|
|
|
|
|
by nja
1648 days ago
|
|
I used to think this, until I happened across FullStory. With that tool you can replay a website visitor's exact session as if it was recorded live on video -- everything they typed (even if it was cleared and never sent in a request), where/when clicks happened, the contents and response of every request, etc. As a backend engineer, I had no idea that frontend monitoring was this advanced, but apparently it is. So now we all have to be extra paranoid, because _any_ website could be using this tool to "spy" on everybody. Of course, it _was_ very helpful to us in tracking down some issues (ever tried to tell a customer how to send you a HAR?). And I assume that operating with an adblocker and blocking nonessential cookies will prevent or hamper the output for us more technical types. Even so... |
|
Okay, wow, that sounds rough...so in a way, phishing attacks don't even require you to login anymore, just typing the password or maybe 75% of it is enough to get you.