PSA: Reddit has enhanced their tracking - they now use the API to track everything you do on reddit

yeah I know fuck reddit but this is important

>3 days ago, a commit (github.com/ryanbr/fanboy-adblock/commit/60a4a73cf177b26ab54f746e992d40d3ba867c5e) was made to Fanboy's Enhanced Tracking List to ensure ALL requests to reddit.com/api are NOT blocked, since it provides extensive functionality to use Reddits website on the desktop.
>Today, I discovered that Reddit is now using their API to collect user events from users.
>Previously, they used e.reddit.com, events.reddit.com, d.reddit.com and so on - all of these subdomains got added to adblock blacklists (and reddit tracks whether you use adblock).
>Now, as you can see here (i.imgur.com/JfZytEE.png) they are using share.json to collect information.
>Now let's block that URL and refresh the page.
>Now we get a request to comment.json (i.imgur.com/JjcZiD5.png)
>Let's block that and refresh.
>Now we get a request to api/submit (i.imgur.com/LvjT5AR.png) - oops, more data trying to be sent away to the mothership.
>This change is fairly recent, and I have never seen Reddit attempt to use their API as a backdoor to collecting information.
>For those more technically inclined, you can refer to redditstatic.com/reddit.en.fTMK7jltQ3I.js line 9426 to see this in action. Create a breakpoint and look at the variables, the one of note is: events_collector_url: "reddit.com/api/vote.json" which is seemingly set when the page loads.
>Also see line 9751 of the same file with e.analyticsV2.sendEvent - there are so many of those.
>They're also POSTing data directly to reddit.com and if you block reddits tracking, it literally cries at you (i.imgur.com/8T54rze.png)
>Also, if you block /api you can't do anything like submit posts or whatever. Great times.
>Each time you block a URL it picks a new one randomly from their api endpoint to try and send the tracking data too, here's a sample
of what's sent (i.imgur.com/ORcHFi0.png)

source link in next post

Attached: aaronswartz_reddit.0.jpg (1200x800, 26K)

Other urls found in this thread:

reddit.com/r/stopadvertising/comments/87d1sq/psa_reddit_has_enhanced_their_tracking_they_now/
twitter.com/AnonBabble

reddit.com/r/stopadvertising/comments/87d1sq/psa_reddit_has_enhanced_their_tracking_they_now/

>implying Sup Forums is any less of a botnet than reddit

Attached: 1511471015716.gif (251x173, 95K)

Are they intentionally trying to kill their userbase? First they massban a bunch of subs and now this?
must suck to be a leddit user

literally >>>/reddit/

Going for an IPO, cleaning up the act for the market and then the owners cash out

>having a reddit account
kys yourself

/thread

go away

I do not go on reddit
Why the hell should I care
More importantly, why post this on a site that is not reddit

it's technology news and reddit has become a resource for quite a few things, but like I said fuck reddit this is still important to know.

they're owned by Condé Nast

1) I don't have a reddit account even though I visit the site for various things (downloading videos, programming).

2) You don't need to load the JS to use the site (NoScript blocks it).

I would be very disappointed if the site required me to run their javascript. But they don't so I don't care. If you don't want them tracking you then don't create/use an account and don't allow their scripts to run.

I'm not saying you shouldn't be concerned, I'm saying there are solutions that exist.

you're right you only need js to post but you can browse it no problem

>reddit

Attached: 1522258160087.gif (237x240, 3.23M)

samefag redditor

>commie site acts like a commie state
IMAGINE MAH SHOK!

Attached: 1345161870311.gif (400x400, 217K)

The autist faggot

Attached: firefox_2018-03-28_14-46-07.png (578x172, 14K)

I can do that too

Attached: Screenshot 2018-03-28 at 12.48.14 PM.png (410x105, 10K)

Attached: 4L_5ae8uCvT.jpg (320x320, 39K)

>they now use the API to track everything you do on reddit
but... they don't, based on the evidence you quoted. did you even bother reading this shit before parroting it?

