• Hawk@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    31
    ·
    21 hours ago

    We tested software at work once.

    It would show who visited your website, their socials, their phone number, e-mail and company they work for. You could also open a video that would show their mouse movement and clicks.

    All by clicking accept.

    And all of this assumes they even show that accept button properly. With all the vibe coders, I wouldn’t even trust the button to do anything at all.

    The web is just fucked. Not leaking your fingerprint sounds like an impossible task to me.

    • percent@infosec.pub
      link
      fedilink
      English
      arrow-up
      5
      ·
      16 hours ago

      Yep. It’s also interesting to see teams have conversations about implementing these things without anyone mentioning how creepy it seems. I guess these things are just normalized now :/

      • ricecake@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        6
        ·
        14 hours ago

        Entirely depends on the group. I’ve been in meetings with developers where we agreed it was creepy and pushed back. I’ve also been in meetings with marketing where they said it was normal, and meetings with others who said it was the cost the user paid to use our website. Ignoring of course that we sold stuff on the website, and that part of it was a management system that the users actually paid us money to use.

        They stopped giving me those projects, which was a win for me but arguably a loss for the users.

        I did though for a bit convince people that it was worthwhile to fix the accept/reject not working right, but that it wasn’t a top priority to fix the reject button disabling tracking for all users of the site for the duration of the cookie. (Cookie stored “be creepy” flag. When the user clicked the button it stored a flag in the session so we could statistics, and then read the flag to set the cookie. Someone used the wrong session value and stuck it in the global store used to cache sitewide data, so when it went to see if they opted out it would see if anyone had in the last month. They fixed it after the data was all fucky for a few months and they realized my argument of “who would opt out? It’s just the way the Internet works” was extremely wrong and no one will ever complain about being opted out of tracking)