Skip to content

Comment on The Problem With Client-Side Analyticsparent

Comments

You don't think that, say, the same people who resent ads being shown and turn them off might think it was hilarious to send back bad analytics data to companies who are quietly profiting from same?

The same people, who, say, use a housemate's phone number for their Safeway card so that Safeway can't determine their shopping habits?

If there was an easy way to do it, many people would want to.

It's clear that there could be an easy way to do it if you put, like, two good hours of work into it.

I co-founded and ran Pinch Media, a mobile application analytics company. We operated independently for around two years before selling. During those two years, I believe we got more bad PR than a typical analytics company. I certainly got my fair share of anonymous hate email.

During that time, we received exactly two easily-filterable attempts to spoof analytics traffic. Historically, anyway, this doesn't seem to be a real problem.

Fair enough. You're much more confident than I would be about knowing.

I work in the Analytics group at Ooyala, a video platform company -- among other things we handle all the analytics traffic for all videos on ESPN.com and its various subsidiaries. We get huge amounts of traffic, weird data mangling constantly, and a wide variety of bad responses -- and that's only the stuff that gets past and mostly checksums.

It would take a pretty significant spoofing attempt for us to even know.

Nice - nothing but respect for Ooyala.

You're right - it's possible we got thousands of attempts to spoof traffic that we automatically dumped for being malformed. Like you, we also got a ton of weird data mangling and bad responses which we just ignored. Most were bad implementations or issues with the phones themselves, but some could've been spoofing attempts.

It's also possible that smaller attempts to spoof traffic went by absolutely undetected by both us and our clients. Like you, it'd take a pretty significant spoofing attempt for us to notice. That said, what's the point of an insignificant spoofing attempt?

The point of an insignificant spoofing attempt, if it isn't just ideological (and ignorable), would be to try to convince more people to do it (i.e. install the GreaseMonkey script).

Put it this way - say Richard Stallman suddenly decided that companies collecting analytics data and profiting by it (Ooyala doesn't sell it exactly, but we profit by it) was a bad thing and people needed to install a GreaseMonkey script, analogous to an ad blocker, that sent back bad data (wrong URLs, repeats, garbage, etc). That would be an individually-insignificant spoof which was potentially nasty in aggregate.

If designed well, it would also look an awful lot like a high level of background noise, but otherwise condition normal.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.