Many popular websites see what you type before you hit submit
wired.com
wired.com
Shit sites becoming responsible for all the data they soak up couldn't have happened soon enough.
When I was younger, I didn't use to have one and tried to cheapen out by reading contracts carefully without checking with a lawyer. One of those contracts was a rev share in exchange for free work I did (plus some work I paid other contractors to do), I didn't notice that there was an easy way to get out of the contract by the company. Once the company was successful thanks to the work I initially did, they used that to cut me out. If I had used a lawyer back then, I'd still be earning 150k a year from that contract...
So, yeah having a relationship with a lawyer in the same way you have a favorite dentist is worth it. Having the reflex of using a lawyer when possible potentially can save a lot of money down the road. And using a lawyer at first for less impactful work is sometimes a good way to find out if the lawyer is any good.
I'd actually suggest any consultant/contractor to have a lawyer, work with him to review every contract and budget a small percentage of your income on this every year.
> costs me 375 usd an hour
> budget a small percentage of your income on this every year
What you are saying is that for those with enough disposable income to throw 375 per hour at minor annoyances, going straight to that nuclear option is often preferable to settling for a cheaper secondary or backup option. This is the "simply buy Twitter if the way it's run annoys you so much" of legal advice.
This doesn't apply to 99.999% of people on this planet. It is "worth it" in the sense that $800 / oz gold plated caviar is better food than McDonalds. If the median American decided to "find out if [your] lawyer is any good" by hiring them for a 1 hour task, they have already spent more than 1% of their yearly income. In a single hour.
On the other hand, I guess we'd all probably be better off if we'd have a lawyer look over things like our employment contracts, renting contracts, etc (I just sign the dang things though).
For other needs, people who can't afford lawyers and need help use family, acquaintances, church members, etc. who are lawyers, either free or at a sliding scale. They also sometimes subscribe to prepaid legal plans which do add up to a few hundred dollars, but over the course of a year.
Big cases (like the sudden need for a defense attorney) are funded by passing the hat (or GoFundMe et al, these days.) There are also public defenders.
The truly destitute don't even have that, of course, but other needs are pressing. Aid and social safety net programs do offer charity legal services where they can, but reach and benefit is limited.
Unless you have never spent $300 on something, i'm absolutely sure you've spent $300 on something that median family would call a waste too.
But I can't figure out what your point is. Its a waste to call out these sites? Lawyers are too expensive? The lower classes don't make enough? Don't give advice if it doesn't apply to %100 of people?
The advice I wrote applies in the context of consultants/contractors on HN which I'm pretty sure tends to earn quite a bit more than the median income.
That said, at a big firm, lawyers often don't have that flexibility.
Something like this you can easily do yourself and imo wouldn't be worth the money, however getting a law firm involved in small tasks is a good way to test them with something simple to see if they're any good, and build up a working relationship with one incase you need them for something more serious or time sensitive later on. It's generally a good life skill to get comfortable working with lawyers because at some point all of us will end up in a situation where we need one, and that's really not the point at which you want to deal with that learning curve.
Now whether or not the example at hand counts as run-of-the-mill, I don't really know.
"Obviously we don't mean having a lawyer on retainer. That'd be unreasonable. We're talking about the lawyer with whom you maintain a working relationship should you need one. You know, kind of like your accountant!"
Either have the courage to directly reply to the people you are talking about or keep it to yourself.
to make you an example I am in the netherlands, few weeks ago I went out with some friends, a dutch guy was complaining about an issue and about having to pay a lawyer, and a polish immigrant here had to tell him that he could give a go to https://www.juridischloket.nl/contact/ , like some people live and grow up in a system and they don't even know what they're surrounded by
IANAL, but it appears that the type of case I'd have to bring against a company that was inappropriately handling my personal information would require over $400 just to file the papers for the lawsuit. And the fact that I can't easily determine if that's the type of legal action I'd need to bring demonstrates the opacity if the legal system that further prevents access by an individual without spending even more money on a lawyer for the help needed to make that determination.
There are ways I could get inexpensive legal advice, but that's where disposable time comes in. I have too much income to get free legal aid for the lawsuit itself, and honestly there are people with much more serious legal problems that need those limited resources. Unless you can catch the attention of a class action lawyer that sees potential for massive $$ damages it is very difficult for the average person to take advantage of the legal system to protect their rights.
Same is true for most others. Things in life really rarely go to court or rarely is there any bespoke contracts.
