TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Data exfiltration in Keepa Price Tracker

62 pointsby taxyovioalmost 4 years ago

10 comments

danpalmeralmost 4 years ago
Wow, they&#x27;ve built a distributed Amazon listing scraping system – essentially a botnet.<p>As someone who has done a lot of web scraping and had to route around a lot of blocking (we have business contracts to allow scraping, but they don&#x27;t stop over-eager sysadmins), this feels like a dream come true.<p>But I&#x27;d never actually want to use this for scraping and I&#x27;m not sure any informed user would agree to use this.
评论 #28048343 未加载
wildealmost 4 years ago
&gt; Unless of course you don’t consider the information collected here personal.<p>I don’t. The author even goes out of their way to point out that these requests aren’t generated by the user and so there’s no latent interest information there. I agree that they should cover this behavior in the privacy policy explicitly, but there’s a tone of moral outrage in this piece that seems unearned.
评论 #28048815 未加载
NazakiAidalmost 4 years ago
I use Keepa basic and it has saved me a ton of money. I always just assumed it was scraping the prices from pages I visit, but I didn&#x27;t know it would automatically fetch Amazon pages in the background. Might just sign out of Amazon, and use a separate browser to purchase from it.<p>Either way, I have some thinking to do on if I should &quot;keepa&quot; it or not (sorry really bad joke). Maybe I should purposely turn a blind eye and just trust they aren&#x27;t going to do anything evil nor have some privacy risk due to how useful it is.
评论 #28049914 未加载
评论 #28050199 未加载
a254613ealmost 4 years ago
I can&#x27;t quite understand this article and its conclusion.<p>The article says: &quot;[The extension] will collect information about the products you look at and the ones you search for&quot;.<p>Yet, two sentences later it says &quot;The company behind the extension fails to comply with its legal obligations. The privacy policy is misleading in claiming that no personal data is being collected.&quot;<p>So which personal information is exactly included in the data submitted to their servers about the products? Because in that json example I don&#x27;t see anything that would be even close to personal information.<p>The remote scraping&#x2F;execution abilities are not great, I&#x27;ll give it that. But the rest of it seems like overblown conclusion and interpretation of how it works.
评论 #28047933 未加载
评论 #28047981 未加载
mrsaintalmost 4 years ago
And not sure if Amazon would agree to this as it essentially threatens the privacy and integrity of their users. Interestingly, Keepa is also an Amazon Affiliate, so they are in a direct business relationship with Amazon.
评论 #28048654 未加载
评论 #28048354 未加载
dzinkalmost 4 years ago
If the additional Amazon pages are loaded on days when the user hasn’t browsed Amazon, or done once a day, that could be cookie stuffing, explicitly prohibited by Amazon Affiliate terms. The Amazon affiliate cookies last 24 hours, so triggering a session when a user doesn’t do it, might extent their affiliate window and is not right at all.
评论 #28048995 未加载
bkoralmost 4 years ago
From the Keepa addon settings:<p>&gt; Allow the add-on to gather Amazon prices to improve our price data<p>I thought it was common knowledge that Keepa uses the addon to gather prices. Though with GDPR it probably needs to be more explicitly said.
评论 #28048084 未加载
评论 #28048116 未加载
robkalmost 4 years ago
i don&#x27;t really care - i love the plugin too much to uninstall it. it&#x27;s saved me a killing.
aviparsalmost 4 years ago
thanks! Uninstalled today!<p>As well as Honey and Keepa
dna_polymerasealmost 4 years ago
Do you remember the time when this weird German startup that publishes an Adblocker tried to start an &quot;Acceptable Ads&quot; program and extort money from Google? Guess what their CTO is up to now.<p>Exactly. Showing the world the shady business of browser plugins.