27 ms·
Parsing access logs in 2015? Really? You mean those logs that are cluttered with bot traffic and that only have IP addresses instead of real user sessions, and
by rgj 12y ago
Parsing access logs in 2015? Really? You mean those logs that are cluttered with bot traffic and that only have IP addresses instead of real user sessions, and do not contain valuable information about for instance exit pages, banner clicks, page load times, and so on?
- thaumaturgy 12y agoYour knowledge of what can be extracted from server logs is a little bit out of date. Also, server logs are the only tracking system that can't be disabled by visitors.
- zwetan 12y agonope, there are number of ways to track visitors even when everything is blocked (like ga.js or whatever) and all cookies disabled. With user-agent header, ip address, etc. you can uniquely identify a user because there is enough entropy, see https://www.eff.org/deeplinks/2010/01/primer-information-theory-and-privacy https://www.eff.org/deeplinks/2010/01/primer-information-the... and that basically allows you to emulate a session id without cookies and without appending it to the URL You can also use the cache to know if the user already visited some content or not, explained here http://joshduck.com/blog/2010/01/29/abusing-the-cache-tracking-users-without-cookies/ http://joshduck.com/blog/2010/01/29/abusing-the-cache-tracki... And finally, you can use CSS custom styles to know if the user already visited some web sites or not, see spyjax http://davidwalsh.name/ajax-evil-spyjax http://davidwalsh.name/ajax-evil-spyjax granted, the user can disable JS, change the user-agent, but I would argue they are still trackable
- ryanmcdonough 12y agoThere isn't always enough entropy to uniquely identify a user - you can't rely on that to provide accurate tracking. If people are coming from a corporate environment using terminal servers then every single browser will identify as one user by that method. Most browsers are now taking steps to stop the CSS custom styles hack working - for example this doesn't work in Chrome anymore. The website can show you which websites you've visited with the change in colour for the link state however it can no lonqer query it.
- zwetan 12y agoit would be as accurate as the server logs, the only difference is I don't need to analyse those logs I can keep using google analytics. that's my whole point: "yadda yadda yadda ublock or adblock or whatever block ga.js on the client side haha you can not track the visitors anymore" nope I can still track them and I don't need to even bother analysing the server logs server side: 1. I can detect if there is a _ga cookie 2. if not, I can generate a UUID based on the user-agent and IP 3. and I send my pageview from the server side it is not perfect, I would certainly not use that UUID to identify a login session but it does work without me having to stop using google analytics. > "There isn't always enough entropy to uniquely identify a user" there is, read the EFF link it explains all that nicely TL;DR - you can not send tracking client side anymore - OK, I can send tracking server side, go ahead try to ublock that