MLB.com is using my Google Analytics code
websanova.com
websanova.com
I guess they copied a little too much.
Wait, why do /you/ feel like a jackass?
"Hi -
Engineer from mlb.com here. It appears this goes a bit deeper down the rabbit hole than meets the eye. Apparently there’s some code laying around in our tests run by a CI setup that randomly generates a tracking code to mock third party scripts (Google analytics, ad tracking, etc) instead of using our actual IDs as to not mess with our marketing guys’ numbers (we run a LOT of tests on CI).
The strange thing is that your IDs aren’t being pulled from your site, but have randomly been generated the same way many, many times and then been shipped out to our production server by mistake.
We can’t figure out why this is happening, but are looking into the build system and how it caches data. Luckily I read HN or we might have never caught this!"
What is more probable, that they a lying, or that the random generator generated not a single code that matched, which is very(!) improbable by itself, but two codes that belong to the same account, generated at the same iteration.
That aside, though, why not just create a different Google Analytics account and use that one consistently for testing?
This was at the height of the browser wars.
It was reasonably easy to deal with, though; all you need to do is figure out where the sites are hosted, and then submit a DMCA complaint to the host's abuse address indicating they're hosting illegally copied copyrighted material. Legitimate hosts will take stuff like that down pretty quick.
There's two things the DMCA requires that they'll look for in your complaint before they'll take action, though, so make sure you include them:
1) The statement "I swear under penalty of perjury" that you hold the copyright for the material, or that you are representing the person who does; and
2) A list of filenames that contain the infringing content.
(If the host won't take action, you can file the complaint at whichever registrar the domain was registered through, too.)
He continued contacting me for about a year saying that he could no longer feed his family after "what I did". It was kind of a nightmare, but I think ODesk had pretty swift judgement because that's the kind of press they don't want. I also talked to the company that was using my code. They explained that they had hired him on ODesk and had no idea. They wanted nothing to do with the stolen code, and were very apologetic for their accidental involvement.
edit as I'm being downvoted rapidly. All I'm saying is that oDesk typically connect a westerner with a developer in somewhere like India who thinks that being paid $3/hour is fantastic, and who's other options for a job are basically hard manual labour.
Obviously I don't know the details of this situation which is why I just said I wasn't convinced.
It seems very plausible to me that the worker really was unable to feed his family after having his account terminated, and it seems like a bit more lenience on the part of oDesk would be more reasonable.
In the western world, if you steal code you expect to get fired. I totally understand that and that's why I just said it wasn't clear-cut to me that the right thing happened here. It might be, but I'm not sure. In the western world if you get fired you have a lot more options.
Maybe situations that involve basically exploiting workers in other countries need a bit more sensitivity. I don't know. Maybe not.
I'd appreciate a discussion instead of just downvoting.
That's called cheating the customer...fuck these guys. Even if they need the money.
I can't quite express the difficulty I'm having in a comment so I'll try to write it up some time.
I can't argue it yet, but my intuitive feeling is that it's socially irresponsible to create this economy for them and then pull the plug like this. The bigger picture, I think, is that OP got his code stolen which sucks, but the contractor (or one like him) may have to sell a kidney or go back to working 18 hour shifts in the factory with toxic fumes now. That doesn't seem proportionate.
Protecting wrong-doers because "we" have supposedly created a system that forces their hands makes no sense.
If I knew a drunken bicycle thief-citizen would be imprisoned for years, I wouldn't report them, either.
This shrinks the market, reducing demand for programmers in India. Now MANY Indian programmers can't find work, even ones who were honest and efficient.
I think this effect is very important to keep in mind if you're concerned about the morality of the situation. The thief is hurting his fellow Indian programmers just as much as his western customer.
>> Maybe situations that involve basically exploiting workers in other countries need a bit more sensitivity.
I disagree that he was being exploited. Yes, he was being paid a lot less than someone in the US but the cost of living where he is is probably much, much lower. And like you say he has a nice job as a computer programmer. He's obviously a smart guy. He can create another account, or use a different site.
>> I disagree that he was being exploited.
Yes, I think that might be what this whole thing hinges on.
There are a lot of people living in poor conditions in the world, and a programmer in any country is near the middle-to-upper end of the spectrum. His situation is unfortunate, but he messed up.
On a similar note: my current lab-mate lives in a pretty bad apartment in Boston right now. It is habitable and up to code, but run down and occasionally the heat goes out... He provided me some prospective by telling me about the one-room, dirt-floor house he grew up in where his parents raised 11 children while working as subsistence farmers in Nepal. That makes luke-warm water and 5Mbps internet seem much fancier.
I pray that some day everyone can live the life of a poor to middle class American, but we are not there yet. I also don't think that being fired is an excessive punishment for fraud/theft at work. I would feel much differently if the story ended with hime being jailed or abused by the police, but the whole point of Odesk is to give everyone a chance and I feel that he got one.
LOL, keep telling yourself that. Having a 'lower cost of living' doesn't excuse paying a software developer a much lower rate than the rest of the world.
While thier might be some anecdotal evidence where this is true it's mostly just you being prejudice.
