10 ms·
How to track and display profile views on GitHub
- andrew_ 6y agoEverything old is new again. I used this same technique on MySpace 15 years ago. I wonder if Github will try to filter that out the same way MySpace did back in the day.
- rushter 6y agoI did some research before writing an article. GitHub started proxying images in 2014, and there are a lot of repositories that use this technique to keep their stats. I think GitHub is OK with that.
- jrrrr 6y agoRe: proxy security concerns: >Unlike GitHub, most of them don't even bother proxying the image to hide IP, referrer, and browser agent. If you want to allow external images on your site, you must proxy them and hide everything about a person who requested it. > A person with bad intentions can trick a victim into opening your profile that looks completely legit and detect his IP and a browser. Can you explain this in more detail? Given a profile host that doesn't proxy, how does that attack work?
- nso 6y agoAttack? 1. your browser opens image from external server (in this step the server gets your IP and potentially user agent as that's how browsers communicate with servers) 2. there is no step 2
- cutemonster 6y agoWhat? My step 2: Go to ip addr and ask your favorite celebrity (whose ip you got) for an autograph and selfie together
- f311a 6y agoThe IP itself can be a very valuable information if you target famous people, politicians, criminals and so on. Such people usually know, that clicking on random links is not safe.
- alibarber 6y agoMemories! I hid my top 6 and made a 'random friend' thing. It was an image i.e. http://whatever/random-friend.jpg http://whatever/random-friend.jpg that linked to http://whatever/forward-to-friend http://whatever/forward-to-friend. The server served up a random profile picture - and crucially a cookie header that set the friend-id as a cookie that forward-to-friend would use to send you to the corresponding profile. I was _so_ proud of it at the time...
- input_sh 6y ago> the same way MySpace did back in the day. For us that weren't around in MySpace era, how did they do that?
- alibarber 6y agoI can't remember much about images - but basically filtering out question-marks and equals symbols (i.e. ...thing.php?some=value) in a lot of places. I remember getting Facebook and when they first started their API it was a bit better thought out, so they loaded images on the user's behalf. Some great reading about 'hacking' myspace at the time: https://samy.pl/myspace/ https://samy.pl/myspace/
- oalders 6y agoRight. So you just had to serve a counter up via http://example.com/path/to/my/counter.gif http://example.com/path/to/my/counter.gif and embed whatever info you needed in the path to get around this.
- vmception 6y agoI think I did this for emails sometime between 15 years ago and today
- ddevault 6y agoCan we please not normalize this? Vanity tracking at its worst. You don't need to know.
- ch4s3 6y agoI definitely agree, and believe that this sort of thing sets a very negative example for young folks coming into the industry. Chasing views, starts, and shares is a sure path to burnout and mental health problems that already seem to plague very online tech people. *[edit] I don't mean to shit on the OPs work or the coolness factor here. I'm just a bit put off by the idea of creating new anxiety levers for people to pull that don't offer much if any real value.
- rushter 6y agoI agree, but I think such information should be available to all people. Some people will be doing this anyway, and they can hide this by using a transparent pixel.
- pc86 6y agoThere will also be plenty of people who put images on their profile like this with no interest in tracking the metrics.
- stagger87 6y agoWhat benefits do you feel you get from this over the view counting Github already does for you?
- rushter 6y agoYou can't view profile statistics right now. Personally, my intent was to demonstrate the concept. I don't have plans using it.
- joeraut 6y agoSeconding this. I don't know if it's a fair comparison but Instagram is removing publically-visible like counts because of their associated consequences, and embeddable banner services for tracking GitHub profile views seems inevitable.
- geerlingguy 6y agoFirst I heard about a readme for your profile page. So the facebook-ification of GitHub progresses? At what point is LinkedIn going to be merged into GitHub? (Only partially /s)
- deleted 6y ago[deleted]
- jomar 6y agoIt's just gone live in the last day or so. The designer talked about it here a few weeks ago: https://twitter.com/pifafu/status/1265773172520914944 https://twitter.com/pifafu/status/1265773172520914944 Personally I don't see much reason for this to be implemented via a git repository (rather than a text field in a database, like the existing Bio text), other than "we're GitHub, everything's a git repository, so why not". At the moment, it's a single-file repository. Perhaps they have some ideas for other things that could be served from there too. Weirdly at the moment it's required to be a public repository. This seems counterproductive: if it's my personal information blurb I don't much want other people looking at its history and I certainly don't want them forking it. (Are there any non-malicious reasons for doing that?)
