User tracking inspection result for about.gitlab.com
themarkup.org
themarkup.org
If you're going to claim Gitlab, as in the tool, has that, then link to an actual example repository for proper comparison.
Not trying to defend Gitlab here, but this headline makes it sound like you have an agenda.
(The page linked compares about.gitlab.com, which is a wildly different site than the rest of Gitlab)
Like i said, I'm not defending Gitlab. But there's a difference in impact between "theres 15 trackers in the tool i use" and "there's 15 trackers in the marketing page i never visit".
Don't make it sound like you don't understand that difference.
Two wrong make no rights.
In Gitlab's case, it seems to be their search function. It provides search results without needing to press Enter or clicking a button. From a technical POV, this is the exact same kind of keylogging as the above, it's only the intent that makes this okay and the above not so.
Is this is the case, then the latter is not keylogging.
The former is some sort of logging, but I wouldn't call it keylogging; after all, you are still entering data to the particular filed intended for entering credentials, to be sent to the remote server for verification. If the purpose of the remote server is something more nefarious, then it is keylogging.
The feature would even make sense if the server would let you in without pressing enter; but for understandable reasons this is not really a thing..
No, I would not. Keylogger, I would say, is what the name implies: is a term for software that records keystrokes. In order for the term to be useful we have to limit it to such software where the recording is not obvious to the user, as otherwise even Notepad would count, but we do not have to limit it to malicious software.
Would that go along with the common consensus, or perhaps water down the term to near meaningless? Maybe Firefox is keylogging my input as well; and in fact, so is Linux. Keyboard itself, definitely.
Once I had X11 enter old keystrokes (so it had missed the read position in the input ring buffer and every stroke entered a key from the past); keyloggers all around.
Kidding aside, I believe it is important to use terminology all parties agree on; after all, words are a tool for communicating. Even if an individual finds a deeper or "fundamental" meaning in a word outside the typical use of a word, attempting to use and understand it in such a way hinders communication.
Over 99% of the hits on a google search use keylogger restricted to malicious software (sampled the first dozen or so pages). The first sentence in Wikipedia is "Keystroke logging, often referred to as keylogging or keyboard capturing, is the action of recording (logging) the keys struck on a keyboard, typically covertly, so that a person using the keyboard is unaware that their actions are being monitored". The top definition googling a definition is "a computer program that records every keystroke made by a computer user, especially in order to gain fraudulent access to passwords and other confidential information."
What metric did you use to conclude that the "common meaning" is not this common meaning? Not a single place I have found claims the common meaning is anything other than surreptitiously recording user keystrokes for nefarious purposes. Do you have even one such link?
https://www.csoonline.com/article/3326304/what-is-a-keylogge...:
> Keyloggers are a type of monitoring software designed to record keystrokes made by a user.
https://securelist.com/keyloggers-how-they-work-and-how-to-d...:
> The term ‘keylogger’ itself is neutral, and the word describes the program’s function.
https://en.wikipedia.org/wiki/Keystroke_logging:
> Keystroke logging, often referred to as keylogging or keyboard capturing, is the action of recording (logging) the keys struck on a keyboard, typically covertly, so that a person using the keyboard is unaware that their actions are being monitored.
https://home.sophos.com/en-us/security-news/2019/what-is-a-k...:
> A keylogger is an insidious form of spyware.
https://www.kaspersky.co.uk/resource-center/definitions/keyl...:
> Keyloggers are used for legitimate purposes like feedback for software development but can be misused by criminals to steal your data.
https://www.mcafee.com/blogs/consumer/family-safety/what-is-...:
> A keylogger (short for keystroke logger) is software that tracks or logs the keys struck on your keyboard, typically in a covert manner so that you don’t know that your actions are being monitored. This is usually done with malicious intent to collect your account information, credit card numbers, user names, passwords, and other private data.
https://searchsecurity.techtarget.com/definition/keylogger:
> Keyloggers are often used as a spyware tool by cybercriminals [...]. Keylogger recorders may also be used by: [...] These uses could be considered ethical or appropriate in varying degrees.
