Live data from Hacker News

How I recorded user behaviour on my competitor’s websites

dejanseo.com.au

211–220 of 329 posts

Re: How I recorded user behaviour on my competitor’s websites

#211

Earlier quoted context omitted.

When you do security work, that's an important part of your job. Sure, in many scenarios like traditional pentesting you can probably do fine within the legal boundaries in most jurisdictions, but as soon as you do serious security research when you actually test your ideas in practice, you're likely to cross the line sooner or later. It's a difference between "it should probably work" and "yes, it worked, I tried it…

> you're likely to cross the line sooner or later. That's basically the opposite of what security researchers working for companies and research institutes are doing. Document everything, get written consent of involved parties and sometimes even inform the police about a planned action. Make sure that you (a) don't cross the line or (b) move the line legally further away. Of course, there are security experts who do…

> But they usually don't publish their results on a website with their real name.

I can name a few who do, but I personally despise them after previous interactions with them and thus don’t want to inflate their ego with a mention.

Re: How I recorded user behaviour on my competitor’s websites

#212
post #115

Earlier quoted context omitted.

The vast majority of regular users I've seen go back and forth between search and search results. Heck, I do it from time to time. Most users are extremely "inefficient" by geek standards.

> Most users are extremely "inefficient" by geek standards. How is that inefficient? I use both interchangeably and I don't see how it's any less efficient than opening a new tab and then having to close it if it's not what you want, or having to close useless tabs if the first one is all you need... On my Macbook, I just swipe right and I'm back at the search results.

You assume you're back at the search results. As OP proved that's not necessarily the case.

Re: How I recorded user behaviour on my competitor’s websites

#213
post #149

Earlier quoted context omitted.

Howdy, former Matasano pentester here. FWIW, I would probably have done something similar to them before I'd worked in the security industry. It's an easy mistake to make, because it's one you make by default: intellectual curiosity doesn't absolve you from legal judgement, and people on the internet tend to flip out if you do something illegal and say anything but "You're right, I was mistaken. I've learned my lesso…

> But again, don't worry too much. I would have made similar errors without formal training. Do you have any idea how patronizing your tone is?

Nope!

(I meant formal security training, FWIW. Also I know that feeling of "Oh boy, I just pissed off the internet, didn't I?" and wanted to remind him it'll blow over soon. It's not a huge deal, and he'll come out of it with +reputation.)

Re: How I recorded user behaviour on my competitor’s websites

#214
post #10

It seems my habbit to open google links in new tabs with right click have more meaning now. I initialy used this to avoid referal information.

Google even has a settings options where all SERP links open in a new tab. I personally use it myself.

Re: How I recorded user behaviour on my competitor’s websites

#215
post #149

Earlier quoted context omitted.

It's sad that everyone is being so harsh to you just because you decided to post about a vulnerability that who knows thousands of other people are quietly exploiting for their own benefit. If anything I am happy that instead of trying to misuse it or keeping it a secret you made it public knowledge so that there can be something done about it. Yes you could have handled it more appropriately and you probably will in…

Howdy, former Matasano pentester here. FWIW, I would probably have done something similar to them before I'd worked in the security industry. It's an easy mistake to make, because it's one you make by default: intellectual curiosity doesn't absolve you from legal judgement, and people on the internet tend to flip out if you do something illegal and say anything but "You're right, I was mistaken. I've learned my lesso…

For those of us who aren't familiar with the story, the RTM exploding the internet reference is this:

https://en.wikipedia.org/wiki/Morris_worm

Re: How I recorded user behaviour on my competitor’s websites

#216

Hi everyone! I did this. It was just a random cool idea I wanted to try. It worked a little too well and I quickly moved it to a disposable site to test if the page will get penalised by Google. I got busy with other things and forgot about it. When I bumped into it again I decided to write about it, for two reasons: 1) To me it's hard to believe that Chrome would allow for this to happen in the first place and 2) th…

I don’t think anyone is objecting to what you did as much as how you did it, and how you seem to be proud of flagrantly abusing your ability to duplicate other people‘s intellectual property. I’m hardly a champion of copyright laws or IP in general, but running duplicates of someone ese’s site feels completely wrong to me without thinking twice. Like the suggestion from the pen tester here, which you posted on your blog, this would be a lot different if you had written the article about conduct that seemed professional, respectful and legal.

Re: How I recorded user behaviour on my competitor’s websites

#217
post #132

Earlier quoted context omitted.

That's a reasonable course of action until you need to use the internet for pretty much anything .

Experience teaches that that is a vastly exaggerated statement. There remains quite a lot of the World Wide Web that does not require Javascript. And of course it is pretty much not required at all for using the Internet outwith the World Wide Web.

And then classic React enters the building

Re: How I recorded user behaviour on my competitor’s websites

#218
post #188

Earlier quoted context omitted.

>‘That isn’t enough. The padlock on the https page gives users a false sense of security.’ >‘We don’t agree with that. Where’s your data?’ Where is your source that this is Google's position? Considering they have some of the best security employees in the business, I find that hard to believe.

Allowing sites to intercept browser actions that should make a user leave the site, and inject other operations is obviously and plainly a security issue. I reported this to google several years ago, and it was never addressed.

Can't you do the same thing without JavaScript, by having the web page go through a brief redirect so the back button takes you to the redirect?

And if so, how do you solve this? Ban server-side redirects? Make the Google SERP iframe all sites it takes you to? I agree this is a problem but I have no idea how to solve it in a way that's not worse.

Re: How I recorded user behaviour on my competitor’s websites

#219

I’d like to defend this guy. What he is doing is testing the trust mechanism. If he went to Google and said ‘I think the trust mechanism is broken’ Google would say: ‘We know, that’s why we are pushing to move everyone to https.’ ‘That isn’t enough. The padlock on the https page gives users a false sense of security.’ ‘We don’t agree with that. Where’s your data?’ Google wouldn’t have accepted this. They have pushed…

Thank you. I'm not having a good time at the moment. Anyway, the basis of my test hypothesis is that people are easily fooled by URL both by HTTPS and brand recognition (e.g. subdomain) so I conducted a survey which revealed the very real problem: https://dejanseo.com.au/trust/ Raw data: https://dejanseo.com.au/wp-content/uploads/2017/04/survey-te...

Don't listen to the haters here. The same people upvoted this article 3 days ago, and then promptly forgot about it https://news.ycombinator.com/item?id=17799083

Re: How I recorded user behaviour on my competitor’s websites

#220

I’d like to defend this guy. What he is doing is testing the trust mechanism. If he went to Google and said ‘I think the trust mechanism is broken’ Google would say: ‘We know, that’s why we are pushing to move everyone to https.’ ‘That isn’t enough. The padlock on the https page gives users a false sense of security.’ ‘We don’t agree with that. Where’s your data?’ Google wouldn’t have accepted this. They have pushed…

FWIW, "the padlock is enough" is quite the opposite of Google's position:

https://blog.chromium.org/2018/05/evolving-chromes-security-...

and in fact one of the main reasons is that use of HTTPS is far too little information for the browser to affirmatively indicate "This site is secure and trustworthy." So they are planning to get rid of the padlock. (Use of HTTP is enough for the browser to affirmatively say it's insecure, though.)

So I think Google understands that one of the consequences of pervasive HTTPS is that the padlock is at best meaningless and at worst misleading, as we saw here.

Post reply on HN