- chrisshroba 6y agoTo be honest, I'm not too concerned. Making it a git repo makes the history more readily available, but a bad actor could still get it from internet archive or other archive sites. And if the concern about forking is that someone could impersonate you, they could do so with a few extra steps by just looking at the rendered HTML of the README. I know there's something to be said for making malicious behavior more difficult to achieve, but in this case the amount of extra work someone would have to do is minuscule if this weren't implemented as public repos.
- victords 6y agoAre there malicious reasons for doing that?
- f311a 6y ago
- jna_sh 6y agoThis is interesting because this didn't used to be possible from a repository's readme, I believe, because linked images would be cached and served from GitHub's CDN. I wonder what's changed (if it indeed has)
- minxomat 6y agoThat's literally discussed in depth in the article. They use headers for cache-busting just like README badges have done forever.
- jna_sh 6y agoAh gotcha, sorry, totally missed that!
- rushter 6y agoYou can check it here https://github.com/dwyl/hits https://github.com/dwyl/hits Also https://twitter.com/holman/status/427937383376379904 https://twitter.com/holman/status/427937383376379904
- gildas 6y agoYou could also simply click on the "Insights" tab of the repository you created to host the README.md page.
- cmeacham98 6y agoFrom TFA: > According to my tests, profile views do not count as repo views, and I hope, in the future, we will be able to see traffic stats in the repository that hosts the README file.
- gildas 6y agoMy bad, I missed that part. Hopefully Github will implement this feature.
- lalos 6y agoFriendly reminder that you can disable automatic downloading of remote images on emails on your phone and other email clients. People use it to track if you've read or not the email, engagement etc.
- adamhearn 6y agoI find it saves tons of time and data as well. The emails are very condensed without (remote) images.
- steventhedev 6y agoWhich exact headers are being leaked by GitHub? Depending on what they leak, this could be something only useful for counting hits (if all they leak is the implicit time of the request), or for fully tracking users (if they leak Etags, original IPs, etc). It's too bad the author removed the badge from their Github profile. It would be interesting to see the effect of this post on profile views.
- rushter 6y agoGithub does not send any extra information. "GET /counter.svg HTTP/1.1" 200 565 "-" "github-camo (62249a1c)" I've reverted the badge.
- zemnmez 6y agoGithub proxies all image requests, like GMail as a security measure. The cache busting technique the author refers to only ensures the security proxy doesn’t cache the image data, which would prevent the counter going up
- pcr910303 6y agoOops, looks like the author got too many load from the server and removed the badge from his Readme.md? This is the commit which removed it: https://github.com/rushter/rushter/commit/00d0d552e262218dae534a699195d657cf002e1a https://github.com/rushter/rushter/commit/00d0d552e262218dae... I guess one shouldn't do this if your profile becomes popular enough...
- rushter 6y agoI've removed it because it does not display relevant information anymore (someone fetches ten times a second via wget). I also don't have plans to use it in the future. I wanted to demonstrate the concept.
- delta1 6y agoOr just use something more performant than Python/Flask - if the author was using the library he linked to [0] [0] https://github.com/brentvollebregt/hit-counter https://github.com/brentvollebregt/hit-counter
- neslinesli93 6y agoShameless plug, but I'm playing with Rust these days and I've setup a small POC: https://github.com/neslinesli93/hits-rs https://github.com/neslinesli93/hits-rs Hopefully actix-web is a bit more resilient than Python!
- tominsam 6y agoImage hit counters! Who's going to build the github developer web ring? We need all the old things back.
- sneak 6y agoIf we’re going back to the 90s, can we re-embrace avoidance of proprietary Microsoft tools (GitHub) in favor of f/oss alternatives?
- mahaganapati 6y agoWhat do you recommend? There was one I remember seeing the name of here but I've forgotten
- brian_herman__ 6y agohttps://sourcehut.org/ https://sourcehut.org/ the owner is a frequent hacker news poster.
- mahaganapati 6y agoYep that was the one! Thank you
- sneak 6y agoPersonally, I self-host Gitea. It works extremely well. It has webhooks that tie nicely into my (also self-hosted) Drone (CI) and Mattermost (f/oss self-hosted Slack replacement) and CapRover (self-hosted Heroku) setups.
