4 ms·
Not a technical person here. I just check my personal site with this tool and see that is possible know that I use Google G Suite. Is no way to opt out this?
by pablo-massa 9y ago
Not a technical person here.
I just check my personal site with this tool and see that is possible know that I use Google G Suite.
Is no way to opt out this? I'm more vulnerable to an attacker, right? They can try to login to my account on gmail.com.
I thought that for not using an email address like @gmail.com, etc. I had the advantage of hiding my login page XD
Maybe I'm a bit paranoid. Sometimes I have the idea that the Internet is not well designed from the ground up for privacy in mind. Recently I check the product Hotjar [0] and was amazed how creepy it is, you can see screen recordings of the users interacting with your site, where are they from, and more. I made a video about this [1]
(spanish). Why by default the Internet is like that?, all those features should be opt in imho, with user consent. What do you think?
Excuse me if my wording is not perfect, my english is not the best :)
[0] https://hotjar.com https://hotjar.com
[1] https://www.youtube.com/watch?v=FDgybTvnhjY https://www.youtube.com/watch?v=FDgybTvnhjY
- captn3m0 9y agohotjar keeps track of user actions, and replays the same. It doesn't record your screen.
- pablo-massa 9y agoThanks for clarify that, with "screen recordings of the users interacting with your site" I mean what you describe ("track of user actions, and replays the same"), is not the same technically but is equally immoral for me, and that is one of the default default features that the Internet has by design from the beginning that I'm questioning, today a regular internet user just download a popular browser and is affected by that without knowing.
- setr 9y ago>today a regular internet user just download a popular browser and is affected by that without knowing. Well, it's not technically a problem of the internet (the protocol of networked-communication between arbitrary machines), but specifically having a turing-complete language in the browser. The browser sandboxes the language to an extent (so you can't load a webpage and it goes and deletes all files on your computer), but it can't offer protection against any arbitrary program without being able to understand the goal of the program, and whether or not you as a user actually want that goal (or any of its sub-goals). The problem comes down to: Freedom to act well is also the freedom to act poorly. The browser can't delete all your files, but it also can't organize your files for you. It can track your mouse position across the screen for the sake of recording it... but it can also track your mouse position for the sake of a game. So it's really a question of how much do you actually want from the browser? Another alternative is to not give it a proper language at all, such that it can only do a predefined subset of behaviors (ie Web 2.0), and thus users are kept safe from any malicious behavior, but of course, at the cost of being kept from any "innovative" behaviors as well. Just fyi, you can enforce this rule if you'd like, by something like the noscript extension, to kill javascript everywhere (and optionally disable it for sites you trust). Half your webpages will break because developers assume javascript, and you can't play any games or fancy websites without opening yourself up to recording, but you'll be safe. So the choice is yours: Self-impose limitations, or accept the risk. Most people choose risk (by market-selection), though they may not have realized they ever made a choice, or understood it if they did.
- pablo-massa 9y agoThat open my eyes in so many ways. Thanks for a detailed explanation. I didn't have time to elaborate on my thoughts about that right now. Sorry for the late response, I hope this product had a notification feature and avoid have to be dependent on him accesing to check when someone responds to you.
- captn3m0 9y ago>Is no way to opt out this? I'm more vulnerable to an attacker, right Others can't send you a mail unless you publish those DNS records that say you use GSuite. Hiding your email host doesn't give you much in the way of security. If you're really concerned about security, see Google's Advanced Protection Program[0]. [0]: https://landing.google.com/advancedprotection/ https://landing.google.com/advancedprotection/
- pablo-massa 9y agoI understand. But I was thinking, a potential attacker receives an email from me (me@customdomain.com), with this tool, they can look up and see that I use G Suite and try to login on my account on gmail.com. Thanks for letting me know about Google Advanced Protection Program.
- lgats 9y agoWith any other custom domain, they can do the exact same thing only it's on a smaller web server perhaps running different software (which may or may not be up to google's particularly high security)
- mosselman 9y agoUsing a good password and two-factor authentication basically eliminates this issue. You are looking for what is called 'security through obscurity' which is never a solid defence plan over real, verified, security (like real encryption, proper passwords, multi-factor authentication, etc)
- pablo-massa 9y agoYou are right. Thanks for let me know about 'security through obscurity', I'm reading the Wikipedia article now [0]. Yes, I'm using two factor and strong passwords (and encouraging people to do that, too). Thanks for let me expand my knowledge through education. [0] https://en.wikipedia.org/wiki/Security_through_obscurity https://en.wikipedia.org/wiki/Security_through_obscurity