Live data from Hacker News

How I recorded user behaviour on my competitor’s websites

dejanseo.com.au

311–320 of 329 posts

Re: How I recorded user behaviour on my competitor’s websites

#311
post #309

If Chrome outright disables JavaScript's ability to alter the "Back" path, it may brake some (poorly designed) applications. A compromise is to prompt with a warning.

Break them then, with no warning. Letting Javascript trump browser controls (or spam confirmation popups) is a problem that never should have been allowed to live beyond the 90s.

Re: How I recorded user behaviour on my competitor’s websites

#313
post #306

Earlier quoted context omitted.

I don't understand. Are you suggesting that if you arrive at a site from Google, the history API should just not work? For example, let's say a user arrives at a single-page application from Google, and clicks a link on that page to get more information. The site adds a history entry with pushState, but doesn't reload the entire page. Are you saying that in this case, when the user clicks back they should get sent ba…

Hmm touche, this wouldn’t fix much

No; you were right. The browser needs some AI to be smarter but this is all still possible.

Re: How I recorded user behaviour on my competitor’s websites

#314

Hi everyone! I did this. It was just a random cool idea I wanted to try. It worked a little too well and I quickly moved it to a disposable site to test if the page will get penalised by Google. I got busy with other things and forgot about it. When I bumped into it again I decided to write about it, for two reasons: 1) To me it's hard to believe that Chrome would allow for this to happen in the first place and 2) th…

I don’t think anyone is objecting to what you did as much as how you did it, and how you seem to be proud of flagrantly abusing your ability to duplicate other people‘s intellectual property. I’m hardly a champion of copyright laws or IP in general, but running duplicates of someone ese’s site feels completely wrong to me without thinking twice. Like the suggestion from the pen tester here, which you posted on your b…

How is it different from archive.org snapshots from an IP perspective?

Re: How I recorded user behaviour on my competitor’s websites

#315
post #131

What's concerning is that the post author seems not to see the problem with trying to sit on both sides of the fence at once. As others have said, the way this was done is likely to be against numerous laws in most major jurisdictions. If you wish to do this as a PoC then simply put a notice up on the page that initiates it and use dummy "competitor" content, so you've got some semblance of user content/transparency…

The problem I'm seeing is not that the author did something un-ethical (there are plenty black hats out there with no such concerns), but that the content can modify the browser chrome behaviors, and that the users trust the browser chrome a lot more than the content (as it should). As a workaround, I recommend using separate Firefox containers for big sites, as the big sites are the main attack surface of a lot of p…

I don’t think your proposed workaround would help. The user stays on the malicious domain. Unless your container is clearly marked visually, only the url shows the savvy user that something is off.

Re: How I recorded user behaviour on my competitor’s websites

#316

Earlier quoted context omitted.

Your statement is far too broad and lacks context. Where is this a violation and where is it considered fraud? There must be some countries where this isn't the case or at least where the article and non-commercial use of the technique are considered to be mitigating circumstances. Also, who doesn't find it cool? You don't seem to be saying that what is described in the article isn't cool, you seem to be making a bro…

Just to be clear: you do not endorse copyright infringement for the sake of being cool, do you?

I believe much of modern copyright law in Europe but especially the US is broken, but in general I don't find crime cool, nor do I find 'cool' a justification in itself to do certain things. Not all laws are sacred though.

I was merely reacting to broad nature of the claims in parent comment. There is a world beyond the US and Europe, laws are not universal truths, they are a representation of what we have come to agree upon as rules to play by. In copyright law specifically though there is often a chasm between what the people find good rules and what companies find good rules. But that is a different discussion.

Re: How I recorded user behaviour on my competitor’s websites

#317

Earlier quoted context omitted.

I don’t think anyone is objecting to what you did as much as how you did it, and how you seem to be proud of flagrantly abusing your ability to duplicate other people‘s intellectual property. I’m hardly a champion of copyright laws or IP in general, but running duplicates of someone ese’s site feels completely wrong to me without thinking twice. Like the suggestion from the pen tester here, which you posted on your b…

How is it different from archive.org snapshots from an IP perspective?

Great question. How about we invert that, and you tell me what IP laws justify operating a functioning duplicate of someone else’s entire website, full of copyrighted and trademarked content, for the benefit of your business?

By this logic, I could duplicate any website in the word and operate a copy for my private business. While I am not a lawyer it seems clear that this is not legal (and as if this is the first time the concept occurred to someone!)

I assume archive.org falls under Fair Use. Check these guidelines.

https://tinytake.com/screen-capture-copyright-violation-or-f...

Duplicating your competitors website for analysis to benefit your business fails the first condition. If it were academic research or some sort of public benefit, that’s different than for-profit republishing for your SEO business.

Re: How I recorded user behaviour on my competitor’s websites

#318

I’d like to defend this guy. What he is doing is testing the trust mechanism. If he went to Google and said ‘I think the trust mechanism is broken’ Google would say: ‘We know, that’s why we are pushing to move everyone to https.’ ‘That isn’t enough. The padlock on the https page gives users a false sense of security.’ ‘We don’t agree with that. Where’s your data?’ Google wouldn’t have accepted this. They have pushed…

Thank you. I'm not having a good time at the moment. Anyway, the basis of my test hypothesis is that people are easily fooled by URL both by HTTPS and brand recognition (e.g. subdomain) so I conducted a survey which revealed the very real problem: https://dejanseo.com.au/trust/ Raw data: https://dejanseo.com.au/wp-content/uploads/2017/04/survey-te...

We need experiments like this.

Clinical studies, try to address various factors beyond does the drug technically work, but does it work in practice (coping with people doing everyday things like having dementia, drinking or babies).

We have a flawed obsession with responsible disclosure (that we should mandate includes public disclosure). What we need is a framework for Software Studies that allows any nature of research including in at risk areas and they should answer to ethics committee and regulators, not a disclosure terms of service from the company likely to be put in a bad light.

We need an equivalent to ICH GxP. Drugs have to deal with all the same craziness as software, they're just centuries ahead at how to do it (although they still fail at public disclosure).

Was this study appropriate? Whilst Google corrupts the security integrity of the internet with its Ad and Analytics system, it shouldn't be complaining. For the rest of us, I think we need to pressure for regulation if you want to draw lines and look to the drug industry for inspiration. At the very least we need InfoSec Trials if not the whole suite of Software.

Re: How I recorded user behaviour on my competitor’s websites

#319

I don't understand why you would have been expected to report this to Google. It's not an issue or bug with Google, it's a simple gray hat social engineering trick. People linking to fake sites as a dark pattern is nothing novel, you just did so too capture analytics instead of, say, installing a virus or taking someone's credentials. That said, you certainly could have done the latter and gotten views into your comp…

The expectation isnt to report to Google. The expectation is to not do this on live sites affecting real people.

the reference is to text in the article, not comments from HN.

From the second paragraph:

> Many are suggesting the right way is to approach Google directly with security flaws like this instead of writing about it publicly.

Re: How I recorded user behaviour on my competitor’s websites

#320

Earlier quoted context omitted.

I'd argue the most interesting and important research is done in this way. It's not that these security experts "don't care", it's just the very nature of certain problems that you need to test them against real users (as opposed to, say, testing an exploit against a system). Consider, for example, honeypot research the very nature of such scenarios is that you can't even hint that users are tracked, let alone asking…

> I'd argue the most interesting and important research is done in this way Links please :)

I'm sorry, I don't think I can provide any links. As an example, imagine you found out about Stuxnet much earlier before the general public.
Post reply on HN