Attached: nNBD7p1.png (1493x616, 65K)

Attached: gb2leddit.png (800x480, 212K)

You need scripts to load the new user pages.

I bet our alphabet agencies think Sup Forums is fucking hilarious.
Constantly bitching about botnets even though we know damn well our gov is not just lurking, but working directly with Sup Forums.
I bet they send these threads around in emails and have a good hearty chuckle.

Didn't you see the CIA leaks from last year?
There were some comments that were included in the dump and all the government employees sound like redditors. I don't think they would enjoy anything here.

Idk what you're trying to say, our government agencies have straight up come out and said that they lurk here to keep an eye on us, and I can guarantee that they are having laughs at our expense.
I'd fish for links but I'm at work.

I haven't seen anything about that but I am interested in finding a source. I'll try to look for something and post it if anyone else is interested.

>some lowly IT user gets caught at work browsing Sup Forums
>"uhh, just keeping track of these guys, looks like they're planning on crashing a plane or something"
>bluff works too well
>ends up heading the Four Chan monitoring team

>Implying it's a bluff

If we were a successful botnet, gookmoot would be raising capital from investors, not scraping by with passes and sex toy adverts.

Nice shop

>bigger trump internet lover
>commie site

Go for it.

...so how exactly is this tracking people? What information are they gathering that wouldn't be gathered normally by your interaction with any website? On the reddit thread I'm seeing people list things like your votes and what thread/subreddit you're posting on, which is information that needs to be sent to the server in order for functionality like voting or posting to even work. Seriously, how the fuck else do they expect to be able to make a post if they don't want the site to know what thread/board they're trying to post to?

>Not reading the post
>Scrolling data is essential to use the website

Web related work isn't my specialty. Simply giving a link to a screenshot with parts of it blurred out and descriptions like "oops, more data trying to be sent away to the mothership." doesn't tell me what data is being sent, and my attention gets drawn to the parts of the screenshot they took the time to edit rather than the parts that are apparently relevant.

>going on R*ddit in the first place

...

>our government agencies
Sorry, not a burgershit.

Reddit made an achievement, by being bigger shit than cuckchan.

Attached: ritsu.jpg (200x200, 8K)

go back

>>ends up heading the Four Chan monitoring team
Hello Bernd

Attached: 1475413430451.png (439x392, 199K)

>Implying any real country isn't monitoring this cess pool

Seems like Reddit is a genuine honeypot.

kek

kek

Attached: redditfags.jpg (352x350, 92K)

Good

Attached: 1469874329105.jpg (664x567, 103K)

>reddit
>important
No, it's not. Seriously.

go discuss it on reddit dipshit

>if Sup Forums is the asshole of the internet
>if

Attached: 1427019808991.jpg (10000x10000, 3.92M)

>Implying he's telling the truth

>Reddit can see what Reddit users do on Reddit

wow it's fucking nothing

>everything YOU do on reddit

Attached: 20171007045958930.jpg (881x664, 25K)

Why is this such a big deal? Same as the facebook bullshit. Are normies really this retarded?

>use botnet
>"careful, this is botnet"
>yeah yeah I know, who cares
>"breaking news: this is botnet!"
>pinkwojaks.jpg
t. normies

Does this only take effect when you're logged in?

because it's not server side, it's abnormal, seems to be a method to get people to drop their adblocker.

yes

>the government found my munchkin multireddit

Attached: uh oh.jpg (251x189, 10K)

What's even the point in multireddits? Just do
/r/subreddit1+subreddit2+subreddit3+subreddit4

this. how is this a problem for anyone who isn't actually a fucking reddit faggot

They closed the source codes of everything last year. It's expected that they'll become even more of a police state.

didn't their canary also get triggered?

Does this change anything if Im permad on a bunch of reddit accounts?
If I change IP and clear cookies I can still sign up more right?

Literally not an issue.

why is this a problem