3 ms·
Apparently CodePen 2.0 sends data to their servers as you type
They send all typed into editor input to codepen.dev almost immediately (you would see in 1-2 sec after you typed your secret that it appears in respective Network/Response tab) even before one saved it. I tested this with a unique marker: after typing it into index.html, CodePen ran a build with "save:false", and the marker then appeared verbatim in the HTML served from the generated "*.codepen.dev preview". Thus, if you ever entered some secrets in there by mistake consider them compromized even if you did not publish/save the pen
- keepo404 28d agobecause this is how autocomplete logic works i guess? Frontend cannot guess language and completions for you
- embedding-shape 28d agoWell, except for the cases when you happen to have the entire VM for your language running in the same tab where you program lives, and they both are all JS. Probably harder, and wouldn't work equally well for everyone, but it would be possible to have "guess language and autocomplete" entirely client-side, especially when it comes to JavaScript of all languages.
- odo1242 28d agoIt seems like the main disadvantage would be that you have to load all the autocomplete data / model weights on the client-side and your webpage might be CPU/memory limited
- embedding-shape 28d ago> main disadvantage would be that you have to load all the autocomplete data / model weights on the client-side Not sure what "model weights" you're talking about, but yes, that is the trade-off. Although complete autocomplete data for the entirely of the JavaScript APIs would be what, in an efficient format, easily below 1MB at least.
- mkgiga 28d agoCode editor autocomplete doesn't use ai — search up LSP
- maxim-fin 28d agoNo autocomplete involved there.
- giancarlostoro 28d agoYeah I remember CodePen refreshing for me plenty of times.
- mkgiga 28d agoyes it can. all you need are some tokenizers for the languages you want to guess and once you derived the language, a few lookup tables to store variable name references in :)
- bashy 28d agoSent to them to render the preview pane. Same as pasting secrets anywhere on a browser. Wait until you find out copying content on a computer might sent it over Wi-Fi/Bluetooth for sharing on other devices.
- maxim-fin 28d agoYes, that is for rendering Edit: and as "kypro" pointed out also for saving the current work but if you you quit (or crash) without saving the pen there is no way to recover unsaved work regardless
- tvink 28d agoYou're gonna be shocked how many input fields do this for various UX features :)
- embedding-shape 28d agoHotJar and similar services are (were?) popular as well, and those record your mouse pointer movements and clicks as well, then displays that as an overlay over the application, so it's essentially a "screen recording" of your session of the application.
- nusl 28d agoShopify does this. If you ever go to purchase a product on a Shopify 'site, and enter eg your e-mail address, it'll save it even if you decide to cancel and close the tab. Sometimes you receive spam from companies along the lines of marketing or "we noticed you didn't complete your purchase" type crap. Shit is rly invasive.
- Boss0565 28d agoHave you checked to see if it’s stored in localstorage
- pdyc 28d agoi made my own html playground that is browser only and shares preview via url hash because of these useless shenanigans of codepen, its not as featureful but i mostly use it for sharing single page html files https://easyanalytica.com/tools/html-playground/ https://easyanalytica.com/tools/html-playground/
- cph123 28d agoFor basic previewing I like to use https://htmledit.squarefree.com https://htmledit.squarefree.com which has been online for years and does it all client side.
- nseskin 28d agoThere’s a detailed discussion of the same issue here https://www.reddit.com/r/webdev/comments/1rj1oac/i_planted_fake_api_keys_in_online_code_editors/ https://www.reddit.com/r/webdev/comments/1rj1oac/i_planted_f...
- maxim-fin 28d agoIndeed, it looks like CodePen v1 was sending data to codepen.io, cpwebassets.codepen.io, and cdpn.io. Now v2 sends to codepen.dev
- deleted 28d ago[deleted]
- cetinsert 28d ago[flagged]
- tmpsvc2695f5 28d ago[dead]
- midnitewarrior 28d agoLook into https://www.fullstory.com/ https://www.fullstory.com/ , many major websites use this, it's basically a real-time video view of the user's browser screen. You can see where they move their mouse, how quickly they are typing, each character one at a time. I worked for a company that would have phone support for users, and we'd be watching their screens giving gentle suggestions to them as they were using our app for how to do what they needed to do. We never offered up what we were doing, but given users' poor descriptions of what they were doing, FullStory was an amazing customer service tool.
- VoidWhisperer 28d agoSomething like this would've been incredibly useful at my previous job - we often had to put together how a user triggered an issue using a combination of logs and analytics to track what actions they took..
