Live data from Hacker News

How I recorded user behaviour on my competitor’s websites

dejanseo.com.au

91–100 of 329 posts

Re: How I recorded user behaviour on my competitor’s websites

#91
post #22
post #18

Honestly, it doesn't shock me in the slightest that someone who markets themselves as an SEO expert would not only do something as unethical as this, but also brag about it, as though they think they've done something they should be proud of.

Is this that different than publicizing bugs? He tested it for a small amount of time, noticed a real security vulnerability (he could collect leads), and publicized his findings knowing Google would likely punish him for it. It's mildly unethical at worse, considering he could have happily done profitable leadgen at scale and it would have likely never been caught if he kept quiet.

"Years"

"Small amount of time"

?!?

Re: How I recorded user behaviour on my competitor’s websites

#92
post #60

Earlier quoted context omitted.

I wish... even GitHub won't work properly without JavaScript enabled these days.

Completely disabling Javascript isn't feasible, but you can use uMatrix or NoScript with all scripts blocked by default, and only whitelist ones on sites/domains that you trust.

Exactly. I've been browsing script-free for twenty years. It used to be a real pain switching on and off, until Opera introduced easy by-site settings. But then, back in the day most sites were perfectly servicable without any scripting whatsoever. And these days, uMatrix makes it all a snap.

Re: How I recorded user behaviour on my competitor’s websites

#93
post #65

Earlier quoted context omitted.

Yay, you misled users and stole content! Seems like you are actually proud of this. I gather you realize this and did this in the best “white hat” spirit, although that’s not really what I get from your blog.

Where did I say I'm proud of this? Everyone keeps saying "proud". I chose to share it in public because it's a serious problem that others may be using it to do real harm. I blog about many things, most harmless and often very useful. I remember one other time when I exposed something broken in Google. I got penalised as a reward.

Lets sum it up - you revealed a bug, and eventually reported it. Good. Showed some technical tricks and creative approach. Thank you.

Bad - amoral and most likely illegal theft of copyrighted content. "Just for fun" ain't gonna cut it. You hurt real businesses, probably because you don't give a f*ck about them, fun is more important.

Is it hard to see that this would stir some controversy to say at least?

Btw calling this "random cool idea" seems like you are proud of this and want some appreciation, hence sharing. If you would be concerned about security, you would share this bug immediately, which is definitely what you didn't do according to your own words.

Things can look significantly different from the other side. You know, the side of the rest of the world.

Re: How I recorded user behaviour on my competitor’s websites

#94
post #65

Earlier quoted context omitted.

Yay, you misled users and stole content! Seems like you are actually proud of this. I gather you realize this and did this in the best “white hat” spirit, although that’s not really what I get from your blog.

Where did I say I'm proud of this? Everyone keeps saying "proud". I chose to share it in public because it's a serious problem that others may be using it to do real harm. I blog about many things, most harmless and often very useful. I remember one other time when I exposed something broken in Google. I got penalised as a reward.

I think in this situation it would be best to admit that it was improper behavior. You can agree that you should have either

- used your own site

- or someone that explicitly agreed to run this experiment.

Then you can go on that you regret your wrong approach in this case, you will do better next time and finally point out that very little damage was done, which you regret nonetheless.

Then we all move on,

- agree that it is an interesting hack

- and the web browser is a terrible platform security wise.

Re: How I recorded user behaviour on my competitor’s websites

#95
post #58

Earlier quoted context omitted.

Copying someone elses site and tricking their users to use your copy is a copyright violation and fraud. Nothing cool about it.

Your statement is far too broad and lacks context. Where is this a violation and where is it considered fraud? There must be some countries where this isn't the case or at least where the article and non-commercial use of the technique are considered to be mitigating circumstances. Also, who doesn't find it cool? You don't seem to be saying that what is described in the article isn't cool, you seem to be making a bro…

Just to be clear: you do not endorse copyright infringement for the sake of being cool, do you?