"My dentist" also isn't my personal pet, but it's the dentist I go to. Neither am I my dentist's pet for being "their customer". I'm sure you also know some professionals that you trust and have some sort of relationship with.
>Are you suggesting that you should hire a law firm at $1000/hour to mildly annoy some website..?
Not really. But there's usually people who do it for the good cause and later take it to court, often backed by nonprofits. Also that cost is insane, it should absolutely top out at 300 euro/hour. Some specialized lawyers charge a flat amount to send such standard requests.
So, none. I've never even met one I think. And I don't think that's quite rare?
Would it be less confusing to say "talk to _a_ lawyer"? This just seems like a bunch of people arguing for the sake of arguing. It has nothing to do with the original point.
No, because in my culture it happens to be rather common for people to have one fixed dentist. Moreover, tranlated we also effectively it 'your dentist'.
Would it be less confusing to say "talk to _a_ lawyer"?
For me personally yes, because it does not have the same connotation i.e. doesn't imply something common. Which leads me to think this might be a combination of cultural/language thing. As in: when I read 'your lawyer' I translate this mentally then think about occurrences where I heard that phrase in my language. Doesn't ring a bell, so I start thinking about what I did hear or think I would hear another person say when talking about something like this. And 'a lawyer' would be that.
This just seems like a bunch of people arguing for the sake of arguing.
It's not, at least not from my part. See previous paragraph: this is HN, I come here because stuff like that gets discussed here freely and going off-topic is also not exactly a problem.
I think those groups just happen to be massively over-represented on HN.
Nowadays only the very rich can claim to have a "family lawyer".
If we were very wealthy, perhaps we'd have a legal matter for him every month instead of every year or two, but that's plenty of time to build up a relationship. Similar to having a family doctor.
Let me explain: they don't walk around with a personal lawyer. Just as if I buy a chocolate bar it doesn't mean I walk around with a personal sweet shop. You've just radically misunderstood how everything in the world works.
Nothing here should have provoked you enough to get that combative.
It's an amusing point they made. Not to mention, we're all roleplaying anyways. It's just not that serious.
And none of us including the thread OP is actually ever going to do this, much less involve "their lawyer" over a networked <form>. It's like when we roleplay that we're going to call our government representative and inconvenience some intern with some stern words: it's just a fun circlejerk. None of us are actually going to do it.
So it doesn't make sense to get emotionally involved to the point of asserting that someone misunderstands how everything in the world works.
Also aeons ago in tv-adverts: "Advocard ist Anwalts Liebling!" meaning with this card you are the lawyers favourite.
So basically, yes, with appropriate insurance you can have that done for you :-)
Something like: https://www.kalzumeus.com/2017/09/09/identity-theft-credit-r...
Yeah, it's amazing! I think we need even harsher laws. Data should be toxic for businesses. They should be aiming to know as little as possible and to forget everything the second business is concluded. They should be too afraid to do what they're getting away with today.
It won't be much of a scramble. First, they will look at your email to see if you have actually provided enough information in the email to tell whose data you are talking about and to prove that you are that person. If not you will probably get a response telling you what you need to provide.
When you've provided that information, then they will run their standard "delete someone's data" procedure. Whether or not that actually deletes and data that came in via some pre-submit channel will depend on whether they actual realize they have that data.
If they are actually using that as an intentional persistent data collection method, it will probably be in some place that is covered by they normal "delete someone's data" procedure.
If they are using it for some transitory purpose, it is quite possible that any long term storage was accidental and might not be in someplace the "delete someone's data" procedure covers.
In either of these cases it won't cause any scrambling.
Finally, your delete request will probably be added to a database along with enough information to identify whose data was deleted. They need this because GDPR data deletion requests do not require the company to immediately go through all backups deleting your data from them. It is likely to remain on old backup media until the ordinary backup media rotation reuses that media for a new backup.
Hence, they need to keep a record of deletions and who they were for so that if they ever have to restore from backup then can then reapply deletions.
This last is kind of amusing. Where I work we keep very little data on customers beyond what is legally required by the EU. When someone requests data deletion it can actually increase the net amount of data we retain about them. The record of their deletion request can add more data than the deletion request deleted.
When you personally request something it will get handled by their usual support people, but letters from lawyers usually go straight to legal and get handled there.
Legal saying "what we're doing may be problematic" is much more likely to cause change.
