Live data from Hacker News

I too know the websites you visited

oxplot.github.com

31–40 of 98 posts

Re: I too know the websites you visited

#32

http://ajaxian.com/archives/spyjax-using-avisited-to-test-yo... come on...

as mentioned elsewhere in this thread, that loophole has been closed by all modern browsers. not to say there aren't other ways to get at that information, but it's not as simple as checking the color of a link anymore.

Re: I too know the websites you visited

#34

What would be a possible use of this attack? I can't think of anything useful you'd do with knowing that you've visited Facebook. And so many people use sites like Facebook you might get a better success rate just always returning "visited" rather than measuring this way!

If a malicious website can tell which banking websites you have visited, it can show a phishing page that looks just like your bank.

Re: I too know the websites you visited

#40
Throwaway account. My company created an analytics product around the ability to track which sites your visitors have visited. It used a different and (at the time) more reliable technique.

About a year after the product launch we were contacted by a powerful washington based lobby group and they wanted to chat. They felt it violated a site visitor's "reasonable expectation of privacy". I agreed. So we pulled the feature and dodged a bullet as this "browser bug" hit the mainstream press a few months later. The feature wasn't a major part of our product's value prop, few of our customers used it and none missed it.

So if you're thinking about basing a startup on this, don't. You will get a call very quickly from organizations much larger than you are asking awkward questions.

Post reply on HN