LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > General
User Name
Password
General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun!

Notices


Reply
  Search this Thread
Old 11-23-2017, 05:58 AM   #1
hazel
LQ Guru
 
Registered: Mar 2016
Location: Harrow, UK
Distribution: LFS, AntiX, Slackware
Posts: 7,574
Blog Entries: 19

Rep: Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453
Session replay. Is this a widely known thing because it's new to me


Apparently some websites (I don't know which ones) have this thing called session replay that logs your input keystroke by keystroke. Even if you don't actually send what you typed, it's still logged. This log is then sent on to what are called "pre-authorised third parties". Any information on what that means is welcome.

The information collected could even include passwords.

Someone called Steven Engelhardt at Princeton did this study. I couldn't find it online, but I found a general site on the project https://webtransparency.cs.princeton.edu
 
Old 11-23-2017, 06:06 AM   #2
syg00
LQ Veteran
 
Registered: Aug 2003
Location: Australia
Distribution: Lots ...
Posts: 21,128

Rep: Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121Reputation: 4121
Have a read of this
 
Old 11-23-2017, 06:11 AM   #3
Turbocapitalist
LQ Guru
 
Registered: Apr 2005
Distribution: Linux Mint, Devuan, OpenBSD
Posts: 7,309
Blog Entries: 3

Rep: Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721Reputation: 3721
That report is useful but the problem is widely known in a more general context. This specific logging being confirmed is somewhat new, at least for much of the general public. There was a lot of discussion once again last year around this time. One of the resulting demonstration sites is here:

https://clickclickclick.click/

However what is being reported by the team at Princeton is just the capabilities of javascript. The scary part is that given how trivially easy it is to MitM HTTPS connection, even 'trusted' sites should not be using javascript if they want their visitors to remains safe. Might or might not be a big deal from home but might be a big deal from a conference center, a hotel, or a cafe. VPNs help but that just moves the egress and thus the target.

You can see how many hundreds of objects some sites bring in. Many of those are external and many of those external objects are javascripts. To see them try going to your local municipal web site or your bank. Then try ctrl-shift-i in your browser. Choose Networking and then reload the page.
 
Old 11-23-2017, 06:44 AM   #4
hazel
LQ Guru
 
Registered: Mar 2016
Location: Harrow, UK
Distribution: LFS, AntiX, Slackware
Posts: 7,574

Original Poster
Blog Entries: 19

Rep: Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453Reputation: 4453
Quote:
Originally Posted by syg00 View Post
Have a read of this
I'm sure that's the one!
 
Old 11-29-2017, 11:59 AM   #5
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
One of my Clients got mentioned in https://www.wired.com/story/the-dark...y-move-online/
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Record and Replay Terminal Session with Asciinema on Linux LXer Syndicated Linux News 0 02-03-2017 02:51 PM
Process killed during close ssh session, how prevent such thing Lenin1 Debian 3 11-23-2016 01:56 PM
How to record and replay a terminal session on Linux onebuck Linux - General 4 05-11-2014 08:11 AM
LXer: How to record and replay a terminal session on Linux LXer Syndicated Linux News 0 05-05-2014 07:30 AM

LinuxQuestions.org > Forums > Non-*NIX Forums > General

All times are GMT -5. The time now is 05:31 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration