Live data from Hacker News

We ditched Google Analytics

spideroak.com

171–180 of 273 posts

Re: We ditched Google Analytics

#171
post #159
post #94

Earlier quoted context omitted.

No. I am not passing IP. I am not passing a client-id. I am not passing any kind of correlation identifier from which a session can be inferred or created. I am not passing user-agent information. I am not passing a cookie ID. I am only passing a page view event. "Page /foo/bar?bash has been viewed". Take a look here: https://code.google.com/p/serversidegoogleanalytics/ Tell me where in that example (mine is similar)…

But isn't the same kind of data you could extract from Apache logs? Since from what you describe is basically a log of all your requests. GA has many utilities, mainly is to follow the user and see the funnel they go and second to monitor the marketing campaigns. If you don't need this, then Apache log + webalyzer is perfect for everyone.

I persist with GA, because every now and then I work with partners who would like to verify the activity on my websites (and yes my user agreements and privacy policy allow this) and have a means to compare this with historical data or data from other sites.

Those partners frustrate me, in that they won't trust me to provide stats generated from server logs, but they all default trust GA.

This technique allows me to use GA, produce the view of the content they need, export the PDF, and share that... and they trust it.

GA is the de facto store of trusted data when it comes to web site activity. For my sites that is tracking content page views.

Re: We ditched Google Analytics

#172
post #41

How about open-sourcing your product before worrying about improving other products? SpiderOak has been "investigating a number of licensing options, and do expect to make the SpiderOak client code open source in the not-distant future" for a very, very long time now. It's no trivial thing to have a closed source client for a "zero knowledge" service. https://spideroak.com/faq/why-isnt-spideroak-open-source-yet... ED…

I came here for this exact thing. They said they were going to go open source in 2014 IIRC, and failed to deliver. I have stopped using SpiderOak - how am I supposed to trust them with my most private files when I can't verify that they're not doing anything shady on my machine?

The opening line of this post is amusing. They ought to give thought to fixing their core product first.

Re: We ditched Google Analytics

#173
post #75

Earlier quoted context omitted.

It's definitely possible to offer that on a monthly basis if you model that each customer stays for 36-39 months. Also, I doubt that they are using replicated storage, but are using erasure coding instead. Also, they dedupe before upload, so more cost savings there.

Spideroak doesn't and cannot dedupe, since everything you upload is encrypted by a key held only by you.

Spideroak can and does dedupe client side before uploading. It can't dedupe across multiple clients, but it does dedupe within the client. It also tracks syncs so that data synced between multiple client machines only has to be stored once (with appropriate redundancy).

Re: We ditched Google Analytics

#174
post #33

Earlier quoted context omitted.

Aren't there self-hosted analytics anyway? Piwik[1] comes to mind first, but I'm sure there are many. 1. https://piwik.org/

Unsurprisingly, Wikipedia has a list: https://en.wikipedia.org/wiki/List_of_web_analytics_software

Strangely Microsoft's one is missing: Application Insights.

Pretty much works like Google Analytics but utilises both client JavaScript and embedded runtime code to generate a richer picture of what is going on.

Too bad the interface on the Azure Portal is terrible. They spent too much time making it look fancy, and not enough time getting the 101s of usability right (which is a criticism I'd lay at the feed of the new Azure portal in general).

Re: We ditched Google Analytics

#175
post #88

Earlier quoted context omitted.

There's a $555 bounty if you can demonstrate a security vulnerability in Piwik because of that.

I'm not interesting in further dehumanizing myself with participation in a bug bounty program. I'll write an exploit for it (the general case, not just Piwik in particular) and drop it on OSS Sec some day, but here's a theoretical attack: 1. Guess a username somehow. Maybe "admin"? Whatever, we're interested in the security of the hash function. Let's assume we have the username for our target. 2. Calculate a bunch o…

How to protect from timing attacks - It's All About Time: http://blog.ircmaxell.com/2014/11/its-all-about-time.html

Re: We ditched Google Analytics

#176
post #43

Not strictly on topic so I apologise if this is unwanted but I thought I'd share my experience with SpiderOak in case anyone here was thinking of purchasing one of their plans. In February SpiderOak dropped its pricing to $12/month for 1TB of data. Having several hundred gigabytes of photos to backup I took advantage and bought a year long subscription ($129). I had access to a symmetric gigabit fibre connection so I…

This comment is ridiculous, and so is the fact that it's at the top. This is supposed to be about Google Analytics, come on.

Re: We ditched Google Analytics

#177

Earlier quoted context omitted.

Unsurprisingly, Wikipedia has a list: https://en.wikipedia.org/wiki/List_of_web_analytics_software

Who makes these lists?!

Well you can see the list of users here:

https://en.wikipedia.org/w/index.php?title=List_of_web_analy...

Re: We ditched Google Analytics

#178
post #42

It took us only a few weeks to write our home-brew analytics package. Nothing super fancy yet now we have an internal dashboard that shows the entire company much of what we used analytics for anyway - and with some nice integration with some of our other systems too. I never quite grasp how the above isn't just a matter of intuition to anyone working in the tech sector. Google Analytics thrives on developers' lazine…

I don't think it's a matter of laziness. More so where is it best to spend your expensive/valuable developer resources, on the product or some home-baked analytic's framework? I applaud SpiderOak, but they are much different from most other sites. They have privacy conscious customers to begin with, this is something that is good press for them and probably a net positive on their bottom line for doing it, not the ca…

Agreed - for some cases just pasting the GA snippet onto a site is sufficient. For others you should add events and such. For others you must roll your own.

Re: We ditched Google Analytics

#179
post #175

Earlier quoted context omitted.

I'm not interesting in further dehumanizing myself with participation in a bug bounty program. I'll write an exploit for it (the general case, not just Piwik in particular) and drop it on OSS Sec some day, but here's a theoretical attack: 1. Guess a username somehow. Maybe "admin"? Whatever, we're interested in the security of the hash function. Let's assume we have the username for our target. 2. Calculate a bunch o…

How to protect from timing attacks - It's All About Time: http://blog.ircmaxell.com/2014/11/its-all-about-time.html

password_verify() compares hashes in constant-time, so, yeah...

Re: We ditched Google Analytics

#180
post #43

Not strictly on topic so I apologise if this is unwanted but I thought I'd share my experience with SpiderOak in case anyone here was thinking of purchasing one of their plans. In February SpiderOak dropped its pricing to $12/month for 1TB of data. Having several hundred gigabytes of photos to backup I took advantage and bought a year long subscription ($129). I had access to a symmetric gigabit fibre connection so I…

That doesn't sound good. On the other hand, I use SpiderOak with not a lot of cloud storage use, with clients on OS X, Linux, and until this morning Windows 10. The only problem I ever had was more or less my fault - trying to register a new laptop with a previously named setup.

BTW, why store photos and videos on encrypted storage? For that I use Office 365's OneDrive: everyone in my family gets a terabyte for $99/year and I really like the web versions of Office 365 because when I am on Linux and someone sends me an EXCEL or WORD file, no problem, and I don't use up local disk space (with SSD drives, something to consider).

Post reply on HN