8 ms·
Fair enough, they’re doing it to protect their business. But why should a user have to subject their machine internals to inspection by eBay? And, without thei
by ferros 6y ago
Fair enough, they’re doing it to protect their business.
But why should a user have to subject their machine internals to inspection by eBay? And, without their consent.
- nojito 6y agoVisiting a website implies consent.
- heinrich5991 6y agoNot in the GDPR.
- mschuster91 6y agoGDPR allows "necessary" data processing for "legitimate interests". IANAL but I believe a non-damaging portscan to check for security issues to be allowed. Especially as eBay has the legitimate interest to ward off fraud - and customers have the legitimate interest to have their accounts protected.
- TehCorwiz 6y agoThen they need to disclose that behavior. Because my firewall marks portscans as a malicious activity.
- rocqua 6y agoSince the portscan happens clientside on 127.0.0.1 I doubt your firewall will be able to notice the portscan.
- mschuster91 6y agoThat depends if you use IPv4 with NAT like almost everyone on a residential Internet uplink or IPv6 with a public routed address...
- zaarn 6y ago127.0.0.1 (aka localhost) isn't affected by your NAT setup. Your browser initiates this scan on the local loopback device, so the traffic will never even leave your computer (even on linux, it's somewhat difficult to get it to route 127.0.0.1 to another computer and it'll break a lot of applications in the process or make them insecure). IPv6 with a public routed address still means there is a firewall, just like with NATv4. NATv4 just also has a NAT router with that firewall.
- HenryBemis 6y ago> non-damaging protscan Tell that to every corporation on Earth, especially to Banks, that "port scanning your perimeter is an innocent thing". Tell that your employer as well and do tell us what's your job status afterwards. (I am not downvoting the utterly silly grey comments - I want them to be visible to a) ;)
- StochasticSand 6y agoConsent is a voluntary agreement to something. Port scanning is definitely not something I would expect when browsing the web (And based on the amount of upvotes on the last thread, not something most of HN would expect), so how can I be consenting to it without knowing about it?
- cornishpixels 6y ago> Port scanning is definitely not something I would expect when browsing the web (And based on the amount of upvotes on the last thread, not something most of HN would expect) Then you're a fool, frankly. Plenty of online services, web or otherwise, use port scans as a means to detect such things as open proxies or open MTAs.
- catalogia 6y agoWhat percentage of ebay visitors even know what portscanning is? How can somebody consent to something they aren't aware of, don't anticipate, and certainly don't even understand? Your notion of "consent" is an utter joke.
- jfoster 6y agoThey might not know what port scanning is, but can they agree to "anti-fraud measures?"
- catalogia 6y agoMaybe they might agree to such anti-fraud measures, but I don't think they have. I don't consider 'ignoring the terms of use buried at the bottom of the page or in small print' a legitimate form of indicated consent.
- jfoster 6y agoAgree with you that simply putting something in the terms of use doesn't necessarily indicate agreement. If they're only doing it to signed in users, then presumably they had the terms put in front of them at some point, but I think your objection is still fair in any case. To what extent do they need consent to port scan, though? They're not intending to do anything malicious, and in fact (assuming you are the owner of the account that's signed in) they're doing it partly to benefit you. Is there a law against port scanning? Does it affect users in any way?
- lern_too_spel 6y agoWhat percentage of eBay users know what an IP address is?
- deleted 6y ago[deleted]
- cornishpixels 6y agoOpen ports which are accessible to the Internet at large are not "machine internals". If you do not want someone to access your systems, then you should configure your systems to not allow that access.
- xook 6y ago"It's not my fault I can break into your house and steal everything"
- AnssiH 6y agoThey are scanning 127.0.0.1 locally from the browser, so the ports do not need to be internet-accessible.
- cornishpixels 6y agoThey are open ports which are accessible to the Internet at large. Or at least, any site you go to. If you don't like that there are various means to close off those ports to your browsers (Windows firewall, network namespaces, etc).
- Fnoord 6y agoIt is illegal for me to perform a portscan. Why it is legal for eBay, who knows?