Re: How I recorded user behaviour on my competitor’s websites

#96
post #83
post #31

A couple of years back I was talking to someone who did SEO for a popular education network. The company was spending millions of dollars every month on SEO and advertising. Their module operandi went like this: 1. Offer money to license or buy a smaller competitor's content 2. If that doesn't work, crawl and clone the site 3. Pump a lot of money into Google Ads, so that the cloned site now appears as an ad above the…

Sorry, calling BS on this one. By simply copying a site you get flagged as having duplicate content. Then there's DMCA. I've seen an e-commerce site's homepage get de-indexed, killing the business, due to 1 single image being used for which the site owner didn't have copyright. SEO undoubtedly has many shady practises, but "professional SEO" is actually really difficult and involves much more than cloning competitor…

1. You don't do this (plagiarism) on your main site.

2. DMCA is a US law. It may or may not apply, depending on the company I referred to. Also, going to court depends on a lot of factors.

3. You don't necessarily need to clone verbatim. You could generate content automatically (or with manual help) targeting the same keywords, but based on parsed content.

4. This is not trying to be in organic search results. Promoted solely via ads.

Sorry, my experience has been that a SEO and content generation (as it happens today in Google and FB) ranks high among shady and manipulative practices. Add: Of course, there are many good companies too.

Re: How I recorded user behaviour on my competitor’s websites

#97
post #83
post #31

A couple of years back I was talking to someone who did SEO for a popular education network. The company was spending millions of dollars every month on SEO and advertising. Their module operandi went like this: 1. Offer money to license or buy a smaller competitor's content 2. If that doesn't work, crawl and clone the site 3. Pump a lot of money into Google Ads, so that the cloned site now appears as an ad above the…

Sorry, calling BS on this one. By simply copying a site you get flagged as having duplicate content. Then there's DMCA. I've seen an e-commerce site's homepage get de-indexed, killing the business, due to 1 single image being used for which the site owner didn't have copyright. SEO undoubtedly has many shady practises, but "professional SEO" is actually really difficult and involves much more than cloning competitor…

"duplicate content" is a problem for both, the original site and the copycat. But the copycat doesn't rely on SEO in this example. It just buys traffic in AdWords. So the duplicate content penalty would harm only the original site.

Re: How I recorded user behaviour on my competitor’s websites

#98
This is really a good example why it is so difficult for security experts to do research and experiments where real users are involved.

What Mr. Petrovic did is illegal in most developed countries: copyright violation (copying web pages) and monitoring and storing user behavior without their consent (and, even worse, by phishing). It doesn't matter that he did it for a "very brief period of time (for ethical reasons)". LOL. If I tried this kind of stuff where I work, I would have a long unpleasant talk with our legal/ethics department afterwards. I cannot even do a network scan in the Internet without first notifying God and a couple of lesser gods.

I am also wondering whether that's good publicity for the author's company. The author is basically saying: "We are doing things without being fully aware (or without caring) of the legal consequences. Are you sure you want to be our customer?".

Re: How I recorded user behaviour on my competitor’s websites

#99
post #58

Hi everyone! I did this. It was just a random cool idea I wanted to try. It worked a little too well and I quickly moved it to a disposable site to test if the page will get penalised by Google. I got busy with other things and forgot about it. When I bumped into it again I decided to write about it, for two reasons: 1) To me it's hard to believe that Chrome would allow for this to happen in the first place and 2) th…

Copying someone elses site and tricking their users to use your copy is a copyright violation and fraud. Nothing cool about it.

It's also a big trademark violation, right?

Re: How I recorded user behaviour on my competitor’s websites

#100
post #82

This is an interesting yet disturbing case of blackhat SEO and phishing, where the site owner hijacks the back button and sends visitors to fake sites where he can observe their behaviour. FTA: Here’s what I did: 1. User lands on my page (referrer: google) 2. When they hit “back” button in Chrome, JS sends them to my copy of SERP 3. Click on any competitor takes them to my mirror of competitor’s site (noindex) 4. Now…

> noindex So, the browser extension indicating (with big red fonts) that this site is noindex could be a simplest solution? For not power users who don't know about any extensions that would be not so easy though. If that function will appear in Chrome enabled by default, that would raise questions about Google motives, obviously.

I think noindex is nice to have but not neccessary for this trick.

The only solution is to fix the back-button bug/vulnerability in Chrome.

Post reply on HN