Which is what’s happening here - they’re collecting data that the user isn’t even submitting.
What if the user submits personal data without being expected to? For example, I have to enter a nickname on online game before starting to play, what if my nickname is my full name and home address? Now they unknowingly store PII without a privacy policy. What should the company do in this case?
I use auto complete A LOT and my customer's love it. On the back end I sure could be storing that information (I don't)...
There's some good use cases that easily could be a keylogger, but aren't, or at least we don't know. Even if they store something that isn't auto complete it could be legitimate "hey are people stumbling over those stupid dashes all the time?" exploration of how the users do things.
Real dark patterns, and legit features tend to intermix sometimes and the devil is in the details...
Saving a partially filled form is something that should be a feature in the browser, you can do "File > Save Form Data" (and then specify the file name) and "File > Recall Form Data".
I generally disable JavaScripts. Sometimes the web page will still be displayed if CSS is also disabled (and sometimes I want to disable CSS anyways), and sometimes links to original data, etc can be found if you view the source.
Do what client side?
Store all the auto-complete possibilities client side? I think that doesn't make sense.
But my larger point is you can't tell for sure if it is a keylogger or just something else.
Once you send a partial text that returns a few hundred results, any additional typing can be completely handled on the client side. If you only have a few hundred options at all, you don't need to send any text.
That's just good software engineering, by the way. Autocomplete queries are quite expensive, you want to minimize them. But, of course, that won't stop sending data pasted in a single step.
Anyway, the article isn't about auto-completing fields.
At that point you're sending anyway ... I'm not sure someone seriously concerned about keylogging to the point that they object to auto complete cares if you send 5 or 6 characters.
I think at that point you're addressing all your users on behalf of a few who are so concerned that they're not going to be happy with any "solution" outside turning it off altogether.
You are literally transmitting my keystrokes through several log keeping machines, to a piece of software that probably keeps logs.
I mean, yes, this is the internet we're talking about. I think this discussion is breaking down because keylogger = surreptitious, like when you are being logged by a third party when typing to a second party (ie you type a Google search into google.com and person who is not Google listens and logs that). It would be weird to describe you performing a search on Google as keylogging, though Google used to "transmit your keystrokes through several log keeping machines" to get auto-complete working
Copy and paste won't help you here. This usually happens on focus changes and frequently is done not as part of form submission but to see if people bounce from the page and for stats - meaning it goes to a less secured database and usually has widely available access to it.
The fix here, in my opinion, is a mixture of technical (browsers aggressively disabling this sort of thing) and legal (penalizing accidental disclosures heavily). As a user, you can't do much.
Here's the original presentation: https://homes.esat.kuleuven.be/~asenol/leaky-forms/
I had a friend that had his card charged, even though he hadn't actually completed it (He entered the card number and exp. date, but then left the shopping cart, without completing the transaction).
The Web site owners were pretty damn aggressive, when he complained about it, but he was even more aggressive (he has since passed, but he was not someone that you wanted to mess with).
I do that somewhat often, for sites that don't reveal shipping charges and other components of the "final price" until the end. Sometimes at that point I'll change my mind. Never been charged, fortunately, but I have worried about the possibility.
What site? I want to know what it is so I can suggest all of my friends avoid it like the plague.
And then popped his clogs, so he took it to the grave with him.
He was an IT guy, though, so it was probably a nerd site.
It'll be for abandoned signups.
If someone is literally on the signup page but end up not clicking the submit button you want to find out what stopped them and coerce them somehow to actually clicking the button.
The more data you gather about the process the more you can adapt the signup page to actually get them to click the button. It's really important for startups as one of their KPI's will be new signups per X. Companies like slack, facebook, youtube ..etc have teams of people who are working on this type of thing.
Note: I do not condone this type of invasive analytics but I'm telling you why they do it that's all.
They found that oftentimes prospective clients would write a first draft that was much more candid about what they wanted and what their budget was, and then they'd revise it to make it more circumspect before submitting.
Going into negotiations, our side had the original unfiltered data.
“Your basket is still here” kinda thing
Protip: Always make sure the focus is on your terminal when typing in credentials to it, or any input box that holds sensitive info. I sometimes forget to focus Firefox's master password prompt too and end up typing my Firefox master passphrase into other apps!
Once having typed a password into Teams, I decided to create a small Keyboard Maestro automation (on Mac) to automatically remove focus from apps like Teams after a short period of inactivity. It’s not intrusive but just ensures that the current focus is not left in the chat message box when I’m not actually typing chat messages.
