say for example a website asks me for something (e.g. an address, phone number, bank account number), I type it in (thus registering my keystroke presses to the keylogger) and then realise oops I didn't mean to type that, I meant to type something else
Does the website then submit the logged keystrokes for offline analysis?
All responsible implementations of this won't actually log PII. It's pretty trivial to withhold certain inputs. All of the services mentioned in the article have easy ways to flag an input field as private / do not log. I'd wager a lot of money that these sites are interested in gathering UX data and not scraping for accidental form input.
I suppose there's a certain level of trust involved, but I don't think that's any different than when you make an online purchase. /shrug
Yes of course. All it takes is misclicking and having the focus on a wrong window, and you're toast.
Hacking a popular extension is one of the easiest routes to fully compromising millions of users (and every account they own). People are generally unaware of this danger, but it's much worse than ads or tracking.
>They found that 482 of the world's top 50,000 sites used scripts provided by one of these firms.
Less than 1% of the sites did this.
God I'm tired of this kind of "journalism".