Live data from Hacker News

How I recorded user behaviour on my competitor’s websites

dejanseo.com.au

181–190 of 329 posts

Re: How I recorded user behaviour on my competitor’s websites

#181
post #149

Earlier quoted context omitted.

It's sad that everyone is being so harsh to you just because you decided to post about a vulnerability that who knows thousands of other people are quietly exploiting for their own benefit. If anything I am happy that instead of trying to misuse it or keeping it a secret you made it public knowledge so that there can be something done about it. Yes you could have handled it more appropriately and you probably will in…

Howdy, former Matasano pentester here. FWIW, I would probably have done something similar to them before I'd worked in the security industry. It's an easy mistake to make, because it's one you make by default: intellectual curiosity doesn't absolve you from legal judgement, and people on the internet tend to flip out if you do something illegal and say anything but "You're right, I was mistaken. I've learned my lesso…

Thank you, I did mess up and wish I could take it back. To everyone bashing on me, I'm truly sorry to offend so many people. That was not the intention. This was purely as you describe it, intellectual curiosity.

I really appreciate your comment and hope it's OK that I added it here: https://dejanseo.com.au/competitor-hack/#shawn

Re: How I recorded user behaviour on my competitor’s websites

#182

I’d like to defend this guy. What he is doing is testing the trust mechanism. If he went to Google and said ‘I think the trust mechanism is broken’ Google would say: ‘We know, that’s why we are pushing to move everyone to https.’ ‘That isn’t enough. The padlock on the https page gives users a false sense of security.’ ‘We don’t agree with that. Where’s your data?’ Google wouldn’t have accepted this. They have pushed…

Thank you. I'm not having a good time at the moment. Anyway, the basis of my test hypothesis is that people are easily fooled by URL both by HTTPS and brand recognition (e.g. subdomain) so I conducted a survey which revealed the very real problem: https://dejanseo.com.au/trust/

Raw data: https://dejanseo.com.au/wp-content/uploads/2017/04/survey-te...

Re: How I recorded user behaviour on my competitor’s websites

#183

For context: Firefox greys out anything that is not the "real" domain, which remains black. So: google.com.fakesite.io/foobar becomes: (grey "google.com.")(black "fakesite.com")(grey "/foobar") This makes it at least a little more obvious you're not on Google. Although that's still a tricky one for non technical users to protect against. Aside from EV, I can't immediately think of anything else a browser could system…

> Domain names being little endian has been one of the most expensive web sec mistakes in history.

Can you clarify what you mean by this?

Re: How I recorded user behaviour on my competitor’s websites

#184
post #94

Earlier quoted context omitted.

Where did I say I'm proud of this? Everyone keeps saying "proud". I chose to share it in public because it's a serious problem that others may be using it to do real harm. I blog about many things, most harmless and often very useful. I remember one other time when I exposed something broken in Google. I got penalised as a reward.

I think in this situation it would be best to admit that it was improper behavior. You can agree that you should have either - used your own site - or someone that explicitly agreed to run this experiment. Then you can go on that you regret your wrong approach in this case, you will do better next time and finally point out that very little damage was done, which you regret nonetheless. Then we all move on, - agree t…

Why? Why are you siding with the big corporations?

Re: How I recorded user behaviour on my competitor’s websites

#185

I’d like to defend this guy. What he is doing is testing the trust mechanism. If he went to Google and said ‘I think the trust mechanism is broken’ Google would say: ‘We know, that’s why we are pushing to move everyone to https.’ ‘That isn’t enough. The padlock on the https page gives users a false sense of security.’ ‘We don’t agree with that. Where’s your data?’ Google wouldn’t have accepted this. They have pushed…

>‘That isn’t enough. The padlock on the https page gives users a false sense of security.’

>‘We don’t agree with that. Where’s your data?’

Where is your source that this is Google's position? Considering they have some of the best security employees in the business, I find that hard to believe.

Re: How I recorded user behaviour on my competitor’s websites

#186

Earlier quoted context omitted.

The Internet works just fine without JavaScript: DNS, FTP, SSH, SMTP, NNTP — none of them have ever required JavaScript. Indeed, HTTP works just fine without JavaScript. HTTP pages perform better without it. Granted, many broken and ill-programmed HTTP pages aren't useful without JavaScript. That's no an indication of how useful it is, but rather an indication of how poorly-skilled those webmasters are. Then there ar…

Your distinction between web pages and web apps is entirely arbitrary. Many web pages use JS in such a way that interacting with them without JS is a lesser, if not broken, experience.

Example: Is reddit a webpage or a web app? Correct - it's both.

Re: How I recorded user behaviour on my competitor’s websites

#187

Earlier quoted context omitted.

He copied Google's SERP page, AND copied all of his competitors websites. That's definitely copyright infringement, you'd be livid if you were a competitor, and as a user you'd be pretty annoyed. It's still an interesting hack, so good to see it being talked about. But it is not ethical and definitely illegal in almost any jurisdiction.

Copyright infringement is a civil case in almost any jurisdiction, not a criminal case. The USA is a notable exception, perhaps due to the vested interests with deep pockets.

A civil case you would lose though.

Re: How I recorded user behaviour on my competitor’s websites

#188

I’d like to defend this guy. What he is doing is testing the trust mechanism. If he went to Google and said ‘I think the trust mechanism is broken’ Google would say: ‘We know, that’s why we are pushing to move everyone to https.’ ‘That isn’t enough. The padlock on the https page gives users a false sense of security.’ ‘We don’t agree with that. Where’s your data?’ Google wouldn’t have accepted this. They have pushed…

>‘That isn’t enough. The padlock on the https page gives users a false sense of security.’ >‘We don’t agree with that. Where’s your data?’ Where is your source that this is Google's position? Considering they have some of the best security employees in the business, I find that hard to believe.

Allowing sites to intercept browser actions that should make a user leave the site, and inject other operations is obviously and plainly a security issue.

I reported this to google several years ago, and it was never addressed.

Re: How I recorded user behaviour on my competitor’s websites

#190

I’d like to defend this guy. What he is doing is testing the trust mechanism. If he went to Google and said ‘I think the trust mechanism is broken’ Google would say: ‘We know, that’s why we are pushing to move everyone to https.’ ‘That isn’t enough. The padlock on the https page gives users a false sense of security.’ ‘We don’t agree with that. Where’s your data?’ Google wouldn’t have accepted this. They have pushed…

Raising awareness is what he want, being called a jerk is the price he has to pay. Defend +1.
Post reply on HN