Has this been normalised? Is this the new default?
Food for thought.
Has this been normalised? Is this the new default?
Food for thought.
If the privacy implications make us uncomfortable we might want to start not sharing this kind of information from browsers by default (this seems unlikely) or at least introducing some sort of browser-level controls. Unfortunately, this represents a lot of work and worries about breaking backwards compatibility contrasted with very little gain for browsers that don't pride themselves on being good for privacy(Chrome).
> In addition to being nonfree, many of these programs are malware because they snoop on the user. Even nastier, some sites use services which record all the user's actions while looking at the page.[1] The services supposedly “redact” the recordings to exclude some sensitive data that the web site shouldn't get. But even if that works reliably, the whole purpose of these services is to give the web site other personal data that it shouldn't get.
[0]: https://www.gnu.org/philosophy/javascript-trap.html
[1]: https://freedom-to-tinker.com/2017/11/15/no-boundaries-exfil...
Always using the most extreme terms just makes it easier to dismiss such views outright.
A friend of mine got a suspicious tax returns email that had a link to a form asking for credit card information. Being careful and responsible, my friend of course asked me if the site looked legit before actually pressing 'submit'.
Of course it was a scam site, and using session recording, they could very well have gotten my friend's credit card details without per pressing 'submit'.
I think it's always the context that decides whether something is malware. Is a program that erases everything on your disk malware? Perhaps, but if it's a disk formatting tool and you asked it to do so, then it's not.
FWIW you probably wouldn't need something as powerful or blunt as session recording to pull this off, though. You'd only need to listen for keystrokes on the relevant input (with document.addEventListener or similar), and send them to the server as they're typed. Same with partially-filled surveys. IIRC Facebook got in some heat a while ago for sending the partially-typed messages up to the server and to the other chat participant.
So another passion of rrweb is to teach people the 'power' of the modern browsers, and I also wish rrweb has a chance to improve the standard of web privacy.
https://a9t9.com/kantu/demo/runweb
Inside your local team you can of course share the recording simply as JSON files, via github and other services.
Another advantage of using browser extensions like kantu, selenium ide and imacros is that they are more powerful by design, but that is another topic.