Additionally I’ve taken to having all comms related apps on a separate machine to my main development machine. This was ostensibly for reasons of reducing distractions, but hugely helps reduce the risk of this sort of accidental input as well.
On my Linux system, I run Fvwm2, and because on X the decision to grant focus to a window lies with the window manager, I can control who gets focus via my Fvwm2 config. I have Fvwm2 set for focus follows mouse so unless a popup happens to appear, directly under where the mouse cursor happens to be at that moment, the popup can appear, and be "on top" and my keyboard focus is unchanged.
I also have Fvwm2 configured so that a window gaining focus does not in any way change its order in the stack, so I can focus, and type, into a partially obscured window, without ever moving that window up/down from where it sits. An old version of OpenOffice (I think back when it was still called StarOffice) had decided at some point that if the mouse cursor so much as brushed across its window that it would pop itself to the top and take keyboard focus. That happened about two times, then I added a couple lines to my Fvwm2 config to take away StarOffice's ability to both take focus and to raise itself to the top, and it became a properly behaved program that stayed put until I told it specifically to move to the top.
These kinds of irritants can be fixed, but only if the environment one uses gives one the ability to control these miss-behaviors.
Especially problematic if you happen to hit Enter for a line return and end up accepting the default selected button on the popup instead.
I think there should be some OS-level heuristics-driven functionality to prevent or delay this sort of thing while the user is actually inputting data. And prevent any third party apps from overriding this unless consent is explicitly given (if the app really needs direct control over window focus) similar to how consent is required for apps to record the screen in macOS.
/me gives Ubuntu the evil eye
I'll open it up, click connect, then go back to my work while it churns away and establishes a connection.
The number of times I've been in the middle of writing something and had the connection dialogue gleefully pop up to inform me that it's finally finished, only for me to hit return on what is now a focused "disconnect" button...
It is indeed, furiating.
Most popular website are tracking your mouse movements and clicks on their website. It's called a user heatmap and it's meant to be used to see what users are actually clicking on when they drop into your website i.e. everyone highlighted this word on you copy or stopped scrolling after this section that sort of thing.
It's been happening for many years. If you don't want to give websites this data block javascript in your browser by default.
Seems fairly sensible to figure out how to optimise the ui
It is. Everything you do is being logged and categorized, and your automatically assigned device fingerprinted user UID (whether you've made an account or not), is associated to all of your actions. Those associations are then dumped into a data lake for data scientists to mine for marketing purposes, and to cross-reference your activities across other sites.
They don't record information typed into forms, e.g. addresses, emails, CC numbers. Well, some don't record by default, with others you have to specify that manually.
Either way, it's better than a Facebook or Twitter Like buttons that infest the web and connect your visits with that site to your Twitter/FB account.
I'm sure some sites don't do this, but plenty do.
Check out FullStory. It's a drop-in Javascript snippet (aka accessible to any marketing/design folks) that records the DOM and rebuilds it as a playable video in their backend as if you were doing a screenshare and recording it.
It's even worse than this. They have full HD screen recordings of every single user session, including all values typed into any input field regardless of submission. I can pull up hundreds of thousands of unique user sessions right now and sit there watching everything they did on our sites, going back for years.
Say it with me now:
Every. Single. Interaction. With. Any. Computer. Is. Tracked.
If you store and mouse movements, scroll events, clicks ...etc and you know what the website looked like then you can replay these to produce something that looks like a video. The bonus points is that you can run mathematically analysis on the clickstream to get things like most clicked area and suchlike.
It's actually the same data that's used in the heatmap just a different visualisation.
Most heat mapping services do not store such qualitative data because of the cost (e.g. hot jar). They opt instead to simply reproduce the "almost full story" by faking a video from the data. Services like fullstory are different.
It's not anonymous and it's not just buttons. Furthermore it comes down to consent. I can see the cameras in the shop. I have no idea without doing network traffic analysis what kind of surveillance is happening on a website.
When I need to allow JavaScript on a page - I know all bets are off.
I like the uBlock Origin toggle myself, aka the "naughty website gets no javascript" button.
A dark pattern all too common these days. I hate the modern web.
This is a belief I strongly disagree with that has become pervasive on HN: "I don't like this thing so it is a dark pattern/is toxic, etc." People will, on the one hand, decry the current state of news media and bemoan how Google and/or Facebook have destroyed or perversely mutated it, while, on the other hand, decry the efforts of the news media to monetize (aka get paid) for their efforts.