https://www.malwarebytes.com/keylogger/:
> Keyloggers are a common tool for corporations, which information technology departments use to troubleshoot technical problems on their systems and networks—or to keep an eye on employees surreptitiously. The same goes for, say, parents, who want to monitor their children’s activities.
https://enterprise.comodo.com/what-is-a-keylogger.php:
> At its most basic definition, a keylogger is a function which records or keystrokes on a computer. Taken at this basic level, a keylogger looks absolutely harmless. In the hands of a hacker or a cybercriminal, a keylogger is a potent tool to steal away your information.
https://us.norton.com/internetsecurity-malware-what-is-a-key...:
> A keylogger is a type of spyware that can be used to track and log the keys you strike on your keyboard, capturing any information typed. Keyloggers are insidious because you don’t know they’re there, watching and recording everything you type.
1st: title mentions they're used by attackers. First sentence: "Keystroke logging software is one of the oldest forms of malware. Under "definition" they state "One of the oldest forms of cyber threat, these keystroke loggers record the information you type into a website or application and send to back to a third party"
Why did you take your sentence out of context? Those above and below state keyloggers are used for criminal activity. The article is about keyloggers being malicious.
Second link: "Today, keyloggers are mainly used to steal user data relating to various online payment systems, and virus writers are constantly writing new keylogger Trojans for this very purpose."
Well, I guess that defines the common usage, hence the word "most". The article also states that "keyloggers have pushed phishing out of first place as the most-used method in the theft of confidential information". So not only are they mostly used for crime, they are the number one method for stealing confidential information.
And most every other link you posted also either defines them as malicious or points out that most uses are malicious.
So, by what metric you claim ". Yes, a keylogger need not be malicious. But so far you competently have made the case that the common meaning is most certainly malicious, and it's not even a close assessment.
So - what was your metric to claim "the common meaning of keylogger is not restricted to malicious software"? This list clearly supports that malicious use is by far the common meaning.
Please state your metric for "common meaning" then we'll test it. If you have no metric, we're done, since so far all the data points to your claim being false.
For the rest, nobody, not myself, nor anyone else here, has suggested that keyloggers are not primarily used maliciously. Of course they are, we all know that. The whole question is whether it's possible for non-malicious keyloggers to also exist, or rephrased, whether the definition of keylogger inherently excludes anything non-malicious. You're only looking at what they refer to using that term, which will be almost exclusively malware, but that's not the point, you're not looking at how they're defining the term.
Here is your quote written to represent the link: "Keyloggers are a type of monitoring software designed to record keystrokes made by a user."
Here is that quote with the surrounding sentences:
"Keystroke logging software is one of the oldest forms of malware, dating back to typewriters. It's still popular and often used as part of larger cyber attacks. Keyloggers are a type of monitoring software designed to record keystrokes made by a user. One of the oldest forms of cyber threat, these keystroke loggers record the information you type into a website or application and send to back to a third party."
Now again tell me who is dishonest?
> they also have legitimate uses
No one disputed that. Your claim is the most common use of the term is not related to malware. Focus on the "most common" phrase you claimed - not the exceptional cases you're obsessing over.
Seems pretty clear the common usage is for malware, from this link, to web samples, to wiki and oxford definitions, to nearly every one of your links.
>nobody, not myself, nor anyone else here, has suggested that keyloggers are not primarily used maliciously
Also you
> "the common meaning of keylogger is not restricted to malicious software"
?
The argument is not whether a program called a keylogger has other uses than malware. The argument is your claim that the most common usage of the term is not the criminal one.
And since you don't have a metric to base your claim "the common meaning of keylogger is not restricted to malicious software" on, you're right. We're done - your claim is nonsense and you cannot provide how you arrived (incorrectly) at what the common meaning is.
The common meaning of keylogger is restricted to stealthily recording an unsuspecting users keyboard input.
Malicious or not depends on the user who uses it and what they use it for and possibly also is in they eye of the beholder, but Google Docs or a an auto complete search field is not a keylogger by any definition I've seen used.