- maxim-fin 28d agointeresting!
- giancarlostoro 28d agoElastic has something like this too, as does Splunk iirc. Idk how all three compare I just know they can track DOM events type of stuff and recreate a flow video.
- deleted 28d ago[deleted]
- maxim-fin 28d agoCodePen does not disclose this in neither ToS nor in Privacy Policy, only in Builds documentation they say: “As you work on CodePen, your Pens are constantly running through the CodePen Compiler”
- kypro 28d agoThis is so it can restore any unsaved changes. I take no opinion on whether this is good or bad, but I can see how from a UX perspective it's nice not to lose 10 minutes of work because your browser crashes or something.
- maxim-fin 28d agoYes, absolutely, there are good reasons for that. The point is that any secrets typed/pasted in there should be considered compromized Edit: but then if you you quit (or crash) without saving the pen first there is no way to recover unsaved work regardless. That is, the pen must be saved manually at least once for the user to benefit from the autosave.
- giancarlostoro 28d agoPretty sure it always autosaved so this makes sense to me? I always assume it would send my data over to their backend, its code that ends up there regardless?
- maxim-fin 28d agoYes, that is for autosave and for rendering Edit: The point is that any secrets typed/pasted in there should be considered compromized
- deleted 28d ago[deleted]
- giancarlostoro 28d agoI don't know why anyone would paste or type secrets into codepen which is public by default... But it always seemed like it auto-saved / sent your code over to the back-end, going back ten years roughly?
- traviswingo 28d agoCopy -> paste -> redact secrets That flow would be considered unsafe, and probably common.
- maxim-fin 28d agoThis is exactly the scenario I pictured
- giancarlostoro 28d agoIf you are pasting secrets into codepen you are probably really terrible at all other basic security practices.
- leptons 28d agoIt's also a foolish thing to do. Any time anyone types anything into anywhere on any webpage, that data is as good as gone, it's out there. Back in the 90's I experimented with per-character logging on all form input boxes, just because I could. That's still possible today.
- alfredo359 28d ago[dead]
- qsbuilder 28d ago[dead]
- quietraster 28d agothe 'it's just autosave' defense in the comments is interesting. is keystroke-level granularity actually needed for that though?
- aveao 28d agoReads to me like it's debounced to a few seconds after you stopped typing.
- maxim-fin 28d agoGood point
- mkgiga 28d agoI think what's more interesting is if privacy is the concern, why does the timing matter? The same data is getting saved either way. Actually never mind, you aren't sending them private information anyway so it's not a privacy concern in the first place.
- huzefashaikh 26d ago[dead]
- dbushell 28d agoI'm looking forward to the Gamers Nexus exposé
- millerm 28d agoReddit does this. Every keystroke you type into a comment box is sent back to them. So, that means even if you decided to cancel posting something, they still receive what you wrote. I have been known to write responses that were harsh and angry, and I simply don't send. Sometimes it's therapy for me to think through something while typing whatever is in my head. Then I go back and edit once I have have thought it through. I don't want that info sent back. So, I tend to not involve myself with much online anymore. I don't want to expose myself to the thought police. I find the browser the most unsafe piece of tech deployed.
- c-hendricks 28d agoEver since I learned about full story / datadog RUM I've been writing my replies in a notes app then copy and pasting back in the browser
- millerm 27d agoYeah, it's infuriating.
- tryka7966 28d ago[dead]
- mkgiga 28d agoif you paste secrets in any website you should be fired immediately
- tmpsvc2695f5 27d ago[dead]
- MoneyLovesSpeed 26d ago[dead]
- tmpsvc2695f5 26d ago[dead]
- spartanatreyu 24d agoWell duh, this is how codepen works! Try this: 1. Open one of your codepens 2. Now open the same codepen in a different window so you have two open at the same time 3. Now type in one window 4. Watch it s̶e̶n̶d̶ ̶y̶o̶u̶r̶ ̶c̶h̶a̶n̶g̶e̶ ̶t̶o̶ ̶t̶h̶e̶ ̶s̶e̶r̶v̶e̶r̶ ̶t̶o̶ magically update all other clients --- Also, notice how your browser never had to download typescript, sass, babel, tailwind, etc...? That's because what you type gets sent to the server to transform it into compiled html.
- eitri 23d agoAutosave doesn't necessarily require the server though. localStorage can provide keystroke level saving on the client and survive a crash just fine. So I'm not sure that "its just autosave" fully explains why every keystroke needs to be sent to the server.