There is no free lunch. Journalism isn't free. Labor isn't free. We certainly aren't entitled to the free use of the products of each other's labor.
It's just a bait and switch. These journalists want all the benefits of the web: free indexing and archiving, free global distribution and rendering, virtual word-of-mouth advertising; a huge and easy revenue generation model. Their production and design costs are nothing compared to two decades ago. They don't own printing presses. The internet pretty much bends over backwards to throw traffic at them, and on top of that, they rip the rug out under your feet as soon as you land there! Like you can't even read the words that they wrote unless you agree to more bother, and they've already made a few cents off you just from the ads that were served! And to boot, the whole show shoved megabytes of crap in your face, which actually costs you money, and they follow you around the internet like an unimaginable creep.
It's like they feel entitled to all this free stuff and the one thing they offer of value they pull back at the last second. Shitty.
FTE salaries, healthcare, equipment, business expenses, travel costs, legal fees, etc, etc versus...few cents? Maybe it would help the conversation if you can you quantify what you think they're actually earning from all the "free stuff" as you claim.
A few cents, for one page load?! lol
> These journalists want all the benefits of the web
Where's this coming from? Where's this "want"? Most of the stuff that you listed is either explicitly paid for or just comes with the web automatically.
> free indexing
Yes, Google offers free indexing because they get search engine ad revenue as a result. There's no "stealing" here.
> archiving
Hosting costs money. Journalists pay for that themselves. There's nothing "free" about it. The end.
> free global distribution
They're also paying bandwidth costs.
> and rendering
There's no way to view a page on the internet without rendering it on your computer. That's not something that journalists are taking advantage of - it's how the internet works. Also, publishers pay for hosting costs, too...
> virtual word-of-mouth advertising
Word-of-mouth is completely unrelated to the internet.
> a huge and easy revenue generation model
Please don't tell me that you're complaining about publishers trying to recoup costs of the journaling process. Who's going to pay for the salaries of writers? Infrastructure costs? Distribution? Web development?
> Their production and design costs are nothing compared to two decades ago.
...and yet, the costs are still there. Publishing is not free, especially if you want content to publish, and especially if you want quality content.
> It's like they feel entitled to all this free stuff and the one thing they offer of value they pull back at the last second.
The only entitlement here is you feeling entitled to the work of journalists. This is a rant with little substance behind it, predicated on the false assumption that publishers and journalists have no costs.
So non-free stories should not get any free promotion on HN then. Non-free outlets are not entitled to get their free share of my attention.
Where can I send the bill for the occasions where they managed to fly under the radar and grab a bit of my attention without paying (me) for it?
I think you've got that backwards
So print newspapers, and sell them. I regard the worldwide web as free to use; I treat sites that don't share my view as not being part of the worldwide web.
The world is full of interesting websites. If a website doesn't want me to read it, that's fine, I'll move on.
Sure, but it's rude to present something and then take it away. Google used to downrank sites who did this, anyone remember how awful experts exchange was? If they want to have a paywall then they should have a paywall.
On a similar note it’s using unnecessary power (quite possibly from a battery of limited capacity) rendering a paywall with an effect nobody wants to see, except probably the people who made it.
There’s an easy solution: HTTP response 402: payment required
In 402's case, if it was, say, legislated by the government, then the following would happen:
(1) Users wouldn't be bait-and-switch'ed by a paywall that revealed part of the content before appearing
(2) Companies would need to band together to implement a micropayments framework
(3) Lasseiz-faire maximalists wouldn't be able to complain because the only requirement would be that paywalls be signalled by an HTTP status code
The only potential downside is that companies might, instead of making a common micropayments API, instead just use Google, or even worse, not use any common platform and instead make consumers sign up for a new account for each site.
Lightning Service Authentication Tokens[1] (LSATs) provide a standard that’s usable today.
With a Lightning Network browser integration like Alby[2] you can access paywalled content behind a proxy like Aperture[3], and it’s a very smooth process already.
However, it’s also not my problem to solve. That’s a problem for Wired to solve. How I feel about these UX patterns and business models is not negotiable; it’s an honest reaction. How Wired makes money and deals with free use is negotiable.
