Still ridiculous, but not quite the same thing as being banned for opening dev tools (of course, I am also speculating here, I guess we'd need to hear from mailchimp to be sure).
Edit: i see that people have replied with answers to this further down the page
https://github.com/sindresorhus/devtools-detect
EDIT: doesn't seem to work if I have devtools as a separate window
The detection is hilariously primitive, entirely unreliable, and only knows about your devtools directly if you're using Firebug.
[0]: https://github.com/sindresorhus/devtools-detect/blob/main/in...
Yeah, as other posters hint at, vertical tabs. But it isn't just vertical tabs that'll trigger it, any sidebar will, including native/vanilla ones; AFAICT it's just looking at the client area being less than the window by some threshold.
It only detects if there is a block in the browser that does not serve as website rendering. Since I use Tree Tab on side panel of Firefox, this plugin will believe I have opened devtools all the time.
Edit: it will think I closed devtools when I really open devtools. I start to wonder how shitty the code is.
I have a tic disorder (not Tourette's, because my tics are all nonverbal). One of my tics is that I mash both mouse buttons over empty space pretty frequently. I even go out of my way to keep my cursor positioned over empty space so I can mash the mouse buttons when I need to, and it's not uncommon for me to move the cursor while mashing the buttons. If the cursor is towards the bottom of the screen, that's pretty much guaranteed to open dev tools, since all it takes is a small motion of the cursor with the right-click menu open to hit the 'Inspect' option.
I suspect that would be easy to solve with smarter context menus that could ignore clicks likely to be accidental, since "Accidentally clicking the thing that just popped up before you even see it" is a common ish mistake worth implementing workarounds for.
Great, now I need to wait 8 seconds while my browser re-renders some 40-meg page which could've been plain text.
On the other hand, if I ever think about using MailChimp to send spam, I hope someone would just come cut my hands off, then I won't need to care about hitting the wrong keys.
You can also do it in Settings: type "cookies" in the search box and it will list both an option to clear all data and an option for site-specific data.
I have severe and sporadic clonus in my mousin' arm. I do exactly the same thing when I need to keep my hand on the mouse.
Another thing that I have done off-and-on to accomodate certain software is to have my keyboard or mouse 'toggled' off and on with an autohotkey (or equivalent) script. If I need to rest or wait for something with my hands on the hardware then I toggle the thing off with an easy-to-reach hotkey of some sort until i'm ready to actually type/mouse.
* The copy command for many terminal apps on linux
That's still Tourette's. Tourette's is described as an involuntary movement /or/ sound.
EDIT: “vocal,” I should say, not “verbal”
> Tics are sudden twitches, movements, or sounds that people do repeatedly. People who have tics cannot stop their body from doing these things. For example, a person with a motor tic might keep blinking over and over, or a person with a vocal tic might make a grunting sound unwillingly.
> The tic disorders differ from each other in terms of the type of tic present (motor or vocal, or a combination of both)
> To be diagnosed with TS, a person must
> * have two or more motor tics (for example, blinking or shrugging the shoulders) and at least one vocal tic (for example, humming, clearing the throat, or yelling out a word or phrase), although they might not always happen at the same time.
> It is characterized by multiple movement (motor) tics and at least one vocal (phonic) tic.
> Tourette's is at the more severe end of a spectrum of tic disorders.
> Tics are sudden twitches, movements, or sounds that people do repeatedly. People who have tics cannot stop their body from doing these things. For example, a person with a motor tic might keep blinking over and over, or a person with a vocal tic might make a grunting sound unwillingly.
> The tic disorders differ from each other in terms of the type of tic present (motor or vocal, or a combination of both)
Three tic disorders are included in the DSM-5:
- Tourette syndrome (TS, sometimes called Tourette disorder)
- Persistent (sometimes called chronic) motor or vocal tic disorder
- Provisional tic disorder
Again, tics don't automatically mean Tourette's.And a non-verbal tic doesn't automatically mean it's not Tourette's.
