Almost Every Website You Visit Records Exactly How Your Mouse Moves (medium.com) 89
Medium's technology blog OneZero reports that many websites today use a service that collects all of your mouse movements, enabling "replays" of every move.
"What surprised me was that the software even recorded when I shook my mouse around while deciding what to click on. It felt like observing digital body language." Session replay services have been around for over a decade and are widely used. One service, called FullStory, lists popular sites like Zillow, TeeSpring, and Jane as clients on its website. Another, called LogRocket, boasts Airbnb, Reddit, and CarFax, and a third called Inspectlet lists Shopify, ABC, and eBay among its users.
They bill themselves as tools for designing sites that are easy to use and increase desired user behavior, such as buying an item. If many users add items to their cart, but then abandon the purchase at a certain rough part of the checkout process, for instance, the service helps site owners figure out how to change the site's design to nudge users over the checkout line... FullStory even has a feature that tracks what it calls "rage clicks." This is when a user gets frustrated with a site and starts angrily clicking over and over.
In a semi-related story, a reporter for The Markup also recently discovered Amazon had apparently collected 90,000 rows of timestamped data about every tap they'd made on their Kindle.
"What surprised me was that the software even recorded when I shook my mouse around while deciding what to click on. It felt like observing digital body language." Session replay services have been around for over a decade and are widely used. One service, called FullStory, lists popular sites like Zillow, TeeSpring, and Jane as clients on its website. Another, called LogRocket, boasts Airbnb, Reddit, and CarFax, and a third called Inspectlet lists Shopify, ABC, and eBay among its users.
They bill themselves as tools for designing sites that are easy to use and increase desired user behavior, such as buying an item. If many users add items to their cart, but then abandon the purchase at a certain rough part of the checkout process, for instance, the service helps site owners figure out how to change the site's design to nudge users over the checkout line... FullStory even has a feature that tracks what it calls "rage clicks." This is when a user gets frustrated with a site and starts angrily clicking over and over.
In a semi-related story, a reporter for The Markup also recently discovered Amazon had apparently collected 90,000 rows of timestamped data about every tap they'd made on their Kindle.
Please note (Score:2)
Re: Please note (Score:2)
Re: (Score:2)
Trying to keep you on the page (Score:4, Informative)
Re: (Score:2)
Windows 7 users will feel right at home then.
Re: (Score:2)
Re: (Score:2)
Down at the bottom-right, the system always pops up messages saying "java needs updating" or "your vpn conection is active." Right above the clock.
Try to mouse over to close the annoying popup, and it disappears just before the mouse reaches it.
I'm an internet window shopper (Score:1)
So I get the coolest ads for all sorts of cool stuff I dream of being able to afford. Maybe they'll send me a winning lottery ticket...
Sounds like a job for some nice scripts (Score:5, Interesting)
to automate, and feed fake data into this system.
You could start with something like mouse jiggler. Use a separate browser that you don't use for anything else. bury their metrics in piles of bad data...
Re:Sounds like a job for some nice scripts (Score:4, Interesting)
to automate, and feed fake data into this system.
There are people working on this problem.
The goal is to be able to use automation tools like Selenium on sites that block them with "I am not a robot" popups, which distinguish between human-generated mouse movements and software-generated mouse movements.
Re: (Score:2)
The "I'm not a robot" pop ups work by knowing you are logged in in google or FB or elsewhere ... ...
A tablet has no mouse movement
Re: (Score:2)
Almost all of them use "recaptcha" which is a property of Google.
But recaptcha could not care less what sites you are logged into.
Re: (Score:2)
Recaptcha knows that you are using google chrome and that you have visited plenty of sites like a human ...
Re: (Score:2)
I mean, maybe they are designed to work together, but I seldom use Chrome, precisely for reasons like that.
In fact in general I use Google products as seldom as I practically can.
Re: (Score:2)
It's a back-and-forth war. One side comes up with a solution, the other side alters their program to nullify it.
And on it goes.
Re:Sounds like a job for some nice scripts (Score:5, Informative)
Yes, some sites do this. But "most" would be a gross exaggeration, and "almost every" is just plain la-la land.
Re: (Score:1)
Re:Sounds like a job for some nice scripts (Score:4, Informative)
Or just browse on your phone, or any touch device really, which has no concept of a "mouse" or "mouse pointer".
You did see the bottom of the summary where it says:
"In a semi-related story, a reporter for The Markup also recently discovered Amazon had apparently collected 90,000 rows of timestamped data about every tap they'd made on their Kindle."
Re: (Score:2)
Just don't allow javascript in the first place, unless you explicitly allow it.
Did anyone else... (Score:4, Funny)
Re: (Score:2)
Re: (Score:2)
I do that in general since when I read I follow my cursor. Drives the wife nuts when I compulsively click for no reason.
Re: (Score:2)
I do that in general since when I read I follow my cursor. Drives the wife nuts when I compulsively click for no reason.
I'm old and I scan each line of text with my mouse as I read.
I get parallax errors that confuse me as to what line I'm, currently on, and where the next begins when I'm at the far right.