The internet has not been kind to many business models, particularly, it has been rough on paying for content. That’s just what happens when copying costs basically $0. You can pirate almost anything and people definitely do. Many people will immediately hop on archive.is if they hit one of these patterns. Personally I often just don’t read the article and leave.
In the end, it isn’t my problem if people don’t like my attitude. Wired is trying to sell to me, so it is absolutely their problem if I don’t like this pattern. And guess what? I am, in fact, a former Wired subscriber. Maybe they make more money now that they paywall, but I don’t even care. I’m still going to hate them for it.
Likewise, I will never like or respect being forced into advertisements. If I like something enough, I will pay for it. I pay for YouTube and it feels like a win/win for me.
You clicked a link to a Wired article that someone posted on Hacker News. Wired was not involved.
Digital properties aren't going to be groomed to meet your precise tastes. This is doubly so for general interest publications like Wired that have to appeal to a broad base of viewers and can't charge more than a few bucks for a subscription.
If the article is valuable but paywalled, there are ways to get around that. Try turning off Javascript or accessing the page in an incognito browser. archive.ph can also work.
> You clicked a link to a Wired article that someone posted on Hacker News. Wired was not involved.
Well, to some extent, I'd argue they _are_ trying to sell to him. From everything I've seen the whole "display the whole page of content and then block with javascript" is done so that the whole page of content gets indexed by Google. If so, then they are intentionally trying to lure non-customers to their site with that content. Admittedly, coming from HN isn't exactly the same, but it's the same general audience of non-subscribers they want to come look at their content and subscribe.
If it works for them today, good for them. It works for some big publications. Let’s see how that continues to pan out as subscription fatigue increases and publications close up content almost entirely.
It loads just fine with NoScript enabled. It also loads instantaneously (well, almost - ~200ms) and doesn't autoplay video or nag about cookies.
But I agree that it sucks to be here. And while I agree that journalism is between a rock and a hard place to all of our detriment, not sure "Wired" is that kind of journalism.
Designing something to deliberately annoy people when they could just be upfront about things seems like a tricksy way to behave IMHO.
I suppose you mean "I hate people making money off the modern web"
or just disable javascript
The closest thing I can think of is as an "abandoned cart" for forms.
"You were about to submit our contact form to ask about our software. Are you still interested in a demo? (we're evil, by the way)"
Not really the same thing as taking your payment and address information and sending it to some guy in a basement. Half-complete or incorrect data isn't an issue any company wants to deal with. Abandoned Cart functionality makes money, so that's why it's included.
Whenever I talk in a chat pop-up I always assume they see live what I'm typing.
And I do think that a normal person must be a bit pathologically skewed, here in 2022, if they are not a little bit cynical or paranoid when they interface with a computer.
Finally, one can be ultra-paranoid, cynical, or just mildly knowledgeable about the technology upon which the entire modern experience depends.
Language can change everything.
A few years ago in a digital self-defence class someone picked me up on choices of words.
Paranoia and cynicism are pre-Snowden words from an era when the nature of online computers was unclear to most people. Since 2013 (that's almost a decade ago now) we've been in a world where it's taken for granted by anyone with an IQ of 2 or more digits, that digital devices and many services are hostile. Cynicism and paranoia are no longer strictly possible.
I was grateful to the young woman who pointed out that adopting negative psychological language empowers the attacker and places the victim on a back-foot. Cynicism and paranoia are no longer accusations you need to hear, nor feelings you need to own.
Since then I have tried to couch digital self-defence language more carefully in terms of self-respect, dignity, informed consent, and ultimately in terms of ethics and morality that reasonable and informed people expect. By "reasonable", we do not mean bullied and browbeaten into learned helplessness by threats of compulsion, total lack of real choice, subterfuge and deception.
Pre-Snowden, there were many of us who weren't paranoid or cynical, but who were not surprised by surveillance tech. And some of us weren't tech experts either.
One person's cynicism is another person's gentle understanding of social mechanisms.
There's probably an untold amount of shady data-trading stuff happening whenever I swipe my credit card at a POS somewhere. I don't know because I'm not a payment processor expert.
If someone is surprised that in 2022 people are tracking / logging your digital interactions, well, I don't know what to say.
Source: Kevin Systrom on Lex Fridman Podcast https://www.youtube.com/watch?v=3pvpNKUPbIY
The issue with the Instagram model is that it looks like you are just doing things locally on your phone, and haven't uploaded yet. If you have second thoughts and decide not to post the pic, Instagram could keep the photo.