> Tics are sudden twitches, movements, or sounds that people do repeatedly. People who have tics cannot stop their body from doing these things. For example, a person with a motor tic might keep blinking over and over, or a person with a vocal tic might make a grunting sound unwillingly.
> The tic disorders differ from each other in terms of the type of tic present (motor or vocal, or a combination of both)
The link you posted establishes that Tourette’s is a tic disorder. The person says they have a tic disorder that isn’t Tourette’s. I’m perfectly happy to take them at their word about that.
You /assume/ I have no knowledge.
Very simple for a system to detect the request for the map file.
If that's their vector turn off the autoloader and try from a clean IP.
Could yours be a Windows Group Policy from $WORK?
The source map requests was a more successful option. Also played around with "snap" resize but it was too agressive.
As for whatever the reason MailChimp would block your up is pretty ridiculous.
Edit: You can redefine console.log to be a noop, but that's also detectable.
foo.toString = () => console.warn("called")
console.log(foo)
[0] https://x-c3ll.github.io/posts/javascript-antidebugging/
...and how to disable them from auto-loading.
I mean, okay, I can see how they definitely have a use. But to try and auto-fetch js and css maps just because I want to have a look at the DOM?
Why not wait until I actually try looking at js/css? Or even until I ask to see the source map?
Prefetching never feels right to me. Even though I know GET requests are supposed to be side-effect free and idempotent (and if they're not, that's a choice by the server devs and they'd better have covered all the edge cases where clients correctly act as if they are...), it has the architectural equivalent of a "code smell" to my nose.
The part I do not understand is even websites that verify you via 2FA do this, so I assume their goal is to track you no matter what.
An email client like Thunderbird or Mail will save a copy of the email on your local hard drive, which will include the HTML. This isn't something I do regularly, but would be first first response if I needed to see the HTML of an email. Maybe Mailchimp has protections against this route too?
Even if you are a single organization user and leaving for good, you might do so gradually or perform test sends first. Speaking from experience again.
We had to contact Mailchimp on March 7th regarding their flawed implementation of CKEditor.
To demonstrate the issue, we sent them a screencast[1] (in the video we opened dev tools).
We requested and were provided with a refund. Per my other comment on this thread. The content of the request was created using GPT (although the prompt history is not available, it can be reverse engineered).
The email sent and reply to the email are available[2].
I'm adding this comment to highlight the very reasonable fair use of opening up dev tools to try to workout what is going on.
[1] https://files.littlebird.com.au/Screen-Recording-2023-03-08-...
[2] https://files.littlebird.com.au/Screen-Shot-2023-03-21-at-8....
In the writeup, the researcher illustrates by copying the service URL from the browser's dev tools. And so the obvious corporate corrective action is...
https://stackoverflow.com/questions/40153206/detect-if-conso...
But if they really detect a resize, anyone who actually does resize their page will be blocked as well.
Doing that seems a bit insane to me.
There's another cute approach based on the fact console.log(foo) calls foo.toString if and only if the devtools is open.
It seems that this would create far too many false positives.
Mailchimp is pretty hostile to developers. I don't recommend using them after that experience.
Tons of downtime, worsening delivery problems, no active development -- or support even -- for years, worse pricing, ...
seems like they want to eject their more sophisticated dev customers. guess i can't blame them, but why bother, just shut the damn thing down instead of wasting everyone's time.
>Yes, you heard that correctly. We can secure ourselves like Fort Knox, but if your computer gets compromised and someone gets into your Mailchimp account, that's not good for either of us.
So mailchimp is SOC2, ISO, PCI, etc. and still gets worried about themselves if a user account is hacked.
"We retain a law firm in the UK to consult on EU privacy issues."
wouldn't it be better to retain a law firm that's actually in the EU? hiring a UK law firm for EU matters is no different that hiring a US law firm, or AUS, or whatever non-EU country
or, maybe i'm confusing them with ad agency types that i've worked with in the past and i'm just projecting one ego industry to another?