But what do I know, I've only been interested in this since the nineties.
I think most people think of a keylogger as a malicious program that secretly records your keyboard activity when you don't know about it. If they think about it at all, they think of autosuggest as analogous to a form submission.
but from my POV i would also say that 95% of the time i've ever bumped into the term, it was always used in a cyber attack context. the other 5% was from corporate overlords wanting to spy on your actions.
wow...
"Type to search" is OK, as the key events processed are restricted to the ones typed into the search field. A key logger would attach an event listener to capture key presses in any field, or even if no field is selected.
It is the same technical difference between a UI which has an explicit "paste" button, which reads from the clipboard only when that button is pressed, vs a web app which reads from the clipboard indiscriminately, in the off-chance that there's something interesting (a password for a different website?) stored in the clipboard.
Reasonable people wouldn't call it a keylogger because they assume that a form input will actually receive what you input.
Fair point, though that's more of a corner case.
> Reasonable people wouldn't call it a keylogger
Not a fair point. If your starting assumption is that everyone who disagrees with you is unreasonable, please take a moment to reflect.
And I stand by my position that considering an autocomplete to be a keylogger is unreasonable because the obvious purpose of the input is to accept you what you type. Automatically submitting may be a slight surprise but doesn't change the intent as you wouldn't type in the box if you were never going to submit it anyway.
Yes, actually, it is. Besides, the tracker explicitly points this out as a possibility.
The tool doesn't handle the direct link, it just gives information for about.gitlab.com again.
And this mostly makes sense. It means they can cache results more easily, there is no way the tool could return so quickly unless it was cached.
(I helped work on Blacklight)
We did make the collection software available on Github if people want to check out arbitrary pages on their own: https://github.com/the-markup/blacklight-collector/
Except there's 32 third-party cookies on my repo versus 22 on the marketing landing page (about.gitlab.com)
So I'd classify it as worse than the marketing landing page. Doesn't see that wildly different.
When I go to one of my repositories, ublock origin shows exactly one third party domain, assets.gitlab-static.net.
Regardless, I have seen other sites that have a vast amount of trackers so I'm gonna ask my question anyway. Anyone know what the point is of having this many trackers? I totally understand that a company wants to figure out how a user interacts with their app, but what is the point of tracking using different trackers where there is a lot of functionality overlap. I doubt Microsoft, Google, Twitter, Facebook and whoever else collect vastly different data where this becomes useful. Maybe one or two different companies e.g. for redundancy but why do their need more than that?
If I load about.gitlab.com without ublock origin enabled the FB network requests show up in in the network console.
All of that could be done server side, but people don't want to build their own version of analytics, run it internally, and keep it up to date with all their data sources.
Our product does not include the tracking that is used on the marketing site.
https://docs.gitlab.com/ee/user/shortcuts.html#repository-gr...
I have different feelings about trackers on the marketing portion of a site vs. the product portion of the site.
What purpose does it even serve? Why does Facebook even care or why does it have to be informed about my visit?
This ad business is crazy stuff. Lucky for me I have some blockers for things like this.
Most noble thing to do would be using server-side tracking/analytics but because of additional coding and losing access to Facebook analytics, most web sites usually don’t bother.
However, this would require a cost, in terms of refusing to do business with untrustworthy websites. Rather than accepting that as a fact of the business, websites/advertisers instead push the cost off to users as an externality. This cost is paid by the user in time/bandwidth (larger page load times) and privacy (ad trackers), even though they were by no means the source of the problem.
Change your password asap.
For better protection you can use totp codes or some type of security token which makes password leaks useless.
I think it’s a clickbait title, for that reason.
That doesn’t sound like “autocomplete purposes” to me.
whereas www.reddit.com doesn't [1]
slashdot seems to have all the trackers [2]
[0] https://themarkup.org/blacklight?url=old.reddit.com
https://about.gitlab.com/press/releases/2019-01-22-gitlab-an...
Background on In-Q-Tel https://en.m.wikipedia.org/wiki/In-Q-Tel