Is anyone actually surprised by this?

  • grey_maniac@lemmy.ca
    link
    fedilink
    arrow-up
    60
    arrow-down
    2
    ·
    4 days ago

    I’m confused. Isn’t “collecting keystroke data” just an alarmist way to describe text entry?

    • Ferk@lemmy.ml
      link
      fedilink
      arrow-up
      1
      ·
      edit-2
      2 days ago

      This is the full paragraph:

      We collect certain device and network connection information when you access the Service. This information includes your device model, operating system, keystroke patterns or rhythms, IP address, and system language. We also collect service-related, diagnostic, and performance information, including crash reports and performance logs. We automatically assign you a device ID and user ID. Where you log-in from multiple devices, we use information such as your device ID and user ID to identify your activity across devices to give you a seamless log-in experience and for security purposes.

      It looks to me that they are using it to identify the user uniquely, maybe also related to captcha to prevent bots (it’s common practice to capture mouse and keyboard while resolving captchas to see if the movement is human-like).

    • noisefree@lemmy.world
      link
      fedilink
      arrow-up
      14
      arrow-down
      1
      ·
      4 days ago

      Maybe. They could also be doing things like paying attention to input cadence and typos/pre-send typo corrections to use as part of a fingerprint associated with the identifying information a user gives them when creating an account so that they can then attempt to detect the user elsewhere on the web whether they are using an identifying account or not.

    • uis@lemm.ee
      link
      fedilink
      arrow-up
      6
      arrow-down
      4
      ·
      4 days ago

      Not exactly. Timing between key presses can be used to identify people.

        • uis@lemm.ee
          link
          fedilink
          arrow-up
          1
          ·
          1 day ago

          The goal is not to identify keyboard model. The goal is to identify person. And people tend to have something called habbits.

          • kekmacska@lemmy.zip
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            1
            ·
            1 day ago

            the chance of this is almost zero. if you are a dangerous cybercriminal, they will track your device down by a networking solution, wait until you leave it unattended and install a hardware-based spy device and capture evidence. No fbi agent will fuck around with keyboard sounds or movie bs like that

            • uis@lemm.ee
              link
              fedilink
              arrow-up
              1
              ·
              23 hours ago

              with keyboard sounds

              Ok, I see you are intentionally going in circles.

      • grey_maniac@lemmy.ca
        link
        fedilink
        arrow-up
        2
        ·
        edit-2
        3 days ago

        I am literally so paranoid I regularly vary my keysteoke rhythms and explore polyrhytmic techniques to create variations. Not even joking.

    • tux@lemmy.world
      link
      fedilink
      arrow-up
      1
      arrow-down
      1
      ·
      4 days ago

      Not usually. Keystroke info is different than text input, like if you didn’t click onto any field and typed it would only be captured if keystroke are all being grabbed. It’s especially scary if you keep the app running in the bg and then type something and it still captures it. Not saying they’re doing that, but the privacy policy says they might.

      The rhythm part is annoying, it’s commonly used to ID people even through things like ad blocks and dns blocks. Could also (in theory) be used to capture what people are typing just by hearing how they type.