The developer stole code without understanding it, happened to be in India, and then attempted to play for sympathy by saying he couldn't feed his family - there are a lot of tech jobs in India, and the vast majority are not on odesk, if he is any good, he could easily feed his family, and furthermore, the fault was his, the offence was his, and then he has the gall to complain to the person he stole code from, who did not even punish him or pursue him, but simply reported what he did. Workers in India with an education have a lot of options which are nothing to do with manual labour, it's a vast and increasingly rich society.
The person reporting a crime is neither responsible for the original crime, nor for the punishment decided on by a third party (odesk in this case), nor for the situation of the criminal, and the dev ejected from odesk should have thought about the consequences of breaching their terms.
He was bound to get caught when being so sloppy, it was just a question of time, and he could have fared far worse (been sued by a client for example). Hopefully this experience will make him question his methods and pursue his career but without carelessly copying work.
Yes I have. There are plenty of middle class people and most technically educated developers are among them. There are also a lot of tech companies hiring.
In any case, alot of my family are middle class and can't find decent jobs. The competition is very high and programmers are a dime a dozen. Technically educated doesn't mean they enjoy it. Most consider it a job to get by. Some find it to be a passion. The ones who see it as a paycheck are far more likely to rip a site off and the culture is such that it doesn't seem wrong. "Someone else's problem."
Why? Does ODesk have zero competition? He could switch over to one of them and probably already did. If it is somewhere like India then there is a thriving non virtual market for software developers. Why couldn't he get a job at one of the big body shops? It certainly isn't ODesk or the salt mines. If it really is ODesk or the salt mines, why take the risk?
They copied everything[3], including my tracking code, but at least changed the name to "Thunder Fighter"[4]. I receive about 20k visits per day from their domain. All my efforts trying to contact them amounted to nothing.
Btw.: is there a way to ignore certain domains in GA? This pollutes all my stats and I have no way to turn it off, other than getting a new tracking code.
[1] http://phoboslab.org/xtype/
[3] http://img.3366img.com/fileupload/html5/games/X-Type2/X-Type...
https://support.google.com/analytics/answer/1033162?hl=en-GB
Note that this doesn't apply retrospectively to your data, so it will only apply to data collected after you make a change. You might want to create an advanced segment which filters out these domains, or only includes the ones that you want.
https://www.google.co.uk/intl/en/analytics/features/advanced...
I found out because he kept emailing me with support related questions whenever he'd run into issues with it.
He didn't get any support from me though and, if I got to know him well enough in that year, I'd say he didn't get much further with it. Google brings up nada so I'm probably right.
But why are you generating those random IDs at all? That means you guys are sending false tracking data to so many websites using those IDs.
Stop doing this! Create a different tracking ID for testing or something!!
Inside google analytics goto filter, create new filter, select custom filter, select include filter, Enter hostname in the filter field, enter your websitename\.com in the filter pattern box,
Apply this filter to your profiles for websitename.com and you should be good to go
Would be happy to discuss if you could clarify your statement regarding A/B testing.
From https://support.google.com/analytics/answer/2637192?hl=en
> If the number of visits/sessions to the property in the given date range exceeds 250K visits/sessions, GA will employ a sampling algorithm...
> It is important to note that session sampling occurs at the property level, not the view level.
So it sounds like reports will sample 250K from total traffic first, and apply the view filter after. This has the potential to be left with reports generated on too small of a sample.
Y/N
And even so I supposed after the verification step the code is active so anyone could use it. Does GA code ever expire?
Sounds like an expiration date would be a reasonable solution plus a way for the account holder to deactivate the code from admin panel.
https://productforums.google.com/forum/#!topic/analytics/Cln...
How large of a spike are we talking about here? Share your digits bro!
They had crawled the entire site (which was designed by our partners) and replaced the logos and text. The GA code was still there.
We decided it is not worth going through the hassle of chasing someone who claims their expertise to be cloning a website.
That's the product they were selling. Clone websites. And I daresay they proved their competence by cloning ours.
It looks like a legit programmer's blog to me, so I gave it a full positive review.
Edit: Might be same shop as mlb.com, they don't appear to care about asset performance either.
More reading: https://support.google.com/analytics/answer/1070983?hl=en
Have you ever run GA on a high traffic site or app?
Google gives you warnings. They're small at first, but when you're really hammering them and aren't paying for premium there are big red warnings about your data is getting heavily sampled. We have a relationship with Google, so they also personally reached out to us to ask us to fix the issue before they shut us off. I work at $BIGCORP so going through the procurement process is a lengthy process.
When you buy premium, you get the unsampled data (and a person to call on the phone)
I once had my site's design stolen complete with my CSS, Javascript errors, the Analytic and the Adsense Code. I think I have the screenshots somewhere on Flickr.
The irony was that, mine was powered by a WordPress theme that I designed and was available as a free download.
If I was a bad guy this would be an easy and subtle XSS attack vector
/I-know-one-weird-trick-to-save-money-on-car-insurance
/buy-coke
Have you tried turning off your machine and turning it back on after 5 seconds?
Verified it's working on Firefox for Android now. (Nexus 5)
GA allows you to then break down stats by domain.
But does their code looks similar to yours?
Much more likely this is a typo in the ID number.
Sergei knew about the potential for a problem with crc32 so they went with crcgoogol instead. Clearly the 1 in 10^42 eventuality happened, improbable as it seemed.
This will not go unnoticed.