3 ms·
Looks really cool, but I find myself thinking about the privacy implications of using this, especially by default. Even if the user gives consent, it still impl
by marksomnian 8y ago
Looks really cool, but I find myself thinking about the privacy implications of using this, especially by default. Even if the user gives consent, it still implies recording every single mouse movement and keystroke on the site.
Has this been normalised? Is this the new default?
Food for thought.
- hardwaresofton 8y agoFrom what I understand rrweb is not introducing or hijacking any browser functionality -- it's just using what's there. Whatever boundaries are being crossed should be considered already crossed, because firms that want this data don't have to work that hard to get it (or they can just buy some off the shelf tool). If the privacy implications make us uncomfortable we might want to start not sharing this kind of information from browsers by default (this seems unlikely) or at least introducing some sort of browser-level controls. Unfortunately, this represents a lot of work and worries about breaking backwards compatibility contrasted with very little gain for browsers that don't pride themselves on being good for privacy(Chrome).
- deleted 8y ago[deleted]
- hjek 8y agoRMS has been writing about the issue of non-free session recording scripts in The JavaScript Trap[0]: > In addition to being nonfree, many of these programs are malware because they snoop on the user. Even nastier, some sites use services which record all the user's actions while looking at the page.[1] The services supposedly “redact” the recordings to exclude some sensitive data that the web site shouldn't get. But even if that works reliably, the whole purpose of these services is to give the web site other personal data that it shouldn't get. [0]: https://www.gnu.org/philosophy/javascript-trap.html https://www.gnu.org/philosophy/javascript-trap.html [1]: https://freedom-to-tinker.com/2017/11/15/no-boundaries-exfiltration-of-personal-data-by-session-replay-scripts/ https://freedom-to-tinker.com/2017/11/15/no-boundaries-exfil...
- SquareWheel 8y agoI agree with the privacy concern, but calling analytics software "malware" is too extreme. It isn't mining for bitcoins on your hardware, or encrypting your documents to extort you. Always using the most extreme terms just makes it easier to dismiss such views outright.
- hjek 8y agoI think it depends on how the software is used. A friend of mine got a suspicious tax returns email that had a link to a form asking for credit card information. Being careful and responsible, my friend of course asked me if the site looked legit before actually pressing 'submit'. Of course it was a scam site, and using session recording, they could very well have gotten my friend's credit card details without per pressing 'submit'. I think it's always the context that decides whether something is malware. Is a program that erases everything on your disk malware? Perhaps, but if it's a disk formatting tool and you asked it to do so, then it's not.
- SquareWheel 8y agoYes, that's a fair point and I agree with you on both examples.
- dceddia 8y agoIt's a good example, and something I often wonder about when I'm filling out a survey and give up part-way -- did they save the questions I had already answered? FWIW you probably wouldn't need something as powerful or blunt as session recording to pull this off, though. You'd only need to listen for keystrokes on the relevant input (with document.addEventListener or similar), and send them to the server as they're typed. Same with partially-filled surveys. IIRC Facebook got in some heat a while ago for sending the partially-typed messages up to the server and to the other chat participant.
- eastendguy 8y agoI agree. So while the project is technically super-cool, I prefer a browser extension for privacy reasons. With an extension (that does not "phone home") all data is stored locally on my machine. And if needed, the open-source kantu tool offers a way to embedded recordings into (your) a website, too: https://a9t9.com/kantu/demo/runweb https://a9t9.com/kantu/demo/runweb Inside your local team you can of course share the recording simply as JSON files, via github and other services. Another advantage of using browser extensions like kantu, selenium ide and imacros is that they are more powerful by design, but that is another topic.
- palerdot 8y agoI think, this should be considered as an easy to use library to do things that is anyway being done already, or anyone can do with some amount of work. Comparing this library to surveillance tool kind of distorts the idea of what this library is trying to achieve here.
- yz-yu 8y agoTotally agreed with your consideration about privacy. Unfortunately, as I wrote in my blog post, some commercial products already shipped features like this. So another passion of rrweb is to teach people the 'power' of the modern browsers, and I also wish rrweb has a chance to improve the standard of web privacy.