That said, I don't really see why they would do this. What would it gain them to keep millions of discarded photos?
My point is that it is feature clearly people appreciated, not a dark UX pattern.
Where Google goes, others will follow.
Storing data is not free and if you plan to use this data for anything it can definitely be not cheap (i.e. cold vs hot storage). When you extrapolate this to the scale of a service like Facebook or Google it becomes insanely expensive. So there would have to be some pretty clear monetary payoff to justify this expenditure. I understand the worries of privacy advocates, but I don't understand the economic incentive of keeping all this data. The only way it could possibly make sense is if it were highly aggregated, but at that point you nullify many of the privacy concerns.
I think there are a lot of companies that are not running out of money and are holding on to a lot of data that might, someday, be valuable. Look at Google's features like spelling correction or search term suggestions - they likely used huge troves of semi-anonymous user input to develop and support them.
> When you extrapolate this to the scale of a service like Facebook or Google it becomes insanely expensive
This is just not true. Backblaze is putting their storage cost at ~$0.035 a gigabyte[1], which means you can store a megabyte of data for every human on earth for a bit under $300k a year (about 8 petabytes). Big companies probably can get even lower. This isn't...a negligible cost, but it's very normal at that scale. Google only has ~4.5 billion users and most companies have orders of magnitude fewer.
[1] https://www.backblaze.com/blog/petabytes-on-a-budget-10-year...
There's a big difference between data which is directly tied to PII and data which is held in aggregate in terms of privacy. I'm not arguing there can't be leakage here, but it certainly blunts many of the more severe privacy implications. Conflating these two is more sensationalist rather than useful in terms of honing in what is ok vs what is not.
> which means you can store a megabyte of data for every human on earth for a bit under $300k a year
Sure, I mean as a slippery slope you could also write this data to paper and keep it indefinitely at a very cheap price. My point here is more: if you plan on using the data, it becomes more and more expensive as your access patterns change. This also has privacy implications because I would imagine the easier the data is to access in raw form the higher the potential privacy cost to the user. If all they are doing with these key strokes is recording somewhere that you might be interested in Corgis and German Shepards based on your keystrokes, as opposed to something more detailed like an accidental paste of your password, I think that changes the conversation.
I don't think this is true either. Google does not need to keep much of its data in hot storage to use it effectively: their ML products can be periodically trained / updated, their search can be iteratively updated with each crawl, etc. Sure, it would be expensive to keep all user data from all sources in hot storage all the time - but it's not needed. The idea that you...would happen upon some new question you hadn't though of before and need to get the answer immediately is just false. Instead, you make regular updates to a model and periodically run your corpus through that model.
Responsiveness creates a better user experience.
In our use cases we are using this primarily in search fields. In a few places we do queries onblur. The cost of these queries is trivial, directly hitting indexed db columns. I don't think we have any db inserts triggered from this behavior, and we don't log request params as a general rule (except rarely for short term debugging or non-sensitive performance tracking).
(Wondering if some built-in accessibility features in the OS might have something similar.)
(TCP View is not really a firewall however, it just lets you inspect traffic, but not block it or filter it)
https://github.com/evilsocket/opensnitch (Linux)
https://www.obdev.at/products/littlesnitch/index.html (Mac)
https://www.glasswire.com/ (Windows)
https://docs.microsoft.com/en-us/sysinternals/downloads/tcpv... (Windows)
Correct. You could always have JS disabled by default in uBlock Origin to mitigate JS snooping on sensitive info, so there is that. You can blacklist specific domains in uBlock too. We need something like Portmaster[0], but inside the browser as an extension.
Apart from a few of us nerds on HN nobody will do that. In reality people have a hard time seeing the problem with re-using a password, making people decide which hostnames are okay or vet javascript files before allowing them is unrealistic and not the solution to the problem.
I subscribe to exactly one website. If I subscribed to every subscription website that I read, I'd spend more on subscriptions than my income.
So: F12, "display: none". Wut? Really? A one-paragraph article? I guess Wired can join NYT and Washpo as sites I'm not going to visit, because they don't want the likes of me to visit.
> Heap collects all the data on your customers - automatically. What they click. Where they go. What they do, even when you’re not looking. All without the need for engineers.
[1]: https://heap.io/
But the simplest way to check would be
1. Inspect element > start recording under ‘Network’
2. Press any key, and check for new requests visually that correlate to the time you pressed the key.