Compliance with those standards doesn't mean they aren't potentially impacted by that sort of thing, and doing what they can to detect and mitigate unauthorized user account usages is part of at least a few of them.
I opened the web inspector to show the library erroring when Mailchimp tried out a to load it, and also provided a screencast.
I wasn't blocked, but I did receive a refund.
So this must be a relatively new thing!
If I were the OP, I would complain and request a refund.
I can haz prompt pls schappim?
We experienced a technical issue with Mailchimp's editor in production, which unfortunately prevented us from editing our campaign before the deadline. Our team used Chrome Version 110.0.5481.177 (Official Build) (arm64), but the editor kept failing to function properly.
As a result, we suffered a significant financial loss due to missing the campaign deadline. In light of these circumstances, we kindly request a refund for our monthly fees, especially considering the recent fee increase.
To provide evidence of the issue, we have included a video showcasing the broken Mailchimp editor and the corresponding JavaScript error from the text editor (ckeditor). The video is available here: https:/[URL to screen capture].mov
We appreciate your assistance in resolving this matter and ensuring we receive the refund we are entitled to.
Asking GPT to reverse engineer the prompt: https://files.littlebird.com.au/Screen-Shot-2023-03-21-08-34...Further information: This interaction took place on March 7th (Sydney time).
If that's actually what's happened here, that's a real dick move.
Disclosure: I formerly worked at SendGrid
Aren't they using a JavaScript based detection mechanism like listening for browser events on the client side or latching on to debugger to pull this information? Sounds to me like they are going out of their way to pull private information from my system that I or my system or my browser had no intention of sharing with them.
Yes.
> Is it okay to collect this kind of info and use it to block access?
No. It's not okay.
> Are there no regulations against this?
Probably not. In this case the remedy is to just use another service, or DIY. And I also think that's a pretty reasonable remedy, which will send a message to others considering such actions.
FWIW I would like to see regulations around intrusive spying on client machines via the browser or any other path. Ideally we'd get new, specific legislation around it. Something might also be done at the executive level at the FCC. Legislation is unlikely because of America's current flirtation with 3rd world style politics.
In terms of advocacy, I would assume that the EFF is of a similar view. Other human rights groups would be supportive of such measures, since in addition to protecting consumers, they protect journalists and their sources as well. The people against will be state security services and all businesses powered by a targeted ad engine.
I wrote a sort of "DIY MailChimp" for a marketer back in the ancient days of the early 2000s. I did the tracking and email content bits.
I did not handle the email servers themselves. Lot of work staying off of blacklists. It was something close to a fulltime job back then, and from what folks have told me it might be more like multiple fulltime jobs these days. Lots of anti-spam regulations to adhere to, and one or two false steps and you're going to wind up in an absolute hell where other email providers (Yahoo, Gmail, whoever) are not going to talk to your servers.
Also need to figure out email templates that render consistently across webmail providers and browsers and mail clients. That is also a loooot.
Making a consumer-friendly UI like Mailchimp is another massive task, but I guess you can skip that for your "DIY" solution.
Again, I'm not defending Mailchimp. I hope I never have to dip my toes into this area again. It is hell.
But...several full-time jobs? How much mail do you need to send before postfix on a $5 VPS falls over? In terms of composing html mail that looks good, that would take some time to learn. A day to get something passable, especially with LLM help? As for tracking, I am against image/pixel tracking in emails, I think it undermines trust, so I wouldn't implement it (or use it).
I think it depends on how important delivery is to your business. If your business team expects near 100% delivery and they want all the tracking features that give them insight into their promotional campaigns, then running email promotions on your own is quite a steep hill to climb.
I run my own MTA on my own domain and only use it for verification purposes and I still have to fight with the free email providers every few weeks. It's definitely not a full-time job but I also have the joy of just not caring if a user doesn't get an email from my system.
A agree with you somewhat that people reach for mass mail services too quickly sometimes but I also understand the perspective of engineers who have things like deadlines and other work to do where if I have the choice of working on truly new things to help grow the business I work for or handling email logistics, I know where I will point the my company.
