4 ms·
A point of worry. You mention tracking keyboard actions. Does that include as they're typing into text and password fields? If you're trying to avoid capturing
by mikemol 16y ago
A point of worry. You mention tracking keyboard actions. Does that include as they're typing into text and password fields? If you're trying to avoid capturing that kind of data, how can you be sure you're filtering out, e.g. custom JS-driven text widgets?
- thomas-st 16y agoRight now it captures any text field. I am planning to implement a filter so the website owner can choose which fields they don't want to capture. An idea would be also to specify an entire area of the page that shouldn't be captured.
- mikemol 16y agoIs it plausible to turn off all text capture, or use an 'opt-in' approach to fields and hooks, rather than an opt-out? (edit: On the part of the site administrator, I mean.)
- thomas-st 16y agoPlanned (no capture for password fields and an opt-out for other text fields). An option might be also to just display stars on regular input fields, so you could see that users are typing, but not see what they actually type.
- mikemol 16y agoAnd it doesn't capture keyboard input except from known text widgets? My paranoia rests with pagewide onKey* hooks and the like. I'm not a JS guy, though, but I'd assume those are possible. That's why I was curious about total opt-out of key trappings.
- thomas-st 16y agoCurrently it only captures known input widgets, i.e. no global key strokes.