Live data from Hacker News

No boundaries: Exfiltration of personal data by session-replay scripts

freedom-to-tinker.com

31–40 of 57 posts

Re: No boundaries: Exfiltration of personal data by session-replay scripts

#31

+1 for highlighting the privacy concerns, but -1 for blaming the software for not having strong enough defaults. As someone who has integrated FullStory into a production site, I spent several days doing a careful audit of our forms and redacting fields from being tracked. FullStory has an excellent, universal account setting to automatically redact fields based on any CSS selector, so it's very, very easy to tell it…

It's still a broken process. Are you going to re-audit every future change to your web site? I doubt it.

The default, as the article suggests, should be to redact all fields, then let the company opt-in the fields that they really mean to record.

Re: No boundaries: Exfiltration of personal data by session-replay scripts

#32

Earlier quoted context omitted.

Several parts of your comment resonate with me: >> There has to be a way for website creators to sandbox content which comes from third parties. The whole 3rd party thing came about because advertisers needed to establish both ad-distribution and trust (they rightly don't want to pay for ads unless they're actually shown etc...). >> It's problematic that including content from elsewhere in your page (like in an ifram…

I guess what I find frustrating is that it's the same class of problem as Captain Crunch's whistle, in-band control. But, I think we're getting to the point where it has to be sandboxes all the way down (running things in sandboxes, inside of VMs, with memory protection, etc). But it's still not enough. This class of problem must be extremely difficult to solve. How do you run Turing-complete code which might be host…

> How do you run Turing-complete code which might be hostile?

That's the key problem that (almost) nobody wants to talk about. We've been trying to solve the decision problem for a long time, and we already know that even relatively simple problems are provably undecidable[1]. Any real program will be much more complex[2]. An unknown program could generate any output it wants and we cannot know that without running it.

The only solution is to remove output methods. If a program can only e.g. draw to a framebuffer without the ability to trigger future network activity, the worst it can do is waste CPU & RAM. Allowing literally any interface to generate network activity (even indirectly) and people will find ways to tunnel data over that interface.

The original design for the web was (probably) safe. It didn't require anonymous Turing complete code, and provided quite a bit of functionality with declarative markup. It even allowed simple (but still useful) server-side applications with 3270-style forms (again, no code needed). This was wonderfully useful, reasonably safe, and most importantly it was understandable by both humans and machines.

Today's web requires trusting a new set of undecidable software on each page load. We're supposed to trust 3rd parties even though trust is not transitive. We're supposed to accept the risk of running 3rd party software even though risk is transitive. Without some sort of miraculous total reversal where browsers revert back to pre-javascript days, this is going to end badly.

[1] https://www.scottaaronson.com/blog/?p=2725

[2] If your program uses >7918 Turing machine states, [1] proves that it's behavior cannot be analyzed by ZF set theory.

Re: No boundaries: Exfiltration of personal data by session-replay scripts

#33
post #4

Is there a browser extension that warns you about the various tracker scripts a website is utilizing?

I use Disconnect in both Chrome and Firefox: https://disconnect.me/

It blocks scripts for analytics, social sharing, etc. and gives a simple UI for reenabling any (in those situations when someone wrote their JavaScript such that button presses fail if Google Analytics is not loaded -- which is not nice).

Re: No boundaries: Exfiltration of personal data by session-replay scripts

#34

Does anyone know if ublock origin blocks this kind of stuff? Yet another reason to never disable it. I'm starting to realize it's a lot more than an ad blocker, but more like a firewall to protect the client against malicious sites with crypto miners, trackers and this stuff...

Hi, one of the authors here. We discuss this in the last section of the post. uBlock Origin uses lists to determine which requests to block. We tested the two largest, EasyList and EasyPrivacy, and both fail to block scripts from FullStory, Smartlook, and UserReplay.

[deleted]

Re: No boundaries: Exfiltration of personal data by session-replay scripts

#35
post #12

Earlier quoted context omitted.

It's not "the browsers" it's primarly the culture of including "whatever" on the pages one maintains. It's so easy as it typically doesn't affect negatively those who decide to do so. And it's typically not a decision of one person.

I was giving this matter some thought early today after getting some stupid malware popup on my phone (where the phone vibrates, says it has lots of viruses, etc) while using Chrome. It wasn't even on any kind of dodgy site, but most likely it was part of a banner rotation for an ad network. There has to be a way for website creators to sandbox content which comes from third parties. I think we have to accept that al…

There's some limited ways to sandbox with iframes.

https://www.w3schools.com/tags/att_iframe_sandbox.asp

Re: No boundaries: Exfiltration of personal data by session-replay scripts

#36
post #6

DAMMIT. Once again the question that immediately come to mind is "Why the FUCK do browsers facilitate this shit?" C'mon you stupid web devs on HN tell me again all your excuses to need these capabilities. Sorry to generalize to all those of you who don't do this, but many of you still want those capabilities that have opened the door. And those browser devs... It's like they compete to sell out the users by adding "f…

> but many of you still want those capabilities that have opened the door Rest assured the majority of (web) developers does not like this crap a bit. Most of the pressure to add hundreds of analytics toolkits, trackers or these snoopers come from marketing - they (or worse, the C-level execs) get convinced that they need to integrate tool XYZ to "stay competitive" or "improve their customer retention" or whatever bu…

All this started with the first ad scripts and invisible pixels.

It got really crazy with google analytics and then all social beacons. Now the only limit are the CPU and RAM available to the browser.

Re: No boundaries: Exfiltration of personal data by session-replay scripts

#37
To be fair, FullStory spends a lot of time in their onboarding, UI and docs encouraging you to check and double check that anything sensitive is excluded. They broadcast this message so clearly that it's obvious that they take privacy seriously (or, about as seriously as any over-the-shoulder-peeking service could), and they strongly encourage their users to adopt the same stance.

This article makes it seem like their defaults are the only exclusion settings possible, which is very far from the truth.

I feel like FullStory is being blamed for trying to provide some minimal default exclusion settings at all. I assume the same holds for competing services.

I'm not saying that this means the core premise of this is wrong: there's many things to dislike about session recording services. But the article goes on and on about a few defaults, instead of focusing on the dangers of the core concept and loses the argument that way IMO.

Re: No boundaries: Exfiltration of personal data by session-replay scripts

#38
post #36

Earlier quoted context omitted.

> but many of you still want those capabilities that have opened the door Rest assured the majority of (web) developers does not like this crap a bit. Most of the pressure to add hundreds of analytics toolkits, trackers or these snoopers come from marketing - they (or worse, the C-level execs) get convinced that they need to integrate tool XYZ to "stay competitive" or "improve their customer retention" or whatever bu…

All this started with the first ad scripts and invisible pixels. It got really crazy with google analytics and then all social beacons. Now the only limit are the CPU and RAM available to the browser.

> Now the only limit are the CPU and RAM available to the browser.

... and in Germany, the data cap if you're on mobile. Video ads with autoplay, tons of trackers, no wonder I regularly hit 3GB a month, which is actually the biggest package my provider offers.

Re: No boundaries: Exfiltration of personal data by session-replay scripts

#39
post #6

DAMMIT. Once again the question that immediately come to mind is "Why the FUCK do browsers facilitate this shit?" C'mon you stupid web devs on HN tell me again all your excuses to need these capabilities. Sorry to generalize to all those of you who don't do this, but many of you still want those capabilities that have opened the door. And those browser devs... It's like they compete to sell out the users by adding "f…

I'm a Single-Page-App developer that runs noscript and selectively enables javascript.

We know. No one listens to us though.

Post reply on HN