That's why "use another service" was first on the list of alternatives.
As I said though compliance with spam regulations will be a constant battle. If you don't care if e.g. Google blacklists you from gmail.com, cool. That makes things a lot easier.
The users of mailchimp don't need to make another mailchimp
Right. I said that I'm assuming you can skip the consumer-friendly UI bits.However, I'm assuming you do at least want the analytic and tracking bits in this theoretical situation. Otherwise, why use something like Mailchimp in the first place? There are other ways to "just send mail." You choose Mailchimp for the extra bits.
I get it that people like to complain about stuff on HN (I recently had a thread too) but there needs to be evidence for people to go off of.
"Request Blocked
We blocked your request because the IP address you’re using looks suspicious. This issue will usually resolve itself after a short period of time, and you can try your request again. You can also try using a different IP address to see if that resolves the issue.
If you need additional help, you can try one of these support options.
Reference Number: #####"
Some websites will try to throw you into a loop of debugger statements if they detect devtools being opened, which is harder to work around, but it doesn't seem to be the case here.
There is a similar button on chrome, but I am not sure if that also applies to the debugger statement.
Give it a try: https://sindresorhus.com/devtools-detect/
For some reason it failed to flag it for one of my attempts, but it consistently flagged it for all the others.
1. Correctly designed dev tools shouldn’t be detectable from the app itself, especially not if the tools are passively used for observing. This can be abused by malicious actors who can make it harder to detect and warn others. It can also cause heisenbugs.
2. One if those malicious actors is apparently Mailchimp. I don’t use it so I’m not affected. But from a meta-perspective it’s concerning when direct user-hostile actions are normalized by what most people consider “legit companies”. The same could be said about fingerprinting and many other tricks.
3. Meta-meta point: if you’re running a business that does this, the open web is not for you. You don’t belong, and you should try building your own proprietary stack instead. I don’t mind wolves, but please stop dressing in sheep clothing. There’s a paradox of tolerance at play here.
On firefox the easy way to get around this is by disabling breakpoints, the harder way is a userscript.
Sooner or later I'll end up on their blacklist. Ugh.
Is there a dev tools open event or does it detect f keys and right click events?
I had wanted to prevent web pages from detecting the window height, which has many benefits, including this but also prevents using the window height to override font sizes, preventing auto-loading on scrolling, and auto-scrolling ads into view, in addition to the debugger.
Additionally, detecting the outer window size should not be possible at all; it is not useful. Only the document view area is useful to detect anyways.
The only other ways I'm aware of are:
- Detecting the keyboard shortcut, ⌘⌥i or equivalent, which you can avoid by using the browser menu, and
- More riskily, evaluating a `debugger` statement and detecting whether evaluation paused. I'm not sure you could do anything about this one, but it would certainly be obvious to you whether it was happening.
Toggle the thing in the dotted rectangle: https://firefox-source-docs.mozilla.org/devtools-user/debugg...
EDIT:
BBC news puts a rather fancy one in the console
Facebook puts a warning about self xss in the console.
Welcome to the 90s.
Not that I would ever use MailChimp.
they have made it IMPOSSIBLE to take them seriously. #justSayin
1. setTimeout to call an endpoint that will block your ip. It's set to run in 2 seconds from now. 2. Insert: debugger; 3. Clear the timeout.
Now you run this function as an interval. If the devtools is closed, debugger will be ignored and the call to this endpoint will never happen. But if it's open, the debugger will stop and the timeout will fire. Not sure if you need to patch SetTimeout to continue running while you stop but I hope you get the general idea
Hackers tell non-techies to paste things into the console, which can then share cookies or access tokens with the attacker.
Obviously the browser is "owned" by the client, so a sufficiently motivated techie could bypass this any number of ways. But it prevents some number of non-techies from security issues.
But here, it seems they are detecting if the window is resized! That's just crazy.