- mahaganapati 6y agoThat's awesome! It sounds like a great setup for a solo dev wanting to save money, or even for bootstrapping a startup. Thanks for sharing
- monokh 6y ago> Of course, there will be some extra requests from bots, but having such statistics is better than nothing. I think this is a bit understated. A simple number coming off the image requests is going to be very unreliable. On average, you will not be able to discern bots and real users. A plotting of the hits over time may be more usable.
- oefrha 6y agoUnrelated badge ideas: 1. Write a watcher that periodically reports whether you’re actively using a coding-related app (Terminal, VS Code, etc.) to a server you control, and serve a “coding”/“not coding” badge on your profile page; (could even detect which project you’re working on, and display that;) 2. Write an Apple Watch app that periodically reports whether you’re asleep, and serve a “sleeping”/“awake”/“unknown” badge on your profile page.
- abjKT26nO8 6y agoSounds dystopian.
- deleted 6y ago[deleted]
- saagarjha 6y ago> Write a watcher that periodically reports whether you’re actively using a coding-related app (Terminal, VS Code, etc.) to a server you control, and serve a “coding”/“not coding” badge on your profile page; (could even detect which project you’re working on, and display that;) Sounds like Discord.
- levosmetalo 6y ago3. Write an integration to the local cemetery, and after funeral is successfully detected serve "alive/dead" badge on the profile page.
- jamil7 6y agoMaybe closer to reality than we think.
- wallflower 6y ago> A cemetery in Slovenia just created a prototype digital tombstone that allows mourners to broadcast videos and images of the deceased in place of the traditional grey grave marker. The weatherproof 48-inch screens cost about $3,200 and have been built to resist vandals, Reuters reported. https://www.marketwatch.com/story/this-creepy-3200-digital-tombstone-has-a-48-inch-screen-to-broadcast-dead-peoples-wishes-2017-04-10-888169 https://www.marketwatch.com/story/this-creepy-3200-digital-t...
- the_arun 6y agoThanks for sharing. Though it is exciting to see so many ideas here, wouldn't it be great if GitHub solves tracking use case in the platform rather than we all hacking different solutions?
- xs 6y ago> The rest of the story is simple — you need to store a counter in the database and return an SVG image with the number of views as a response. Of course, there will be some extra requests from bots, but having such statistics is better than nothing. "The rest of the story is simple" uh, no that's not simple at all! You want me to register a domain, get a hosting provider, create a database, and create logic to listen for requests with anti-bot detection? Please don't say this is simple.
- justicz 6y agoAnother reason proxying requests to external images is important is that some browsers will display an HTTP Basic Auth dialog if the image request responds with the right kind of 401. It’s confusing and sort of disconcerting to see a basic auth dialog pop up from a random site if you’re just browsing Github.
- ebg13 6y ago> As part of recent design changes, GitHub has introduced READMEs for profiles This is a weird new myth that might just highlight the difficulty of discoverability. GitHub has had user profile READMEs for years. The difference is just where the README shows and what the name of the repo is supposed to be. You could already create a "<username>.github.io" repo that governs what shows up when visiting https://<username>.github.io https://<username>.github.io
- JoblessWonder 6y agoI did this for Facebook back in the day back when you used to be able to post your own images! Back in the early, early days. I got a few blogs to write it up because it tracked the referring URL so you could send out special links to people and then track how often they viewed your profile. I miss being young and having a seemingly infinite amount of time on my hands...
- wonderlg 6y agoThis isn’t meant to last. GitHub has been proxying markdown images for years to avoid exactly this. Probably they haven’t gotten around to fixing that here yet… but this surprises me.
- paulgb 6y agoThe trick here is preventing the proxy from caching the image. The request is then still proxied but has a 1:1 correspondence to requests for the image. But now that it's public knowledge that this works, I agree that GitHub will close the hole.
- flywheel 6y agoI've been using this exact trick to track hits on my github repos for years already. If/when Github gets around to fixing it, I've already had it working for many years so even if it wasn't "meant to last", it's already lasted quite a while and I have no regrets. If they stop allowing it, then so be it.
- philshem 6y agoInteresting, when I create a repo with my profile name, it shows this text: > You found a secret! philshem/philshem is a special repository that you can use to add a README.md to your GitHub profile. Make sure it’s public and initialize it with a README to get started. Edit: HN stripped some emojis