What I do is highlight a small segment of current text as sort of a bookmark. That way I can find the next line underneath that.
I do the same thing when it's a long article and I have to pee. It's a placeholder.
I'm sure my consistent behaviour is readily identifiable.
Re: Did anyone else... (Score:1)
Re: (Score:2)
Maybe I'll write an extension... (Score:2)
Re: (Score:2)
Re: (Score:2)
user name legit
Re: (Score:2)
All that directional movement will certainly provide a ton of useful entropy...
Hmmm interesting idea, random number generation is not so easy in computers so we harness the mouse movements from porn site visitors, all that movement captured as tons of free entropy for encryption systems. We could pay them for it, call it "Jack and Earn", for the guilty Catholics we could call it "Earn while you Burn!".
Re: (Score:2)
All that directional movement will certainly provide a ton of useful entropy...
Hmmm interesting idea, random number generation is not so easy in computers so we harness the mouse movements from porn site visitors, all that movement captured as tons of free entropy for encryption systems. We could pay them for it, call it "Jack and Earn", for the guilty Catholics we could call it "Earn while you Burn!".
Our computers are monitored for sound. We could easily mishmash that shit from millions of computers as random noise and get random numbers.
Or we could more easily do the same thing with Trump speeches.
My mouse movement patter (Score:2)
I can practice my drawing skills then as I make a giant FUCK YOU.
What mouse? (Score:2)
Re: (Score:2)
I have an old web app for home use that has mouseover UI elements. Buttons that appear on hover. I'm too lazy to reprogram it. A careful tap and slight drag will trigger mouseover anyway.
Re: (Score:2)
Slow performance (Score:5, Insightful)
And this is one of many reasons why browsing the web requires way more system resources than it should. I don't want to go to Lynx or anything - I just don't want Chrome to eat more than 8GB of RAM and for web sites to be fast enough to operate on my phone, too. Is that too much to ask? Between tracking, resources loaded from 50+ domains, and video ads the web is a really annoying place these days. Popup or popunder windows almost seem quaint and unobtrusive.
Re: (Score:2)
I just don't want Chrome to eat more than 8GB of RAM
I just saw (didn't read) about a Mac Pro with 1TB of RAM, and it was able to open 6,000 tabs and still be responsive and what-not.
You've got 1TB of RAM and you're ONLY able to open 6 thousand tabs?
Here it is. [9to5mac.com]
Re:Slow performance (Score:5, Informative)
If you use uBlock Origin or a similar ad blocker then the popular EasyPrivacy filter list will kill this for you.
Re: (Score:2)
And this is one of many reasons why browsing the web requires way more system resources than it should. I don't want to go to Lynx or anything - I just don't want Chrome to eat more than 8GB of RAM and for web sites to be fast enough to operate on my phone, too. Is that too much to ask? Between tracking, resources loaded from 50+ domains, and video ads the web is a really annoying place these days. Popup or popunder windows almost seem quaint and unobtrusive.
Yeah, when I navigate to a site, it's astounding the number of other sites riding shotgun and they all have to load successfully before I can make a soft landing.
And they STILL can't make a working web site (Score:5, Insightful)
Re: (Score:2)
Case in point, if your web site is just a white rectangle if Javascript is disabled, you have failed in life and should kill yourself.
Would it be better if turning off JavaScript caused the website to display a link to download a matching native client installer?
Re:And they STILL can't make a working web site (Score:5, Informative)
Happily, some of us still exist. I recently de-WordPress'ed one of our customer's websites into static HTML. While I was at it, I made sure it worked without JavaScript, even creating pop-up windows that worked with just HTML and CSS. Finally, I added back a little tiny bit of non-essential JavaScript for some progressive enhancement (smooth scrolling). In the end, the website that was once 1.2 GB as WordPress is now a nice little 1.7 MB HTML site that works for anyone and can't be hacked.
I'm hoping someday there is a resurgence of this kind of development. The new techniques are not always better.
Re: And they STILL can't make a working web site (Score:1)
Just curious, did you use a static site generator? I've played with Hugo - https://github.com/gohugoio/hu... [github.com] - but haven't used it for a serious project yet.
Re: (Score:2)
No, everything was redone by hand, including completely original CSS (no frameworks). This has been my career since 1995.
If you're curious to poke around the source code, the website is https://www.grossmanstanley.com/ [grossmanstanley.com].
Re: (Score:1)
If you idiots were able to record every synapse firing in my body while I use your web site, you still could not make a functional web site. It's like all competent web developers decided to quit at the turn of the century.
You sound like you're going for insightful, but the reality is broken websites are truly rare. Slow to load, yes, but pretty much every website out there not targeted at IE6 is perfectly functional save for the occasional CDN outage that is outside of the webmaster's control.
I'd take an old Geocities web page over many a "modern" web site.
Hyperbole makes any point you had weak and meaningless.
Case in point, if your web site is just a white rectangle if Javascript is disabled, you have failed in life and should kill yourself.
Indeed. The website should just display the text "Turn on Javascript and welcome to the year 2000. The internet isn't static text and graphics anymore."
Do us a favour and disable Ja
Re:And they STILL can't make a working web site (Score:4, Informative)
If your site "requires" Javascript to function it is a shit site that is more concerned with form then function.
Re:And they STILL can't make a working web site (Score:4, Interesting)
The internet isn't static text and graphics anymore.
I stand by what I wrote. If your web site needs Javascript to show at all or to show pictures (above or below the fold), then you're a waste of oxygen. Comment posted with Javascript disabled, as requested.
Re: (Score:2)
You are missing half of the interesting stuff you can do with JavaScript ... e.g. single page web apps.
Re:And they STILL can't make a working web site (Score:5, Insightful)
Re: (Score:1)
I'm pretty aware about the bullshit many websites do with javascript.
But it seems you are not aware about what YOU actually could do with it if you were not blinded by your ignorance.
Re: (Score:2)
Semantically correct markup should render properly, with or without Javascript. One should have the option of "missing half the interesting stuff" without missing the content. Heck, some don't even have the option of enjoying it, for instance, the blind.
I think that's the point Honk is trying to make. It's perfectly possible to make a single page web app, that also renders correctly when javascript is disabled (though clearly without the single page stuff.) His objection seems to be aimed towards devs who c
Re: (Score:2)
Re: (Score:3)
"If you idiots were able to record every synapse firing in my body while I use your web site, you still could not make a functional web site."
Designer here (currently termed "User Experience Designer"), mainly involved in interpreting research and coming up with interaction designs for software interfaces. I mainly work for large companies.
Everywhere I've worked over the past 10 or 12 years has had some system that tracks mouse movements, page scrolls and whatnot. Sometimes per session, sometimes aggregated
Re: (Score:2)
Ugh, hungover Sunday. I meant to say anything that tells you what happened is orders of magnitude less useful in making a better product than something that tells you why it happened.
Re: (Score:2)
I didn't start working with web heat maps until 2006, I was a bit late to the game but needless to say, I've been religious about ad blocking and javascript blocking ever since. Prior to that, it was merely a strong interest and a deep concern.
Not on my computer's (Score:2)
I whitelist only the servers I trust with no script, and not any that are tied ad companies.
Re: (Score:1)
The new recaptcha does the same thing, so you would have to blacklist Google as well.
Re: (Score:2)
so you would have to blacklist Google as well.
Wouldn't be a bad idea for everyone to do that.
Hosts file? domain names mouse data going to? (Score:2)
... so they can be added to my blocklist?
Re: (Score:2)
Easy to solve for most sites (Score:5, Informative)
If you don't allow third-party scripts, you prevent most of these sorts of data collectors to function.
Re: (Score:2)
Do I assume ad blockers already block these?
Re: (Score:1)
Do I assume ad blockers already block these?
No, don't assume.
This isn't content being served to your browser to be put on a blacklist, this is javascript callback functions sending 'user input' in response to events.
('User' in quotes as you personally may not desire this, but user in the context of your browser letting you click buttons links and also sending cords in a canvas)
You'd need a script blocker that doesn't allow javascript to run unless sent from a domain you whitelist.
Plus to be actually safe, this isn't a "install and forget" sort of thi
Re: (Score:2)
No, you probably need something additional. For iOS, the Firefox Focus app can do this if you enable it as a content blocker for Safari.
Re: (Score:2)
No, it would break all the "analytics" for web developers. You need additional protection. Typically, everybody is using a cloud-based service, so these will be third-party scripts that are automatically blocked with something like uBlock Origin.
Adblockers are never enough by themselves, you always need an additional tool to prevent third party scripts. Otherwise you're an internet gloryhole.
Re: (Score:2)
Uh, isn't UO an ad blocker too?
Re: (Score:2)
No, uBlock Origin is what keeps Ceiling Cat from watching you while you do it.
Flagrant Bullshit (Score:4, Informative)
Sure, I'll believe there are a bunch of secondary Javascripts running that track that stuff but I don't believe for a minute every site is running them. More importantly, none of them are running if you use an extension like no-script to shutdown all those scripts.
Re: (Score:2)
Recaptcha? (Score:1)
I don't see a script on reddit that looks like it (Score:2)
aaxads
amazon tagsystem
google tagservices
Thats it.
Ainâ(TM)t nobody got time for that (Score:1)
What? (Score:2)
They record on which button I click?
Preposterous!
Click this MOFO! (Score:2)
Touchscreen (Score:2)
Guess I will use the touchscreen more often on my Lenovo.
too bad i use tridactyl (Score:2)
Re: too bad i use tridactyl (Score:1)
That's righteous....
Will NoScript block this? (Score:2)
And now (Score:2)
Ok, time to roll some heads.
Excellent term (Score:2)
Rage clicks? (Score:2)
I constantly click and select text while reading. Do i have rage issues? I usually notice rage, only if website starts opening some popups on my clicks
Good. (Score:2)
But I did remove a couple of dozen OK'd sites for which I can't remember the reason for allowing. I should do that more often - weekly, not monthly.